Lec 7: UC-(In)Secure PAKE Protocols
Example 1: Diffie-Hellman key exchange is not UC-secure
Man-in-the-middle attack on DH not simulatable
Example 2: allowing for offline dictionary attack makes PAKE not UC-secure
Example 3: EKE with plain Diffie-Hellman is not UC-secure