Security Notes
System Design

System Design Interview Prep

Based on the HelloInterview curriculum. Each topic file follows the same structure: problem → requirements → core design → key decisions → security angle → interview tips.

10 min read 6 sections

How to Use

Understand the delivery framework

(foundations.md) before individual problems

Study by difficulty

start Easy → Medium → Hard

Security lens

every design has a security section — always weave this into your answer

Numbers matter

know latency/throughput/storage estimates cold (see foundations.md)


Reusable Requirements Cheat Sheet

Copy-paste these into any design. Most systems share ~80% of their requirements — the differentiator is the unique functional requirement and the dominant non-functional constraint.

Recurring Functional Requirements

These appear in almost every system. State them briefly, then move on to the unique ones.

Authentication & accounts
  - Users can register, log in, log out
  - Password reset via email
  - Optional: OAuth (Sign in with Google/GitHub)

User profiles
  - View and edit own profile
  - View other users' public profiles

Notifications
  - In-app notifications
  - Optional: email/SMS/push notifications for important events

Search & discovery
  - Search for content by keyword
  - Optional: filters (by date, category, location)

Settings & preferences
  - Users can configure notification preferences
  - Users can delete their account (GDPR)

Admin / moderation
  - Report and flag content
  - Admin dashboard to review flagged content

Rate limiting
  - API endpoints are rate-limited per user / IP

Recurring Non-Functional Requirements

These appear in virtually every design. Know your numbers and state them with justification.

RequirementTypical valuesWhat to say in an interview
Availability99.9% (8.7 hr/yr downtime) to 99.99% (52 min/yr)"For a social app: 99.9%. For payments: 99.99%."
Read latency (P99)< 100ms for API responses, < 10ms for cache-backed reads"Reads under 100ms P99, served from cache wherever possible."
Write latency (P99)< 500ms for mutations"Writes async where possible; sync only for financial operations."
Durability99.999999999% (11 nines) for user data"User data must never be lost — replicated across 3+ AZs."
ConsistencyDepends on domain"Eventual for feeds/social; strong for inventory/payments/reservations."
ScalabilityHorizontal for stateless services"Stateless services scale horizontally behind a load balancer."
SecurityTLS, AuthN/AuthZ, rate limiting, audit logAlways mention these; they're table stakes.
ObservabilityMetrics, logs, traces, alerts"Every service emits latency/error metrics; structured logs to SIEM."

The Non-Functional That Defines the Design

Every system has one dominant non-functional requirement that forces the interesting design decisions. Identify it first.

Dominant NFRSystems that have itKey design consequence
Low read latencyURL shortener, DNS, CDNCache everything; serve from edge
High write throughputActivity feed, IoT sensors, ad clicksWide-column DB (Cassandra), log-based append
Strong consistencyPayments, inventory, reservationsDistributed transactions, two-phase commit, saga
Real-time deliveryChat, live comments, auctionsWebSocket/SSE, pub/sub, fan-out
Large media / storageYouTube, Dropbox, InstagramChunked upload, CDN, object storage
Geospatial queriesUber, Yelp, TinderGeohash/quadtree index
Ordering & fairnessAuction bidding, trading, schedulerSingle-node sequencer or distributed lock
Approximate counts at scaleYouTube Top K, ad analyticsCount-Min Sketch, HyperLogLog

Interview Delivery Framework (30-min format)

0-3 min   → Requirements: functional + non-functional (scale, latency, availability)
3-5 min   → Capacity estimation: QPS, storage, bandwidth
5-10 min  → High-level design: main components on a whiteboard
10-20 min → Deep dive: the 2-3 interesting design problems in this system
20-25 min → Security, failure modes, trade-offs
25-30 min → Questions / clarifications

Problem Index

Easy

TopicKey ConceptsFile
URL Shortener (Bitly)Hashing, redirect, key generation, cachingurl-shortener.md
File Storage (Dropbox)Chunked upload, dedup, sync, CDNfile-storage-dropbox.md
Local Delivery ServiceGeo-indexing, ETA, routinglocal-delivery-service.md
News AggregatorRSS/scraping, dedup, ranking, feednews-aggregator.md

Medium

TopicKey ConceptsFile
TicketmasterInventory lock, concurrency, seat reservationticketmaster.md
Facebook News FeedFan-out on write vs read, timeline, rankingnews-feed.md
TinderGeo-match, swipe, recommendation enginetinder.md
LeetCode (Judge)Code execution sandbox, queue, resultsleetcode-judge.md
WhatsApp (Chat)WebSocket, message delivery, E2E encryptionwhatsapp-chat.md
Yelp (Nearby Search)Geo-index, quadtree/geohash, reviewsyelp-nearby-search.md
Strava (Activity Tracking)GPS ingestion, segments, leaderboardsstrava.md
Distributed Rate LimiterToken bucket, sliding window, distributed countersrate-limiter.md
Online AuctionBidding, real-time updates, consistencyonline-auction.md
Facebook Live CommentsFan-out, real-time, pubsub, orderingfb-live-comments.md
Facebook Post SearchSearch index, ranking, freshnessfb-post-search.md
Price Tracking ServiceScraping, change detection, alertingprice-tracking.md

Hard

TopicKey ConceptsFile
InstagramMedia storage, feed, social graph scaleinstagram.md
YouTube Top KHeavy hitters, Count-Min Sketch, streamingyoutube-top-k.md
Uber (Ride Sharing)Location, dispatch, matching, ETAuber-ride-sharing.md
Robinhood (Trading)Order book, matching engine, real-time quotesrobinhood-trading.md
Google Docs (Collab Edit)OT/CRDT, conflict resolution, real-time syncgoogle-docs.md
Distributed CacheConsistent hashing, eviction, replicationdistributed-cache.md
YouTube (Video Platform)Transcoding pipeline, CDN, recommendationyoutube.md
Job SchedulerDAG, workers, retry, at-least-once deliveryjob-scheduler.md
Web CrawlerBFS/politeness, dedup, robots.txt, scaleweb-crawler.md
Ad Click AggregatorStream processing, exact vs approx countsad-click-aggregator.md
Payment SystemIdempotency, ledger, double-entry, sagapayment-system.md
Metrics MonitoringTime-series DB, aggregation, alertingmetrics-monitoring.md
ChatGPT (LLM API)Streaming inference, queuing, multi-tenantchatgpt-llm-api.md

Quick Concept Reference

Problem PatternKey TechniqueSystems
Fan-out writePrecompute feeds at write timeNews Feed, Instagram
Fan-out readCompute feed at read time (celebrities)Twitter (hybrid)
Inventory lockOptimistic locking / reservation TTLTicketmaster, Auction
Geo-proximityGeohash / QuadtreeUber, Yelp
Real-time pushWebSocket / SSE / Long-pollWhatsApp, Live Comments
Heavy hittersCount-Min Sketch, TopK heapYouTube Top K
DeduplicationBloom filter / hash fingerprintWeb Crawler, File Storage
Rate limitingToken bucket / Sliding windowRate Limiter, API GW
IdempotencyUnique request IDs + dedup tablePayments, Job Scheduler
Conflict resolutionOT / CRDTGoogle Docs
Time seriesRRD/TSDB, downsamplingMetrics Monitoring

Condensed Scenario Reference

One-line condensed summary for every scenario: the unique functional requirement, the dominant non-functional constraint, and the single most important design decision. Use this for rapid review.

Easy

ScenarioCore Functional (unique)Dominant NFRThe Key Design Decision
URL ShortenerCreate short code → redirectRead latency < 10ms; 115k redirects/sCounter + Base62 encoding for keys; cache all redirects in Redis (99% hit rate)
File Storage (Dropbox)Upload, sync, share files; delta syncDurability 11 nines; large file support (GBs)Chunk files (4MB blocks) + content-addressed dedup; CDN for downloads
Local Delivery ServiceMatch riders/drivers; ETA; routeLow latency geo-queries (<50ms)Geohash grid index in Redis; driver location updates every 5s
News AggregatorScrape RSS/web; dedup; rank; deliverFreshness (new articles within minutes)Crawler + message queue + dedup by URL hash + ranking by recency + engagement

Medium

ScenarioCore Functional (unique)Dominant NFRThe Key Design Decision
TicketmasterBrowse events; reserve seats; purchaseStrong consistency — no double-bookingOptimistic lock with reservation TTL (hold seat for 10 min, release if unpaid)
News FeedFollow users; see their posts in ranked orderFan-out scale for celebrity accountsPush (fan-out on write) for normal users; pull for celebrities with 1M+ followers
TinderSwipe left/right; match on mutual like; chatLow latency geo + preference matchingPrecompute candidate pool per user; geohash for local queries
LeetCode JudgeSubmit code; run against test cases; return resultsIsolation + fairness + sandboxingQueue submissions → isolated container per run (Docker/gVisor) → return results via WebSocket
WhatsApp ChatSend/receive messages; delivery + read receipts; group chatReal-time delivery; offline queuingWebSocket per connection; message store per conversation (Cassandra); fan-out to group members
Yelp Nearby SearchSearch businesses by location + filters + reviewsGeo-query latency < 50msGeohash or quadtree for spatial index; Elasticsearch for full-text + facets
StravaRecord GPS activities; segments; leaderboardsHigh write throughput (GPS points); ranking queriesTime-series DB for GPS points; precomputed segment efforts; Redis sorted set for leaderboard
Rate LimiterEnforce per-client request limits; 429 on exceedDecision latency < 5ms; distributed accuracySliding window counter in Redis (2 integers per client); fail open if Redis down
Online AuctionPlace bids; real-time current price; win at closeStrong consistency on bids; real-timeSerialized bid processing per auction; WebSocket for live price updates; auction close via cron
Facebook Live CommentsPost comments on live video; see others' comments in real-timeFan-out to millions of concurrent viewersPub/sub with SSE/WebSocket; comment fan-out via Kafka; read from cache (not DB)
Facebook Post SearchSearch posts by keyword; ranked by relevance + recencySearch freshness (new posts indexed quickly)Elasticsearch index; async indexer via Kafka consumes new posts; re-rank by social signals
Price TrackingTrack product prices across retailers; alert on price dropFreshness of prices (scrape frequency)Scheduler + scraper pool; store price history (TimescaleDB); alert via queue on threshold breach

Hard

ScenarioCore Functional (unique)Dominant NFRThe Key Design Decision
InstagramPost photos/videos; follow; feed; storiesScale: 500M DAU; read-heavy; large mediaObject storage (S3) + CDN; feed precomputed via fan-out on write; graph in separate service
YouTube Top KReturn top-K trending videos over a time windowApproximate counts at billion-event scaleCount-Min Sketch for frequency estimation; TopK heap for top results; aggregate per shard
Uber Ride SharingRequest ride; match driver; track; payReal-time geo matching < 1s; ETA accuracyDriver location in Redis geo index; matching via proximity search + availability; ETA from routing engine
Robinhood TradingPlace orders; order book; real-time quotesStrong ordering; no double-executionSingle-threaded matching engine per symbol; event sourcing for order book; WebSocket for live quotes
Google DocsMulti-user real-time editing; no conflictsConflict-free concurrent editsOperational Transformation (OT) or CRDT for merge; operational log per document; WebSocket sync
Distributed CacheGet/set/delete; eviction; consistent distributionConsistent key distribution across nodesConsistent hashing ring; virtual nodes for balance; LRU eviction; replication factor = 3
YouTube PlatformUpload video; transcode; stream; recommendationsHigh throughput transcoding; global CDN deliveryAsync transcode pipeline (queue + workers per format); HLS chunked streaming; CDN edge caching
Job SchedulerSchedule recurring and one-off jobs; retry on failureAt-least-once delivery; no double-executionDAG of tasks; worker pool with lease/heartbeat; idempotency key per job run; retry with backoff
Web CrawlerCrawl URLs; respect robots.txt; dedup; storePoliteness (don't hammer one domain); dedup at scaleBFS queue (Kafka); Bloom filter for visited URLs; domain-based rate limiting; distributed workers
Ad Click AggregatorCount clicks per ad per time window; query aggregatesEventual accuracy is fine; very high event rateStream processing (Flink/Spark); Count-Min Sketch for hot keys; pre-aggregate per 1-min window
Payment SystemDebit/credit accounts; ledger; idempotencyExactly-once, no double-charge; strong consistencyIdempotency key + dedup table; double-entry ledger; Saga pattern for multi-step transactions
Metrics MonitoringCollect metrics; aggregate; alert on thresholdHigh ingest throughput; efficient range queriesTime-series DB (InfluxDB/Prometheus); downsampling for long-term storage; alert engine with hysteresis
ChatGPT LLM APIAccept prompt; stream tokens back; multi-tenantHigh GPU cost; streaming response; queue fairnessRequest queue with priority tiers; GPU worker pool; Server-Sent Events (SSE) for streaming tokens

Core Concepts File

→ See foundations.md for: CAP theorem, consistency models, caching patterns, database selection, numbers to know, and the full delivery framework.