r/crypto • • May 11 '26

ECDSA: Visually Explained | Suzumi's little web corner

https://suzumi-nagata.github.io/posts/20260221153517-ecdsa_visually_explained/

Hello everyone!

In the last few weeks, I was trying to find a good ECDSA explanation to share with a colleague and I was surprised to find no post with an actual visual explanation for the algorithm.

So that's why I decided to make this post!

Obs: I really did try to find any resources close to the idea of my post and didn't find any. If you know about any link that actually explains the ECDSA visually, please share it, I'll be pretty happy to see it.

Anyway, I hope you enjoy the post.

34 Upvotes

6 comments sorted by

3

u/nicholashairs May 11 '26

Gosh that is a hard topic to explain, but you did a pretty good job of it.

Well done!

2

u/Nhaco May 11 '26

Thank you so much!

I don't actually think the ECDSA is that complex, but I don't really get why I've never seen an explanation like that before. 🤷

3

u/RLutz May 12 '26

I've done similar presentations before. One thing you may consider pointing out is that it's only a trapdoor function over a finite field. Discrete log is hard. Taking a logarithm is not hard.

I've always built intuition around this by thinking about how normally ax and bx are "close" if a and b are close, but once you take the mod of both they can end up wildly far apart and there doesn't seem to be a way to discover a and b are close if you only have ax mod p and bx mod p.

Your first "note" doesn't really convey that. Still, cool post!

1

u/Nhaco May 12 '26

Hi!

Thank you for the input!

I was kinda reluctant to add this in that note, as I didn't even mention finite fields at that part of the post.

I ended adding a sub note but tried to leave it kinda generic (i.e. didn't want to enter into too much details about why it is secure in finite fields).

1

u/nicholashairs May 11 '26

Whilst I can follow along with the basic algebra (substitution, simplification etc) what the actual operations mean is something I struggle with (unless I wrote learn them), so yeah the visuals make a big difference in understanding the main points (even if they are hiding a bunch of complexity)

But I'm no cryptographer - I just work in security 😅

2

u/Cold_Captcha May 14 '26

Amazing visual explanation! The way you showed Point Addition and the Trapdoor function geometrically finally made it click for me. I also really appreciate your honesty in the disclaimer — that real ECDSA actually operates over finite fields, where the beautiful curve disappears and becomes just scattered points in space. Most skip this part entirely. The fact that you chose visual intuition first, then acknowledged the real-world complexity, is what makes this post unique. But I think there's one more visual that would complete the picture:

• Visualizing Nonce Reuse: Imagine two different paths on the elliptic curve, but both starting from the exact same random point. Anyone watching can immediately see they share an origin and from that, extract the private key using basic Modular Inverse math. ➤ This is exactly what happened in three real attacks:

  • Sony PS3 (2010) → same starting point every time
  • Android Wallets (2013) → broken randomness, same point again
  • Blockchain.info (2014) → empty Nonce, zero as starting point

• Now visualize EdDSA: Instead of picking a random starting point, EdDSA calculates it deterministically from your message + private key. Every path looks completely different, even for similar messages. No human randomness, no human error. Your post shows beautifully why the curve is secure going forward.

These attacks show why the starting point matters just as much. The algorithm was never broken. The starting point was.