Security Notes
System Design

Design Facebook Live Comments

3 min read 6 sections

DifficultyMedium | HelloInterview: problem breakdown


Problem Statement

Design a real-time comment system for live video streams. Millions of viewers can comment simultaneously; all viewers should see comments in near-real-time.

๐Ÿ“–

Real-world: This is a massive fan-out problem: one comment must reach millions of concurrent viewers in near-real-time, which is the inverse of chat (few recipients, guaranteed delivery) โ€” here you have enormous recipients but can tolerate dropping/coalescing some comments (nobody reads all 50,000 comments/second on a viral stream anyway). So the design leans on pub/sub broadcast over WebSocket/SSE, reading from a cache rather than the database, and often sampling or rate-limiting what's displayed. The hard, underappreciated layer for a security audience is real-time moderation at scale: live comments are a firehose of potential spam, harassment, hate speech, and scams, and unlike a stored post you can't review before publishing โ€” so you need inline automated moderation (ML classifiers, slur filters, rate limits per user) running in the fan-out path itself. "How do you moderate a million comments a minute in real time?" is the question that separates a complete answer from a naive one.


Requirements

Functional

  • Post a comment on a live stream
  • All viewers see new comments in near-real-time (< 2s)
  • Comment feed is paginated (most recent N comments visible)
  • Comment count displayed live
  • Moderation: hide/remove comments

Non-Functional

  • Viral stream: 1M concurrent viewers, 1k comments/s
  • Comment delivery latency: < 2s
  • Not necessary for every viewer to see every comment (sampling acceptable for very high rate)

Core Design

Fan-Out at 1M Viewers

The core problem: 1 comment posted โ†’ deliver to 1M viewers. Classic fan-out challenge.

Can't do direct WebSocket fan-outpushing to 1M WebSocket connections from a single app server is not feasible.

Solution: Pub/Sub at scale

Comment Posted โ†’ Kafka (topic: comments:{stream_id})
                      โ†“
            Comment Server cluster (each server handles N viewers)
                      โ†“
                  Each server subscribes to Kafka topic
                  โ†’ pushes to its connected WebSocket clients

Each comment server handles ~50k WebSocket connections. For 1M viewers: ~20 comment servers. Each subscribes to the same Kafka topic. Kafka delivers each message to every server (broadcast). Each server fans out to its 50k clients.

Comment Sampling for High Rate

At 1k comments/s with 1M viewers, no viewer can read every comment. Sample:

  • Show at most 5-10 comments per second in the UI
  • Server samples 1/10 of comments for broadcast; store all in DB
  • UI smoothly streams the sampled comments

Comment Storage

Cassandra:
  comments(
    stream_id   UUID,
    comment_id  TIMEUUID,  -- auto-sorted by time
    user_id     UUID,
    content     TEXT,
    status      ENUM('visible','hidden','deleted')
    PRIMARY KEY (stream_id, comment_id DESC)
  )

Architecture

Viewer (WebSocket) โ†โ†’ Comment Server (one of 20) โ† Kafka โ† Comment API
                                                      โ†“
                                             Comment DB (Cassandra)
                                                      โ†“
                                             Moderation Service (ML + human queue)

Security Considerations

ThreatMitigation
Comment spam / floodRate limit per user (5 comments/sec); CAPTCHA on suspicious velocity
Harassment / hate speechML classifier (pre-publish); keyword filter; report+hide flow
Bot commentsAccount age check; behavior analysis
WebSocket DoSMax connections per IP; token auth before upgrade

Interview Tips

Kafka as pub/sub broadcast

is the key architectural decision โ€” enables each comment server to receive every comment without coordination.

Sampling

is a product-aware answer โ€” shows you understand that showing every comment in a 1k/s stream is visually useless.

Scale the fan-out math

1M viewers รท 50k per server = 20 servers ร— comment rate = each server handles the broadcast independently.