Foundations MOC
Date: 2026-08-16
Language-independent. If a note here would need rewriting because a framework updated, it’s in the wrong section.
Data and structure
- Data Structures — arrays, maps, sets, trees, graphs, and the operation each is fast at
- Time and Space Complexity — Big O as a tool for deciding, not as an interview ritual
- Sorting and Searching — the handful worth knowing, and why you’ll almost never write one
- Recursion — and when iteration is the honest choice
- Immutability — copying instead of mutating, and what it buys in reasoning and costs in memory
- Serialisation Formats — JSON, CSV, XML, protocol buffers: what each assumes about the reader
- Character Encoding — Unicode, UTF-8, and the precise reason emoji break string length
- Regular Expressions — the model, the syntax, and catastrophic backtracking
- State Machines — modelling a process by its legal states and transitions, which removes whole classes of bug
Memory and execution
- Memory Models — stack, heap, references, and what “pass by reference” actually means
- Garbage Collection — how memory is reclaimed, and the leaks that survive it
- Concurrency and Parallelism — the distinction, and why one thread can still do many things
- Async Models — callbacks, promises, futures, coroutines: the same problem solved differently
- Race Conditions — the shapes they take, and the ones that only appear under load
- Idempotency — an operation safe to repeat, and why every retryable system needs it
- Type Systems — static, dynamic, strong, weak, gradual, structural, nominal. Four axes usually confused for one
Networking
- How the Web Works — one request, end to end
- DNS — resolution, record types, TTLs, and why a change takes hours to appear
- TCP and UDP — reliability versus speed, and where each is chosen
- TLS and HTTPS — the handshake, certificates, and what encryption does and doesn’t protect
- HTTP Semantics — methods, status codes, headers, conditional requests
- HTTP Versions — 1.1, 2, 3: head-of-line blocking, multiplexing, and what each fixed
- Latency and Bandwidth — the two constraints, and why round trips dominate
- Content Delivery Networks — moving bytes closer, and the invalidation problem it creates
Data storage
- The Relational Model — tables, keys, relations, and why the model outlived every product built on it
- Normalisation — the forms, and the deliberate denormalisation that follows
- Indexing — how an index makes a query fast and a write slow
- Query Planning — reading an execution plan, which is the only way to know why a query is slow
- Transactions and ACID — atomicity, consistency, isolation, durability, and the isolation levels underneath
- N+1 Queries — the most common performance bug in application code
- SQL vs NoSQL — the access-pattern question that actually decides it
- Eventual Consistency — accepting temporary disagreement in exchange for availability
- CAP Theorem — the constraint, stated precisely rather than as a slogan
Security foundations
- Hashing — one-way functions, collisions, and why hashing isn’t encryption
- Encryption Basics — symmetric, asymmetric, and what each is for
- Authentication vs Authorisation — who you are versus what you may do
- Sessions and Tokens — server-side sessions, JWTs, and the tradeoffs each makes
- OAuth and OpenID Connect — delegated access, and the flows worth recognising
- Common Vulnerabilities — injection, XSS, CSRF, SSRF: the mechanism of each, not just the acronym
- Secrets Management — why a secret in a repo stays compromised after you delete it
Systems thinking
- Routing and Resolution — how a URL finds its code: the route table versus the content declaring its own type, and who ends up owning the URL space
- Coupling and Cohesion — the pair that explains most architecture arguments
- Libraries, Frameworks and Toolkits — inversion of control: who calls whom, what each label means, and what removing one costs
- Abstraction and Leaky Abstractions — what abstraction buys, and the reliable ways it fails
- Shims and Polyfills — standing in for something missing or inadequate, and why only one of the two is ever deletable
- Caching Strategies — where a copy may live, staleness, and invalidation as the hard half
- Backwards Compatibility — changing something everyone depends on, without breaking them
- Versioning — semantic versioning, and what it promises versus what it delivers
- Error Handling Strategies — fail fast, degrade gracefully, retry with backoff, and when each is right