whatis least-privilege
Principle of Least Privilege
Also known as: least privilege, PoLP
The security practice of giving every user, service, and program only the permissions it needs to do its job, and nothing more.
What Is the Principle of Least Privilege?
On Linux this means running services under dedicated unprivileged accounts, avoiding root logins, limiting sudo rules, tightening file permissions, and confining processes with systemd sandboxing, SELinux, or AppArmor.
When something is compromised, least privilege limits what the attacker can reach. A web app running as www-data cannot read /etc/shadow; one running as root can.
Example
[Service]
User=app
NoNewPrivileges=true
ProtectSystem=strict Learn more about Principle of Least Privilege
- Linux Security Best Practices A practical security checklist for Linux systems -- covering user privileges, SSH hardening, firewall setup, automatic updates, file integrity monitoring, and auditing tools like Lynis.
- Hardening systemd Services: The Directives That Actually Confine ProtectSystem, PrivateTmp, NoNewPrivileges, and the rest, what each one blocks, and how to use systemd-analyze security to find out how exposed your services are right now.
- The First Ten Minutes on a New Linux Server A fresh VPS is reachable from the entire internet within seconds of provisioning. Here is the short, ordered list of things to do before you install anything else.
Related tools
- systemd Unit Builder Generate systemd service files with restart policies, dependencies, and sandboxing options.