Skip to content
Artwork for Software Engineer Interview Prep Podcast
Software Engineer Interview Prep Podcast · Yesterday · 27 min

How WebSockets Power the Real-Time Web

Why does a chat message arrive instantly, but the web was never built for it? In this deep dive we unpack WebSockets: how engineers turned a request/response web into an open, two-way line, and what that costs at scale. You'll learn: - Why short polling, long polling and Server-Sent Events fall short (and the math behind 200,000 empty requests per second) - How the WebSocket handshake hides inside a normal HTTP request, and the "cryptographic high-five" that proves the server understood - Why clients mask every frame but servers never do, and the cache-poisoning attack it prevents - Half-open connections, idle timeouts and why heartbeats every 20–30 seconds keep sockets alive - Close code 1006, the "ghost code" every system design candidate should know - The real cost of state: 1 million connections × 20 KB = 20 GB of RAM before a single message - Gateways, pub/sub buses, the thundering herd, and exponential backoff with full jitter - Cross-site WebSocket hijacking, and why tokens never belong in the URL - When NOT to use WebSockets: SSE vs WebSockets vs gRPC - Head-of-line blocking and why QUIC and WebTransport may be next Perfect for software engineers preparing for system design interviews. Chapters 00:00 Intro: the web wasn't built for real time 02:19 Short polling and the 200,000 requests/second problem 03:54 Long polling 04:42 Server-Sent Events 05:31 WebSockets and full-duplex communication 06:19 The handshake: disguised as HTTP 07:55 Sec-WebSocket-Accept: the cryptographic high-five 09:05 Why clients mask frames 09:53 Cache poisoning explained 11:50 Half-open connections 12:38 Idle timeouts at every network hop 13:47 Heartbeats: Ping and Pong 14:36 Close code 1006 15:23 The cost of state 16:57 Scaling with gateways and pub/sub 18:34 The thundering herd 19:46 Exponential backoff with full jitter 20:58 Cross-site WebSocket hijacking 22:32 Ticket-based authentication 23:45 When not to use WebSockets 24:55 The big trade-off: latency vs statefulness 25:43 Head-of-line blocking 26:55 What's next: QUIC and WebTransport #SystemDesign #WebSockets #SoftwareEngineering #InterviewPrep #BackendEngineering Interview Prep Podcast

0:00-27:32

transcript

No transcript — this publisher did not publish one.

show notes

Why does a chat message arrive instantly, but the web was never built for it? In this deep dive we unpack WebSockets: how engineers turned a request/response web into an open, two-way line, and what that costs at scale.


You'll learn:

- Why short polling, long polling and Server-Sent Events fall short (and the math behind 200,000 empty requests per second)

- How the WebSocket handshake hides inside a normal HTTP request, and the "cryptographic high-five" that proves the server understood

- Why clients mask every frame but servers never do, and the cache-poisoning attack it prevents

- Half-open connections, idle timeouts and why heartbeats every 20–30 seconds keep sockets alive

- Close code 1006, the "ghost code" every system design candidate should know

- The real cost of state: 1 million connections × 20 KB = 20 GB of RAM before a single message

- Gateways, pub/sub buses, the thundering herd, and exponential backoff with full jitter

- Cross-site WebSocket hijacking, and why tokens never belong in the URL

- When NOT to use WebSockets: SSE vs WebSockets vs gRPC

- Head-of-line blocking and why QUIC and WebTransport may be next


Perfect for software engineers preparing for system design interviews.


Chapters

00:00 Intro: the web wasn't built for real time

02:19 Short polling and the 200,000 requests/second problem

03:54 Long polling

04:42 Server-Sent Events

05:31 WebSockets and full-duplex communication

06:19 The handshake: disguised as HTTP

07:55 Sec-WebSocket-Accept: the cryptographic high-five

09:05 Why clients mask frames

09:53 Cache poisoning explained

11:50 Half-open connections

12:38 Idle timeouts at every network hop

13:47 Heartbeats: Ping and Pong

14:36 Close code 1006

15:23 The cost of state

16:57 Scaling with gateways and pub/sub

18:34 The thundering herd

19:46 Exponential backoff with full jitter

20:58 Cross-site WebSocket hijacking

22:32 Ticket-based authentication

23:45 When not to use WebSockets

24:55 The big trade-off: latency vs statefulness

25:43 Head-of-line blocking

26:55 What's next: QUIC and WebTransport


#SystemDesign #WebSockets #SoftwareEngineering #InterviewPrep #BackendEngineering


Interview Prep Podcast