Security¶
Security is broad. Unless you have deep experience or are applying for a security role, you likely only need the basics.
The essentials¶
- Encrypt in transit and at rest.
-
Sanitize all user inputs and any input parameters exposed to users to prevent XSS (cross-site scripting) and SQL injection.
-
Use parameterized queries to prevent SQL injection.
- Apply the principle of least privilege (give users/processes only the permissions they need).
Quick checklist¶
| Concern | Mitigation |
|---|---|
| Data in transit | TLS/HTTPS |
| Data at rest | Encryption (disk/DB) |
| SQL injection | Parameterized queries + input sanitization |
| XSS | Escape/sanitize user input |
| Over-permission | Least privilege |
Key takeaways¶
- For most system design interviews, mention the four bullets above and move on.
- Security is cross-cutting: it applies to every layer (edge, app, DB, storage).
Common Interview Questions¶
Design a secure URL shortener
Why it's asked here: URL shorteners have real abuse/security concerns.
Key points to discuss:
- Rate limiting to stop abuse; auth/API keys for privileged operations.
- Validate/sanitize input URLs; prevent open redirect and SSRF.
- Use HTTPS (encrypt in transit); hash secrets; least privilege.
- Prevent enumeration (unpredictable short codes).
flowchart LR
U[User] --> R[Rate limiter]
R --> A[App + auth]
A -->|validate URL| H[Hash generator]
H --> D[(URLs DB)]
U -->|HTTPS| A
Design an authentication/authorization system (SSO)
Why it's asked here: auth is the core security design question.
Key points to discuss:
- Tokens (JWT) vs sessions; sign with strong keys; short expiry + refresh.
- Encrypt credentials at rest (bcrypt/argon2); TLS in transit.
- OAuth2/OIDC flows for third-party login (SSO).
- Least privilege and scopes for authorization.
flowchart LR
U[User] --> ID[Identity Provider]
ID -->|OAuth2 / OIDC| A[App]
A -->|JWT| RES[Resource]
A -->|validate| ID