<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Security on Jeanphilo Blog</title><link>https://shio-chan-dev.github.io/jeanblog/zh/dev/security/</link><description>Recent content in Security on Jeanphilo Blog</description><generator>Hugo -- 0.159.2</generator><language>zh-cn</language><lastBuildDate>Sat, 24 Jan 2026 12:33:47 +0800</lastBuildDate><atom:link href="https://shio-chan-dev.github.io/jeanblog/zh/dev/security/index.xml" rel="self" type="application/rss+xml"/><item><title>什么是双因素认证（2FA）：机制、实现与风险</title><link>https://shio-chan-dev.github.io/jeanblog/zh/dev/security/two-factor-auth-basics/</link><pubDate>Sat, 24 Jan 2026 12:33:47 +0800</pubDate><guid>https://shio-chan-dev.github.io/jeanblog/zh/dev/security/two-factor-auth-basics/</guid><description>解释 2FA 的基本机制、常见实现方式与工程注意事项。</description></item><item><title>在已有 Web 应用中实现 2FA：落地步骤与风险控制</title><link>https://shio-chan-dev.github.io/jeanblog/zh/dev/security/implement-2fa-in-existing-web/</link><pubDate>Sat, 24 Jan 2026 12:33:47 +0800</pubDate><guid>https://shio-chan-dev.github.io/jeanblog/zh/dev/security/implement-2fa-in-existing-web/</guid><description>给出在已有 Web 应用引入 2FA 的工程步骤、数据模型与回滚策略。</description></item><item><title>为什么不该自己设计密码学：风险、误区与替代方案</title><link>https://shio-chan-dev.github.io/jeanblog/zh/dev/security/why-not-roll-your-own-crypto/</link><pubDate>Sat, 24 Jan 2026 11:11:28 +0800</pubDate><guid>https://shio-chan-dev.github.io/jeanblog/zh/dev/security/why-not-roll-your-own-crypto/</guid><description>解释自创密码学为何高风险，并给出工程上更安全的替代做法。</description></item></channel></rss>