<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>gus.gray</title>
    <subtitle>Notes on security and engineering.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://gusthegray.dev/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://gusthegray.dev"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2026-07-12T00:00:00+00:00</updated>
    <id>https://gusthegray.dev/atom.xml</id>
    <entry xml:lang="en">
        <title>Efficient vs Effective and Other Thoughts on Team Dynamics</title>
        <published>2026-07-12T00:00:00+00:00</published>
        <updated>2026-07-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://gusthegray.dev/blog/efficient-vs-effective/"/>
        <id>https://gusthegray.dev/blog/efficient-vs-effective/</id>
        
        <content type="html" xml:base="https://gusthegray.dev/blog/efficient-vs-effective/">&lt;p&gt;In this post I want to outline something that I end up pontificating on a lot and explaining to new leaders. The difference between what an efficient team looks like, what an effective team looks like, and the spectrum &#x2F; tradeoffs between the two. Finally I also talk about what high performing teams actually look like.&lt;&#x2F;p&gt;
&lt;h1 id=&quot;teams-optimized-for-efficiency&quot;&gt;Teams optimized for efficiency&lt;&#x2F;h1&gt;
&lt;p&gt;Efficient teams are characterized by being able to operate with the most minimal resources necessary to deliver. They are lean and scrappy, with every resource fully utilized. They look great on the bottom line. They are one incident, pivot or complexity discovery away from disaster. The problem is they have no slack to absorb the unexpected and in our industry, there&#x27;s always something unexpected.&lt;&#x2F;p&gt;
&lt;h1 id=&quot;teams-optimized-for-effectiveness&quot;&gt;Teams optimized for effectiveness&lt;&#x2F;h1&gt;
&lt;p&gt;Effective teams are characterized by their ability to consistently deliver, on or under time, pivot at a moment&#x27;s notice, and deliver something that hadn&#x27;t even been conceptualized a short time ago. They can anticipate a need from a mile away, handle unexpected incidents, and still deliver their projects on time. They can do this because they have resources to spare. There&#x27;s slack in their capacity which allows them to absorb the unexpected complications that will inevitably arise. They are also more expensive on paper.&lt;&#x2F;p&gt;
&lt;h1 id=&quot;the-slider-between-effective-and-efficient&quot;&gt;The slider between effective and efficient&lt;&#x2F;h1&gt;
&lt;p&gt;Costs, both hidden and visible, are the tradeoffs. The cost difference between the two can almost be thought of as an insurance policy. By running a team more efficiently, you&#x27;re lessening your costs, but also lessening their capacity to absorb the unexpected. This &lt;em&gt;will&lt;&#x2F;em&gt; result in higher incidence of missed deadlines, unexpected outages, and of course, fatigue and burnout on the team.
In contrast, a team staffed with greater amounts of unallocated capacity is going to look more expensive on the bottom line, but will be able to be more consistent in deliverables and less prone to disruption. You&#x27;ll have a healthier, happier team, and that results in better, higher quality, outcomes.&lt;&#x2F;p&gt;
&lt;h1 id=&quot;what-does-a-true-high-performing-team-look-like&quot;&gt;What does a true, high performing team, look like?&lt;&#x2F;h1&gt;
&lt;p&gt;So far I&#x27;ve talked about resourcing as a dial you set. But there&#x27;s a separate question that resourcing alone doesn&#x27;t answer: what does the team look like when it&#x27;s actually working?&lt;&#x2F;p&gt;
&lt;p&gt;I&#x27;ve had the pleasure of working with many teams and a whole bunch of leaders of all calibers during my career. I&#x27;ll tell a story, give an analogy, and then some further thoughts.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;a-story-from-my-past-a-tale-of-two-teams&quot;&gt;A story from my past, a tale of two teams&lt;&#x2F;h2&gt;
&lt;p&gt;At one company I previously worked at, there were two teams for one mobile app. One was for the iOS version, the other for the Android version. One team was almost a dozen people between developers and QA. They occupied an entire room, were constantly in frantic motion, lots of visible running around late nights and weekends, trying to get things closed out by the last minute.
The other team was significantly smaller, only two developers and a QA. They shared a room with another team, mine. In the morning they would put their heads together, talk for about 15 minutes, then get to work. At noon they went to lunch. If they needed to discuss something during the day, they&#x27;d stop working, turn their chairs towards each other for a few minutes, then quietly turn back to their monitors and get back to work. They&#x27;d usually leave promptly, right at 5, or earlier. One team was motion, smoke and fire constantly, the other was just smooth and quiet.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;the-drivers&quot;&gt;The drivers&lt;&#x2F;h2&gt;
&lt;p&gt;Any fans of top gear? There are two episodes from 2012 that have always stood out to me as a good contrast. will.i.am and Matt LeBlanc. Both of them took a drive in the &quot;Star in a Reasonably Priced Car&quot; segment for episodes in series 18. This segment is where a celebrity would be given a few attempts to drive a track in a &quot;reasonably priced car&quot; and their best time was recorded.
will.i.am was exciting. He made a bunch of mistakes but by his final lap he seemed to have it dialed in. Tires were squealing around the corners, hard engine revving etc... Really kept you on the edge of your seat. LeBlanc on the other hand, well Hammond straight up described it as &quot;...boring...&quot;  LeBlanc&#x27;s final lap on the track was almost boring to watch, almost just looked like a dude heading to the store to grab some milk.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;who-s-actually-high-performance&quot;&gt;Who&#x27;s actually high performance&lt;&#x2F;h2&gt;
&lt;p&gt;So in each of the previous cases, which one was the actual high performer? The one that was exciting to look at with lots of motion, smoke, noise, and excitement? Hammond said it best in his full quote about LeBlanc&#x27;s best run. &quot;The more boring it looks, the faster it often is.&quot;
That&#x27;s it. The best teams I&#x27;ve worked with have been straight up boring. They are quiet, unassuming professionals that just get shit done without a lot of noise and fuss. Things are organized, quiet, and move smoothly. Disruptions are handled as part of the standard process and there just isn&#x27;t a lot of disruptive noises, emergency meetings, fire drills, or the other things that make for exciting TV.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Visualizing Diffie-Hellman in Rust + WASM</title>
        <published>2026-06-22T00:00:00+00:00</published>
        <updated>2026-06-22T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://gusthegray.dev/blog/diffie-hellman-visualized/"/>
        <id>https://gusthegray.dev/blog/diffie-hellman-visualized/</id>
        
        <content type="html" xml:base="https://gusthegray.dev/blog/diffie-hellman-visualized/">&lt;p&gt;The Diffie-Hellman equation was my first love in the world of cryptography and cybersecurity as a whole. So I think it fitting it be the first article for this new blog. Hopefully it won&#x27;t be the only one.&lt;&#x2F;p&gt;
&lt;p&gt;I first came across it when a buddy of mine recommended I apply for a job at the company where he then worked. This company was heavily involved in the cryptography space, so in order to get ready for the interviews, I decided to read up on what was then a new-to-me concept. I checked out a copy of &lt;em&gt;An Introduction to Mathematical Cryptography&lt;&#x2F;em&gt; by Jeffrey Hoffstein from the library of the community college I was attending. I started reading it and working through some of the early exercises. Early on we get to a chapter on the Diffie-Hellman exchange. I stopped. I re-read the earlier sections. I read the proof again and walked through it myself step by step. I found it elegant, magnificent, and absolutely beautiful in the truest sense of that word. I learned it so well that when I went in for my interview I was able to even fully walk through the formal proof on a white board when asked a question about it. I did not get that job (hindsight 20&#x2F;20, that&#x27;s a good thing) but that was the first step that catapulted me into the career I enjoy today.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;1-the-problem-agreeing-in-public&quot;&gt;1. The problem: agreeing in public&lt;&#x2F;h2&gt;
&lt;p&gt;The question Diffie-Hellman solves is actually pretty simple on the surface: how do you agree on a shared secret with another party whom you have never met and can only communicate with in a public setting? I promise that this shared secret being &lt;em&gt;just a number&lt;&#x2F;em&gt; will pay off big down the road (probably in a future post).&lt;&#x2F;p&gt;
&lt;p&gt;The answer as it turns out is math. Really cool math.&lt;&#x2F;p&gt;
&lt;p&gt;Our cast of characters are ones familiar to anyone that&#x27;s read anything about cryptography. Alice, Bob, and Eve. Alice and Bob are our protagonists, Eve (short for Eavesdropper) is the antagonist.&lt;&#x2F;p&gt;
&lt;p&gt;Alice and Bob have never met and share no secret. Every byte they exchange is
visible to Eve, who is recording everything. Somehow they need to end up
holding the &lt;em&gt;same&lt;&#x2F;em&gt; secret number that Eve does &lt;strong&gt;not&lt;&#x2F;strong&gt; have.&lt;&#x2F;p&gt;
&lt;p&gt;That sounds impossible — and with more classic cryptographic techniques, it is. The trick is
to pick an operation that&#x27;s cheap to do and ludicrously expensive to undo.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;2-the-toy-protocol&quot;&gt;2. The toy protocol&lt;&#x2F;h2&gt;
&lt;p&gt;The Diffie-Hellman key exchange leans on the &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Discrete_logarithm&quot;&gt;Discrete Logarithm Problem&lt;&#x2F;a&gt; — easy to compute one way (powers mod p), painfully hard to reverse. Everything starts from two &lt;strong&gt;public&lt;&#x2F;strong&gt; numbers, agreed in the open:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #CDD6F4; background-color: #1E1E2E;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;p = prime modulus&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;g = generator   (a base whose powers cycle through the group)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Then each side rolls a private number and publishes one value:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #CDD6F4; background-color: #1E1E2E;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Alice:  private a    public  A = g^a mod p&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Bob:    private b    public  B = g^b mod p&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;They swap &lt;code&gt;A&lt;&#x2F;code&gt; and &lt;code&gt;B&lt;&#x2F;code&gt; over the open channel and each finishes locally:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #CDD6F4; background-color: #1E1E2E;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Alice computes  s = B^a mod p&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Bob computes    s = A^b mod p&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;With the textbook small values &lt;code&gt;p = 23, g = 5, a = 6, b = 15&lt;&#x2F;code&gt;:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #CDD6F4; background-color: #1E1E2E;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;A = 5^6  mod 23 = 8&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;B = 5^15 mod 23 = 19&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;s = 19^6 mod 23 = 2     (Alice)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;s = 8^15 mod 23 = 2     (Bob)&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Both land on &lt;code&gt;2&lt;&#x2F;code&gt;. Eve saw &lt;code&gt;p, g, A, B&lt;&#x2F;code&gt; go past and still can&#x27;t get there.
Drag the sliders and watch it hold:&lt;&#x2F;p&gt;
&lt;div class=&quot;dh-lab&quot; id=&quot;dh-lab&quot;&gt;
  &lt;noscript class=&quot;dh-error&quot;&gt;This lab needs JavaScript + WebAssembly. The static example below shows the same idea.&lt;&#x2F;noscript&gt;
  &lt;!-- Fallback shown until the WASM module loads (or if it can&#x27;t). --&gt;
  &lt;div class=&quot;dh-fallback&quot;&gt;
    &lt;div class=&quot;dh-channel&quot;&gt;
      &lt;div class=&quot;dh-party&quot;&gt;
        &lt;h4&gt;Alice&lt;&#x2F;h4&gt;
        &lt;code&gt;a = 6&lt;&#x2F;code&gt;
        &lt;code&gt;A = g&lt;sup&gt;a&lt;&#x2F;sup&gt; mod p = 8&lt;&#x2F;code&gt;
        &lt;code&gt;s = B&lt;sup&gt;a&lt;&#x2F;sup&gt; mod p = 2&lt;&#x2F;code&gt;
      &lt;&#x2F;div&gt;
      &lt;div class=&quot;dh-wire&quot;&gt;
        &lt;div class=&quot;dh-wire-line&quot;&gt;A = 8 →&lt;&#x2F;div&gt;
        &lt;div class=&quot;dh-wire-line&quot;&gt;← B = 19&lt;&#x2F;div&gt;
        &lt;span class=&quot;dh-wire-label&quot;&gt;public channel&lt;&#x2F;span&gt;
      &lt;&#x2F;div&gt;
      &lt;div class=&quot;dh-party&quot;&gt;
        &lt;h4&gt;Bob&lt;&#x2F;h4&gt;
        &lt;code&gt;b = 15&lt;&#x2F;code&gt;
        &lt;code&gt;B = g&lt;sup&gt;b&lt;&#x2F;sup&gt; mod p = 19&lt;&#x2F;code&gt;
        &lt;code&gt;s = A&lt;sup&gt;b&lt;&#x2F;sup&gt; mod p = 2&lt;&#x2F;code&gt;
      &lt;&#x2F;div&gt;
    &lt;&#x2F;div&gt;
    &lt;p class=&quot;dh-match&quot; data-ok=&quot;true&quot;&gt;shared secret agreed: s = 2 &amp;nbsp;(p = 23, g = 5)&lt;&#x2F;p&gt;
  &lt;&#x2F;div&gt;
&lt;&#x2F;div&gt;
&lt;script type=&quot;module&quot; src=&quot;https:&#x2F;&#x2F;gusthegray.dev&#x2F;js&#x2F;dh-lab.js&quot;&gt;&lt;&#x2F;script&gt;
&lt;h2 id=&quot;3-why-both-sides-get-the-same-number&quot;&gt;3. Why both sides get the same number&lt;&#x2F;h2&gt;
&lt;p&gt;There&#x27;s no magic here — just exponents that commute:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #CDD6F4; background-color: #1E1E2E;&quot;&gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;B^a = (g^b)^a = g^(b·a) mod p&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;A^b = (g^a)^b = g^(a·b) mod p&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;Since &lt;code&gt;b·a = a·b&lt;&#x2F;code&gt;, both sides land on the very same &lt;code&gt;g^(ab) mod p&lt;&#x2F;code&gt;. Alice and Bob
arrive at the identical number from opposite directions — and notice what never
crossed the wire: not &lt;code&gt;a&lt;&#x2F;code&gt;, not &lt;code&gt;b&lt;&#x2F;code&gt;, and not the secret &lt;code&gt;s&lt;&#x2F;code&gt; itself. That&#x27;s the
whole beautiful trick, in one line.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;4-why-eve-loses&quot;&gt;4. Why Eve loses&lt;&#x2F;h2&gt;
&lt;p&gt;So where does all this leave Eve? She&#x27;s been listening the whole time, so she
has &lt;code&gt;p&lt;&#x2F;code&gt;, &lt;code&gt;g&lt;&#x2F;code&gt;, &lt;code&gt;A&lt;&#x2F;code&gt;, and &lt;code&gt;B&lt;&#x2F;code&gt;. To break in she needs to find &lt;code&gt;a&lt;&#x2F;code&gt; (or &lt;code&gt;b&lt;&#x2F;code&gt;) — some
exponent where &lt;code&gt;g^a mod p = A&lt;&#x2F;code&gt;. And that, right there, is the &lt;strong&gt;discrete
logarithm problem&lt;&#x2F;strong&gt; we ran into back in section 2.&lt;&#x2F;p&gt;
&lt;p&gt;Going forward — &lt;code&gt;a → g^a mod p&lt;&#x2F;code&gt; — is quick. Going backward — &lt;code&gt;A → a&lt;&#x2F;code&gt; — has no
known efficient method when &lt;code&gt;p&lt;&#x2F;code&gt; is large and well chosen. Look at the right-hand
plot in the lab and you can almost feel it: &lt;code&gt;g^x mod p&lt;&#x2F;code&gt; scatters everywhere with
no usable structure. No slope to follow, no clever binary search, nothing to
exploit but brute force — and brute force quietly loses the instant &lt;code&gt;p&lt;&#x2F;code&gt; grows to
hundreds of digits.&lt;&#x2F;p&gt;
&lt;p&gt;The left-hand plot is where you can see &lt;em&gt;why&lt;&#x2F;em&gt; the choice of &lt;code&gt;g&lt;&#x2F;code&gt; matters so much.
A true generator&#x27;s orbit sweeps through &lt;strong&gt;every&lt;&#x2F;strong&gt; nonzero value mod &lt;code&gt;p&lt;&#x2F;code&gt; before it
loops back around. Pick a &lt;code&gt;g&lt;&#x2F;code&gt; that isn&#x27;t a primitive root, though, and that orbit
collapses into a small subgroup — the lab will call this out for you — and all of
a sudden Eve&#x27;s search space is a lot smaller than it ought to be. Which is exactly
where toy Diffie-Hellman starts to break. We&#x27;ll pull on that thread in part two.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;5-under-the-hood-modular-exponentiation-in-rust&quot;&gt;5. Under the hood: modular exponentiation in Rust&lt;&#x2F;h2&gt;
&lt;p&gt;We&#x27;ve leaned on &lt;code&gt;g^x mod p&lt;&#x2F;code&gt; this whole post without once saying how you actually
compute it. Strip everything else away and that&#x27;s the only operation the protocol
needs — done over and over. The naive way — compute the giant power and &lt;em&gt;then&lt;&#x2F;em&gt;
take the remainder — falls apart fast, because that power gets astronomically
large. So instead you reduce as you go, with square-and-multiply:&lt;&#x2F;p&gt;
&lt;pre class=&quot;giallo&quot; style=&quot;color: #CDD6F4; background-color: #1E1E2E;&quot;&gt;&lt;code data-lang=&quot;rust&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #F9E2AF;font-style: italic;&quot;&gt;#&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;[&lt;&#x2F;span&gt;&lt;span style=&quot;color: #F9E2AF;font-style: italic;&quot;&gt;wasm_bindgen&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;]&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt;pub fn&lt;&#x2F;span&gt;&lt;span style=&quot;color: #89B4FA;font-style: italic;&quot;&gt; mod_exp&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;(&lt;&#x2F;span&gt;&lt;span style=&quot;color: #EBA0AC;&quot;&gt;base&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt;:&lt;&#x2F;span&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt; u64&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt; mut&lt;&#x2F;span&gt;&lt;span style=&quot;color: #EBA0AC;&quot;&gt; exp&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt;:&lt;&#x2F;span&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt; u64&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;,&lt;&#x2F;span&gt;&lt;span style=&quot;color: #EBA0AC;&quot;&gt; modulus&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt;:&lt;&#x2F;span&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt; u64&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;)&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; -&amp;gt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt; u64&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt;    if&lt;&#x2F;span&gt;&lt;span&gt; modulus&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; &amp;lt;=&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FAB387;&quot;&gt; 1&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt;        return&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FAB387;&quot;&gt; 0&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;    }&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt;    let&lt;&#x2F;span&gt;&lt;span&gt; m&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; =&lt;&#x2F;span&gt;&lt;span&gt; modulus&lt;&#x2F;span&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt; as u128&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt;    let mut&lt;&#x2F;span&gt;&lt;span&gt; result&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt;:&lt;&#x2F;span&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt; u128&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; =&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FAB387;&quot;&gt; 1&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt;    let mut&lt;&#x2F;span&gt;&lt;span&gt; b&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; =&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt; (&lt;&#x2F;span&gt;&lt;span&gt;base&lt;&#x2F;span&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt; as u128&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;)&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; %&lt;&#x2F;span&gt;&lt;span&gt; m&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt;    while&lt;&#x2F;span&gt;&lt;span&gt; exp&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; &amp;gt;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FAB387;&quot;&gt; 0&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt;        if&lt;&#x2F;span&gt;&lt;span&gt; exp&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; &amp;amp;&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FAB387;&quot;&gt; 1&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; ==&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FAB387;&quot;&gt; 1&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt; {&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;            result&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; =&lt;&#x2F;span&gt;&lt;span&gt; result&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; *&lt;&#x2F;span&gt;&lt;span&gt; b&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; %&lt;&#x2F;span&gt;&lt;span&gt; m&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;        }&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        exp&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; &amp;gt;&amp;gt;=&lt;&#x2F;span&gt;&lt;span style=&quot;color: #FAB387;&quot;&gt; 1&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        b&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; =&lt;&#x2F;span&gt;&lt;span&gt; b&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; *&lt;&#x2F;span&gt;&lt;span&gt; b&lt;&#x2F;span&gt;&lt;span style=&quot;color: #94E2D5;&quot;&gt; %&lt;&#x2F;span&gt;&lt;span&gt; m&lt;&#x2F;span&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;;&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;    }&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    result&lt;&#x2F;span&gt;&lt;span style=&quot;color: #CBA6F7;&quot;&gt; as u64&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span style=&quot;color: #9399B2;&quot;&gt;}&lt;&#x2F;span&gt;&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;See that &lt;code&gt;u128&lt;&#x2F;code&gt;? It matters more than it looks. Stay in &lt;code&gt;u64&lt;&#x2F;code&gt; — or worse, reach
for &lt;code&gt;saturating_mul&lt;&#x2F;code&gt; to &quot;handle overflow&quot; — and you&#x27;ve built a primitive that&#x27;s
&lt;strong&gt;silently wrong&lt;&#x2F;strong&gt; the moment a factor climbs past &lt;code&gt;2^32&lt;&#x2F;code&gt;, because &lt;code&gt;b * b&lt;&#x2F;code&gt;
overflows before the &lt;code&gt;% m&lt;&#x2F;code&gt; ever runs. With the toy primes here you&#x27;d never catch
it. In real code you&#x27;d have shipped a broken crypto primitive and been none the
wiser. Widening the intermediate to &lt;code&gt;u128&lt;&#x2F;code&gt; is the whole fix: cheap, boring,
correct. (Past &lt;code&gt;u64&lt;&#x2F;code&gt; you&#x27;d reach for a big-integer type instead.)&lt;&#x2F;p&gt;
&lt;p&gt;And here&#x27;s the part I still find a little magical: this is the &lt;em&gt;exact&lt;&#x2F;em&gt; function
the lab above runs, compiled straight to WebAssembly with &lt;code&gt;wasm-bindgen&lt;&#x2F;code&gt;. No
JavaScript reimplementation, no hand-waving — the same Rust I&#x27;d write for a real
implementation is what&#x27;s executing in your browser right now.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;why-it-mattered&quot;&gt;Why it mattered&lt;&#x2F;h2&gt;
&lt;p&gt;It&#x27;s hard to overstate what Whitfield Diffie and Martin Hellman pulled off in
1976. Before their paper — &quot;New Directions in Cryptography&quot; — private
communication meant somehow exchanging a key in secret &lt;em&gt;first&lt;&#x2F;em&gt;, a chicken-and-egg
problem people had wrestled with for millennia. They showed that two strangers
could agree on a secret in full view of their adversary. That&#x27;s the whole idea
we&#x27;ve been circling, and it quietly became part of the plumbing of the modern
world: a direct ancestor of the key exchange behind nearly every HTTPS connection
you make.&lt;&#x2F;p&gt;
&lt;p&gt;However this toy version we&#x27;ve been poking at is fragile. Tiny primes fall to brute force in microseconds. A badly chosen &lt;code&gt;g&lt;&#x2F;code&gt;
leaks structure — you watched its orbit collapse into a handful of dots. More important, even
with big, careful parameters, plain Diffie-Hellman doesn&#x27;t know &lt;em&gt;who&lt;&#x2F;em&gt; it&#x27;s talking
to: unauthenticated, it&#x27;s wide open to a man-in-the-middle who quietly runs the
exchange with each side. This was actually a key thing I didn&#x27;t call out in that interview all those years ago.&lt;&#x2F;p&gt;
&lt;p&gt;That gap — between this beautiful equation and what now holds up just about the entirety of private communications on the public networks we call the internet — is where we&#x27;ll go next.&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
