Diffie-Hellman implemented very carefully can be a one component of a sound crypto protocol that does key exchange.
Both italicized phrases are important:
* It is extremely easy to implement textbook Diffie-Hellman in ways that are gravely insecure. In addition to domain-specific software implementation concerns that you must known about to safely implement number-theoretic crypto, you also have to carefully select parameters. It's parameter selection weaknesses David's paper takes advantage of.
* Diffie-Hellman by itself produces trivially breakable cryptosystems. DH is a building block. To build a safe protocol that uses DH, you need a higher-level construction --- usually, an authenticated key exchange. Check out the Noise protocol framework for more details on what this looks like. As you skim it, try to think about how relaxing or altering any of the constructions in an instantiation of Noise might produce a crypto vulnerability. This stuff is _hard_.
http://noiseprotocol.org/noise.html
The basic idea of the paper is to explore the different species of [p,g] DH parameter tuples you can come up with to produce a version of DH whose key exchanges are cryptographically difficult for randos to break, but easy for their authors to break. For instance, you can set p = pq for p and q sharing a bad generator g.
A true cryptographic "NOBUS" DH backdoor is an interesting thing to have: you can deploy it across the Internet and it will chug along executing key exchanges that only you, as the author of the parameters for the backdoor, can break.