The only flaw in the DHM algorithm is that it depends on a RNG.
It goes back to the fact that if the NSA has infiltrated the RNG, then DHM key exchange is merely a slight nuisance.
I wrote some software that patched out MS' CryptGenRandom() to only return 0x01's all day. I was easily able to then implement a MITM attack on Adobe RTMPE traffic all day long.
I'm stupid... Imagine what an NSA engineer could accomplish.