How would you rate-limit OTP sends for an Indian login flow without locking out a shared NAT?
PICTURE THIS: HOW TO EXPLAIN IT
Simple meaning
Cap per phone number strictly, and cap per IP more loosely because offices and mobile NATs share addresses.
WHY — Rate limiting instead of guessing?
Why interviewers care about Rate limiting:
question about Rate limiting.
trade-offs, and what you would actually do on a Backend project - not buzzwords.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1Cap per phone number
strictly, and cap per IP more loosely because offices and mobile NATs share addresses.
- 2Use Redis sliding windows,
exponential backoff after failures, and never reveal whether a number is registered.
- 3Couple this with device
signals so attackers cannot rotate IPs against one MSISDN.
- 4Give an example
One tiny concrete case you can say aloud.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
Cap per phone number strictly, and cap per IP more loosely because offices and mobile NATs share addresses. Use Redis sliding windows, exponential backoff after failures, and never reveal whether a number is registered.