Skip to main content
Principle of least privilege

Principle of least privilege

Search complete. 24 mentions across 7 episodes found for "Principle of least privilege".

Sep 17, 2026

Sec GuyHOST
5:45
The cryptographic proof eliminates plausible deniability.
Sec GuyHOST
5:49
This brings us to our core operating doctrine, least privilege.
Sec GuyHOST
5:53
Lease privilege dictates that every user, application, and service account must operate with only the minimum permissions necessary to complete their job and strictly for the time needed.
Sec GuyHOST
6:05
If a junior analyst only needs read-only access to customer support tickets, granting them database administrator privileges is an architectural defect.
Sec GuyHOST
1:56
Because that instance had an IAM role with a policy that was too broad, the attacker was able to use the server's own identity to steal an API key from the metadata service.
Sec GuyHOST
2:07
This is why we follow the principle of least privilege.
Sec GuyHOST
2:11
Your policies should never use a wildcard asterisk to grant all permissions.
Sec GuyHOST
2:16
They should be granular.
Sec GuyHOST
4:47
They will show up on the test.
Sec GuyHOST
4:50
And the foundation, principle of least privilege.
Sec GuyHOST
4:54
Least privilege means giving users only the permissions they need to do their job, nothing extra.
Sec GuyHOST
5:00
This minimizes damage from mistakes or compromised accounts.
W. Curtis PrestonHOST
0:10
That cost them 400,000 euros in fines.
W. Curtis PrestonHOST
0:13
And when they appealed, the court basically said they didn't even try the concept of least privilege.
W. Curtis PrestonHOST
0:20
Today, that's what we're talking about.
W. Curtis PrestonHOST
0:21
Least privilege, best practices.
W. Curtis PrestonHOST
0:24
What does that mean exactly? And also, where do you start when everybody already has domain admin? Finally, we talk about role-based administration and why that's really the only realistic path here.
W. Curtis PrestonHOST
0:37
We talk about privileged account inventories, fire call accounts, segregation of duties, non-repudiation, and three backup roles that you should split apart before somebody quietly deletes your backup configuration.
W. Curtis PrestonHOST
4:53
My God, we've already spent 20 minutes on this.
W. Curtis PrestonHOST
4:56
So let's go.
Jason ElrodGUEST
8:20
So this is why it's essential that we give AI, especially ag- agents, their own identity.
Jason ElrodGUEST
8:28
That way, we can assign least privilege, ba- basically the minimum permissions necessary.
Jason ElrodGUEST
8:33
Segmentation is intensely important here, so only in the environments required for its function.
Jason ElrodGUEST
8:40
And I mentioned identity.

9 MINS LATER

Erica Spicer-MasonHOST
17:26
But I wanna give our, our listeners just kind of a forward-looking view of, uh, where this approach that we've talked today, whether that's segmentations, creating, you know, constrained or contained environments, w- where might that approach stop helping, and what risks would you leave listeners with to consider even after they've achieved the constrained access and segmentation?
Jason ElrodGUEST
17:50
Segmentation's critical, right? We, we've already mentioned that.
Jason ElrodGUEST
17:52
Least privilege, again, also helps dramatically reduce risk.
Jason ElrodGUEST
17:56
So segmentation and least privilege dramatically reduces risk.
Benny PoratGUEST
3:59
We need to make sure to deliver access to the business.
Benny PoratGUEST
4:02
But in the same time, we need, of course, to make sure for security perspective, to have least privilege.
Benny PoratGUEST
4:08
But at the same time, we are so lack of context.
Benny PoratGUEST
4:12
At the end, we are not running the business.

18 MINS LATER

Benny PoratGUEST
22:34
It don't know what it's going to use.
Benny PoratGUEST
22:37
So for sure, you actually want to restrict it.
Benny PoratGUEST
22:40
You want to start and just give it the minimum, the least privilege as possible.
Benny PoratGUEST
22:45
And least privilege is difficult.
Rob AllenGUEST
17:43
It's like, where does it, where do you draw, where do you draw the line? Where does it draw the line? Um, but yeah, as I said, sensible guardrails external to the thing itself, I think.
Rob AllenGUEST
17:53
Uh, I mean, it'll, it's, it's effectively the principle of least privilege, which is realistically best practices, or best practice for all security, you could argue.
Rob AllenGUEST
18:03
This is just another layer.
Tyler ShieldsHOST
18:04
Yeah.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.