Be the man in the middle — without breaking Diffie-Hellman's math

Alice and Bob each run a real DH handshake with whoever answers on the network path between them. The math is honest on both sides — the only question neither side ever asks is who answered. Sit in the middle, run two independent handshakes, and read their "secure" message in the clear.

What Alice sends into the connection she believes is Bob's (this is all a passive eavesdropper — or you, before you start substituting keys — would ever see):

What Relay computes (real modular exponentiation, every run):

The message as it actually crosses Relay

Verifier A — Vulnerable: plain DH

Alice/Bob derive a session key from whichever public value arrived — never checked against anything

Verifier B — Fixed: HMAC-authenticated DH

tag = toy_hmac(AUTH_KEY, pubkey_bytes) — checked before either side derives a session key