Design an Authentication System
Problem Design the system behind a login page: user signup and login, credential storage, and session management.
Functional requirements
- Sign up with email/password; verify the email.
- Log in and receive a session credential.
- Log out; invalidate the session (single device and all devices).
- Reset a forgotten password.
- Protect against brute-force and credential-stuffing attacks.
Non-functional requirements
- ~50M registered users; ~5M logins/day -> ~60/sec average, ~500/sec at morning peak.
- Login p99 < 500 ms — dominated deliberately by the password hash, which must be slow.
- Password hashing tuned to ~100-250 ms per verification (bcrypt cost ~12, or argon2id at ~64 MB). At 500 logins/sec that is a real capacity input (~50-125 CPU-seconds/sec), so size the auth tier accordingly.
- Session validation runs on every authenticated request: ~50k QPS, p99 < 10 ms.
- 99.99% availability — if auth is down, the entire product is down.
Areas to go deep
- Credential storage and the choice of password KDF.
- Session strategy: server-side sessions vs JWTs and revocation.
- Brute-force mitigation without creating a DoS vector; enumeration/timing attacks; cookie flags; password-reset safety.
asked …