Skip to content

Security

Security is broad. Unless you have deep experience or are applying for a security role, you likely only need the basics.

The essentials

  • Encrypt in transit and at rest.
  • Sanitize all user inputs and any input parameters exposed to users to prevent XSS (cross-site scripting) and SQL injection.

  • Use parameterized queries to prevent SQL injection.

  • Apply the principle of least privilege (give users/processes only the permissions they need).

Quick checklist

Concern Mitigation
Data in transit TLS/HTTPS
Data at rest Encryption (disk/DB)
SQL injection Parameterized queries + input sanitization
XSS Escape/sanitize user input
Over-permission Least privilege

Key takeaways

  • For most system design interviews, mention the four bullets above and move on.
  • Security is cross-cutting: it applies to every layer (edge, app, DB, storage).

Common Interview Questions

Design a secure URL shortener

Why it's asked here: URL shorteners have real abuse/security concerns.

Key points to discuss:

  • Rate limiting to stop abuse; auth/API keys for privileged operations.
  • Validate/sanitize input URLs; prevent open redirect and SSRF.
  • Use HTTPS (encrypt in transit); hash secrets; least privilege.
  • Prevent enumeration (unpredictable short codes).
flowchart LR
    U[User] --> R[Rate limiter]
    R --> A[App + auth]
    A -->|validate URL| H[Hash generator]
    H --> D[(URLs DB)]
    U -->|HTTPS| A
Design an authentication/authorization system (SSO)

Why it's asked here: auth is the core security design question.

Key points to discuss:

  • Tokens (JWT) vs sessions; sign with strong keys; short expiry + refresh.
  • Encrypt credentials at rest (bcrypt/argon2); TLS in transit.
  • OAuth2/OIDC flows for third-party login (SSO).
  • Least privilege and scopes for authorization.
flowchart LR
    U[User] --> ID[Identity Provider]
    ID -->|OAuth2 / OIDC| A[App]
    A -->|JWT| RES[Resource]
    A -->|validate| ID

Further reading