Alice and Bob agree on a secret while every message they exchange is public. Nothing is encrypted and no key is ever sent — the security is that recovering a private exponent means solving a discrete logarithm.
To get the secret Eve must find a from A = ga mod p — the discrete logarithm problem. Easy for p = 23; believed infeasible for a 2048-bit prime.
Eve knows g, A and p. Recovering a means answering “g to what power gives A?” Brute force below tries every exponent — instant for a small prime, and the reason real deployments use primes of 2048 bits or more.
One warning this tool cannot show you: Diffie-Hellman gives no authentication. Eve sitting in the middle can run one exchange with Alice and another with Bob, and read everything while both believe they are secure. That is why real protocols sign the exchange — the key agreement and the identity check are separate problems.
(g^a)^b = g^(ab) = (g^b)^a mod p
Alice and Bob agree publicly on a prime p and a generator g. Alice picks a secret a and sends ga; Bob picks a secret b and sends gb. Each raises what they received to their own secret.
Both land on gab mod p, because exponents multiply the same way in either order. Neither ever transmitted their exponent, and no key travelled across the wire at all.
Eve sees p, g, ga and gb. To finish she needs gab, and the only known route is to recover a or b — the discrete logarithm problem.
Diffie-Hellman solves exactly one problem, and it is important to be precise about which:
The tool shows the mechanism — the slides show why it is built that way.
Agreeing a secret in public sounds impossible until you see it work. One-on-one tutoring builds it from the group theory up, then shows how TLS uses it today.