Skip to main content
system design course

Security

Proving who someone is, keeping the connection private, and the mistakes that undo both.

4 chapters16 lessonsabout 1 hour
0 of 16 lessons readStart the course
  1. TLS encrypts data in transit; HTTPS is HTTP over TLS.

    1. What TLS Protects Against2 min
    2. The TLS 1.3 Handshake2 min
    3. Certificates and the Chain of Trust3 min
    4. TLS Termination in Real Architectures2 min
  2. Stateless, self-contained tokens that carry signed claims, no server-side session lookup needed.

    1. Anatomy of a JWT2 min
    2. Signing and Verification3 min
    3. The Revocation Problem2 min
    4. JWT Mistakes That Get Exploited3 min
  3. OAuth delegates authorization (can App X access resource Y); OIDC adds authentication on top.

    1. The Delegation Problem2 min
    2. The Authorization Code Flow2 min
    3. The Tokens Involved2 min
    4. OIDC: Authentication on Top3 min
  4. Stateful sessions stored server-side vs stateless tokens carried by the client.

    1. Server-Side Sessions3 min
    2. Stateless Tokens2 min
    3. The Hybrid Reality2 min
    4. CSRF and Storage Pitfalls3 min