Access control and least privilege · การควบคุมการเข้าถึงและสิทธิ์ขั้นต่ำ
Least privilege
- A core security rule: give every person and program only the access they need — no more.
- If an account is broken into, least privilege means the attacker can reach less.
สิทธิ์ต่ำสุด (Least privilege)
- กฎความปลอดภัยพื้นฐาน: ให้บุคคลและโปรแกรมทุกตัวมี สิทธิ์เข้าถึงเท่าที่จำเป็น เท่านั้น — ไม่เกินกว่านั้น
- หากบัญชีถูกเจาะทะลุ หลักสิทธิ์ต่ำสุดหมายถึงผู้โจมตีจะเข้าถึงข้อมูลได้ น้อยลง
Access control on files
- On Linux, file permissions are access control in action (you met these in the Linux course).
ls -lshows who can read, write, and execute, for the owner, the group, and everyone else.
การควบคุมการเข้าถึงไฟล์
- ในระบบ Linux, อนุญาตให้ทำรายการ (permissions) คือการควบคุมการเข้าถึงในทางปฏิบัติ (คุณเคยรู้จักสิ่งเหล่านี้ในรายวิชา Linux แล้ว)
ls -lแสดงให้เห็นว่าใครสามารถ อ่าน (r), เขียน (w) และ ดำเนินการ (e) สำหรับเจ้าของกลุ่ม และทุกคน其余
ls -l secret.txt
Locking down a secret
- A file holding a password or key should be readable by its owner only.
chmod 600gives the owner read+write, and nothing to anyone else:
6= read+write for the owner;0and0= no access for group and others.
การปิดล็อกความลับ
- ไฟล์ที่เก็บรหัสผ่านหรือคีย์ควรถูกอ่านได้โดย เจ้าของไฟล์เท่านั้น
chmod 600ให้สิทธิ์เจ้าของไฟล์อ่าน+เขียน และมี ไม่มีอะไรเลย ให้กับผู้อื่น:
chmod 600 secret.txt
6= อ่าน+เขียนสำหรับเจ้าของ;0และ0= ไม่มีการเข้าถึงสำหรับกลุ่มและผู้อื่น
Your turn
- Lock down
secret.txtso only its owner can touch it. Good permissions are a simple, powerful defence.
Covers: A-Level 6.1 (access levels / security measures).
ถึงเวลาฝึกฝน
- ปิดล็อก
secret.txtเพื่อให้เฉพาะเจ้าของไฟล์เท่านั้นที่สัมผัสได้สิทธิ์ที่ดีเป็นเกราะป้องกันที่เรียบง่ายแต่ทรงพลัง
*ครอบคลุม: A-Level 6.1 (ระดับการเข้าถึง/มาตรการความปลอดภัย)
Common mistakes
- Give each user only the access they need (least privilege).
- Do not use an administrator account for everyday work.
ข้อผิดพลาดที่พบบ่อย
- ให้แต่ละผู้ใช้มีสิทธิ์เข้าถึงเท่าที่จำเป็น (สิทธิ์ต่ำสุด)
- อย่าใช้บัญชีผู้ดูแลระบบสำหรับการทำงานประจำวัน
Least privilege · สิทธิ์ขั้นต่ำ
Give each user only the rwx they need — nothing more. · มอบ rwx ให้แต่ละผู้ใช้เท่าที่จำเป็น — ไม่มากกว่านั้น
secret.txt is currently readable by everyone. Lock it down so only its owner can read and write it, with chmod 600 secret.txt. The check shows ls -l. · secret.txt ปัจจุบันอ่านได้โดยทุกคน. ล็อคมันให้ เจ้าของไฟล์เท่านั้น อ่านและเขียนได้ โดยใช้ chmod 600 secret.txt. การตรวจสอบแสดง ls -l
Least privilege is not always 600. Your team should read team-notes.txt, but not change it — and outsiders get nothing. Use chmod 640 team-notes.txt (6 = owner read+write, 4 = group read-only, 0 = others none). · สิทธิ์ขั้นต่ำไม่ใช่ 600 เสมอไป. ทีมของคุณควร อ่าน team-notes.txt, แต่ไม่แก้ไข — และบุคคลภายนอกไม่มีสิทธิ์. ใช้ chmod 640 team-notes.txt (6 = เจ้าของอ่าน+เขียน, 4 = กลุ่มอ่านอย่างเดียว, 0 = คนอื่นไม่มีอะไร).