Encrypted messages (P1)
Two devices, Alice and Bob, send each other messages that the relay between them cannot read.
How a message is encrypted
Each device makes an X25519 key pair when it opens and sends only the public half. A browser without X25519 uses the P-256 curve instead. For every message the sender makes a random salt, combines its private key with the other device's public key, and turns the shared secret and the salt into an AES-GCM key with HKDF. The message is encrypted with that key, and the names of the sender and the receiver are bound to it as additional data.
The safety number
Both devices show a safety number of 30 digits made from both public keys. When the numbers match on the two screens, nobody in the middle swapped a key. When a device gets a new key, the other device says so.
The relay
The relay lists every frame: public keys, messages and goodbyes. Its button Send a changed copy flips one bit in the last message. The receiving device refuses the copy, because the authentication tag no longer matches.
Previous: Overview. Next: Signed documents (P2).