Access control and least privilege · アクセス制御と最小権限
Least privilege
- A core security rule: give every person and program only the access they need — no more.
- If an account is broken into, least privilege means the attacker can reach less.
最小権限
- 基本的なセキュリティ原則:すべての人およびプログラムに必要なアクセスのみを与え、それ以上は与えません。
- アカウントが乗っ取られた場合、最小権限により攻撃者が到達できる範囲は少なくなります。
Access control on files
- On Linux, file permissions are access control in action (you met these in the Linux course).
ls -lshows who can read, write, and execute, for the owner, the group, and everyone else.
ファイルにおけるアクセス制御
- Linuxにおいて、ファイルの権限はアクセス制御の具体例です(Linuxコースで触れたことがあります)。
ls -lは所有者、グループ、その他すべての人が read(読み取り)、write(書き込み)、execute(実行)できるかを示しています。
ls -l secret.txt
Locking down a secret
- A file holding a password or key should be readable by its owner only.
chmod 600gives the owner read+write, and nothing to anyone else:
6= read+write for the owner;0and0= no access for group and others.
シークレットのロックダウン
- パスワードや鍵を含むファイルはその所有者のみが読み取り可能にするべきです。
chmod 600は所有者に読み取り+書き込みを与え、他者には一切与えません:
chmod 600 secret.txt
6= 所有者の読み取り+書き込み;0と0= グループおよび他者のアクセスなし。
Your turn
- Lock down
secret.txtso only its owner can touch it. Good permissions are a simple, powerful defence.
Covers: A-Level 6.1 (access levels / security measures).
実践
secret.txtをロックダウンし、所有者のみがアクセスできるようにします。適切な権限設定は、単純でありながら強力な防御手段です。
対象:A-Level 6.1(アクセスレベル / セキュリティ対策)。
Common mistakes
- Give each user only the access they need (least privilege).
- Do not use an administrator account for everyday work.
よくあるミス
- 各ユーザーに必要なアクセスのみを与える(最小権限)。
- 日常業務で管理者アカウントを使用しないでください。
Least privilege · 最小権限
Give each user only the rwx they need — nothing more. · 各ユーザーに必要なrwxのみを与え、それ以上は与えないでください。
secret.txt is currently readable by everyone. Lock it down so only its owner can read and write it, with chmod 600 secret.txt. The check shows ls -l. · secret.txtは現在すべての人が読み書きできます。chmod 600 secret.txtを使用して所有者のみが読み書きできるように制限してください。チェック結果はls -lになります。
Least privilege is not always 600. Your team should read team-notes.txt, but not change it — and outsiders get nothing. Use chmod 640 team-notes.txt (6 = owner read+write, 4 = group read-only, 0 = others none). · 最小権限が常に600とは限りません。チームメンバーはteam-notes.txtを読みて変更してはいけませんが、外部者はアクセスできません。chmod 640 team-notes.txt (6 = 所有者の読み書き、4 = グループの読み取り専用、0 = その他なし) を使用してください。