Often this sort of leakage comes down to timing, you can infer what a person is doing by the amount of time it takes you to do something. In the simplest example (and only slightly related to the linked article), imagine we have an API end point that allows you to log in using a password. A naive implementation of authentication might look like this:
if ( password = "hunter2" ):
return True
This in a lot of cases will be vulnerable to a timing attack. If the user submits the password "huntducks" it will take the function momentarily longer to return than if they had submitted "whalehorn", due to the underlying comparison exiting at the first non-match. With a bit of trial and error they can deduce the password one character at a time by altering their guess to take longer and longer to execute. To avoid this security sensitive code needs to be time constant, which is a lot harder than you'd imagine.Attacks like the author are performing are a lot more complicated and use tricks like coercing the victim into signing distinctive plaintexts, but the example also works for more complex systems like ECDSA where people can derive the signing key by just knowing how long it took.