We are independent & ad-supported. We may earn a commission for purchases made through our links.
Advertiser Disclosure
Our website is an independent, advertising-supported platform. We provide our content free of charge to our readers, and to keep it that way, we rely on revenue generated through advertisements and affiliate partnerships. This means that when you click on certain links on our site and make a purchase, we may earn a commission. Learn more.
How We Make Money
We sustain our operations through affiliate commissions and advertising. If you click on an affiliate link and make a purchase, we may receive a commission from the merchant at no additional cost to you. We also display advertisements on our website, which help generate revenue to support our work and keep our content free for readers. Our editorial team operates independently of our advertising and affiliate partnerships to ensure that our content remains unbiased and focused on providing you with the best information and recommendations based on thorough research and honest evaluations. To remain transparent, we’ve provided a list of our current affiliate partners here.
Internet

Our Promise to you

Founded in 2002, our company has been a trusted resource for readers seeking informative and engaging content. Our dedication to quality remains unwavering—and will never change. We follow a strict editorial policy, ensuring that our content is authored by highly qualified professionals and edited by subject matter experts. This guarantees that everything we publish is objective, accurate, and trustworthy.

Over the years, we've refined our approach to cover a wide range of topics, providing readers with reliable and practical advice to enhance their knowledge and skills. That's why millions of readers turn to us each year. Join us in celebrating the joy of learning, guided by standards you can trust.

What Is Privilege Separation?

Mary McMahon
By
Updated: May 17, 2024
Views: 4,760
References
Share

Privilege separation is a computer security technique that breaks programs up by privileges needed to perform operations to limit access to more sensitive areas. This can be structured natively into an operating system or computer program, or it can also be programmed in, depending on the level of complexity. This is one among many tactics that can prevent external attacks and also minimize the amount of damage caused by such attacks by limiting their penetration into the system.

For computer security reasons, users of computers usually must register or work under a guest account. This allows the computer to assign privileges based on the account level. A guest user might be able to perform basic read and write functions, but no system changes. An administrator account could perform system changes and other significant actions. In privilege separation, different functionalities are kept separate to isolate high security areas.

Programmers can accomplish privilege separation by separating out program processes into privileged and unprivileged categories. All users can access the unprivileged section, but users without privileges cannot go into the other parts of the program. If a hack or virus attempts to attack the program, it may be able to operate freely in the unprivileged segments, but it cannot cross the divide to the privileged areas. Meanwhile, privileged users can communicate back and forth between the segments as necessary.

In computer security, the goal is usually to minimize the amount of time administrative accounts need to be in use. Such accounts can be vulnerable to exploit, and if someone uses them to perform routine, unprivileged tasks, it can create a security hole. One benefit of privilege separation is better distancing, to make such accounts less tempting targets. Administrators can also issue fewer of these accounts because users will not need them to perform low-level activities, and this increases the security of the system by limiting the number of vulnerable accounts.

Information technology personnel can program databases and systems with built-in privilege separation, and they can also encourage employers to adopt programs with this security measure already in place. This, in combination with controlling the types of user accounts issued, can help make a system more secure. It is also important for users to exercise basic precautions like regularly checking passwords, not leaving their computers logged in when they are away from the desk, and shutting down their computers at night unless directed to do otherwise for maintenance and other activities.

Share
WiseGeek is dedicated to providing accurate and trustworthy information. We carefully select reputable sources and employ a rigorous fact-checking process to maintain the highest standards. To learn more about our commitment to accuracy, read our editorial process.
Link to Sources
Mary McMahon
By Mary McMahon

Ever since she began contributing to the site several years ago, Mary has embraced the exciting challenge of being a WiseGeek researcher and writer. Mary has a liberal arts degree from Goddard College and spends her free time reading, cooking, and exploring the great outdoors.

Editors' Picks

Discussion Comments
Mary McMahon
Mary McMahon

Ever since she began contributing to the site several years ago, Mary has embraced the exciting challenge of being a...

Learn more
Share
https://www.wisegeek.net/what-is-privilege-separation.htm
Copy this link
WiseGeek, in your inbox

Our latest articles, guides, and more, delivered daily.

WiseGeek, in your inbox

Our latest articles, guides, and more, delivered daily.