什么是时序攻击(Timing Attack)?
Posted on Thu 12 February 2026 in Tech • Tagged with security, timing-attack, constant-time, authentication, crypto • 2 min read
用 == 或 strings.Compare 比较密钥、密码或 HMAC 时,比较时间会随 "猜对多少" 变化,攻击者可以按响应时间逐字节猜出秘密;一文说清原理与常数时间比较的用法。
Continue reading