- Each device makes an X25519 key pair when it opens, and sends only the public half. A browser without X25519 uses P-256.
- Each message gets a new random salt. HKDF turns the shared secret and the salt into an AES-GCM key, so no two messages use the same key.
- Both devices show a safety number made from both public keys. When the numbers match, nobody in the middle swapped a key.
- Send a changed copy flips one bit in the last message and sends it on. The receiving device refuses it, because the authentication tag no longer matches.