Access control and least privilege · בקרת גישה ומינימום זכויות
Least privilege
- A core security rule: give every person and program only the access they need — no more.
- If an account is broken into, least privilege means the attacker can reach less.
זכויות מינימליות
- כלל אבטחה בסיסי: תן לכל אדם ותוכנה רק את הגישה שהם צריכים - לא יותר.
- אם חשבון נפרץ, עקרון הזכויות המינימליות פירושו שהתוקף יגיע לפחות.
Access control on files
- On Linux, file permissions are access control in action (you met these in the Linux course).
ls -lshows who can read, write, and execute, for the owner, the group, and everyone else.
בקרת גישה לקבצים
- ב-Linux, רשיונות קובץ הם ביצוע בפועל של בקרת גישה (פגשת אותם בקורס Linux).
ls -lמראה מי יכול read (לקרוא), write (לכתוב) ו execute (לבצע), עבור בעל הקובץ, הקבוצה ואנשים אחרים.
ls -l secret.txt
Locking down a secret
- A file holding a password or key should be readable by its owner only.
chmod 600gives the owner read+write, and nothing to anyone else:
6= read+write for the owner;0and0= no access for group and others.
סגירת סוד
- קובץ המכיל סיסמה או מפתח אמור להיות קריא רק על ידי בעלו.
chmod 600נותן לבעל קריאה+כתיבה, ושום דבר לאחרים:
chmod 600 secret.txt
6= קריאה+כתיבה עבור הבעל;0ו0= אין גישה לקבוצה ולאנשים אחרים.
Your turn
- Lock down
secret.txtso only its owner can touch it. Good permissions are a simple, powerful defence.
Covers: A-Level 6.1 (access levels / security measures).
תורך
- נעל את
secret.txtכך שרק בעלו יוכל לגעת בו. רשיונות טובים הם הגנה פשוטה וחזקה.
מכסה: A-Level 6.1 (רמות גישה / אמצעי אבטחה).
Common mistakes
- Give each user only the access they need (least privilege).
- Do not use an administrator account for everyday work.
טעויות נפוצות
- תן למשתמש כל אחד רק את הגישה שהוא צריך (זכויות מינימליות).
- אל תשתמש בחשבון מנהל לעבודה יומיומית.
Least privilege · מינימום זכויות
Give each user only the rwx they need — nothing more. · תן למשתמש כל אחד רק את rwx שהוא צריך – לא יותר.
secret.txt is currently readable by everyone. Lock it down so only its owner can read and write it, with chmod 600 secret.txt. The check shows ls -l. · secret.txt נמצא כרגע בקריאה לכל אחד. נעל אותו כך שרק בעליו יוכל לקרוא ולכתוב בו, באמצעות chmod 600 secret.txt. הבדיקה מראה ls -l.
Least privilege is not always 600. Your team should read team-notes.txt, but not change it — and outsiders get nothing. Use chmod 640 team-notes.txt (6 = owner read+write, 4 = group read-only, 0 = others none). · מינימום זכויות אינו תמיד 600. הצוות שלך צריך לקרוא לteam-notes.txt, אך לא לשנות אותו – ואנשים חיצוניים לא יקבלו כלום. השתמש בchmod 640 team-notes.txt (6 = קריאה+כתיבה לבעלים, 4 = קריאה בלבד לקבוצה, 0 = אין כלום לאחרים).