Review of PDM
Have deterministic method of calculating a safe (Sophie-Germain) prime p from the password
Store at the server: p and credentials
Optimization: store also B and 2B mod p
Do D-H using 2 as the base, mod p
To speed up client side, tell user a single character “hint”, which is 6 bits of p