Safety risk
Tripping over a cable, electrocution, fire.
This chapter looks at physical safety when using computer equipment, e-safety and data security. It also covers common threats such as hacking, phishing and malware, together with ways of protecting data.
Use these links to move directly to each part of Chapter 8.
Physical safety is concerned with dangers from computer equipment that could cause serious injury or even loss of life. This is different from the health problems covered in Chapter 5.
| Safety risk | Possible cause | Ways to reduce the risk |
|---|---|---|
| Electrocution | Damaged wires, liquids near electrical equipment | Check cables regularly, keep drinks away, use safe electrical equipment |
| Fire | Overloaded sockets, overheating, short circuits | Avoid overloaded sockets, keep ventilation holes clear, ensure good ventilation |
| Tripping | Loose/trailing cables | Use cable ducts, keep cables away from walkways |
| Personal injury | Heavy equipment falling from desks | Use strong, suitable desks and keep equipment away from edges |
Students should not confuse the two:
Tripping over a cable, electrocution, fire.
RSI, eyestrain, headaches, back/neck strain.
E-safety means the safe and responsible use of technology. It involves both electronic security and the way users behave when using ICT.
Most countries have some form of Data Protection Act (DPA).
Data protection legislation is designed to:
It applies to both computerised and paper records.
Important principles include:
Simple precautions include:
Personal data is information that can be used to identify a living person.
Sensitive personal data requires extra protection.
Important precautions include:
When using email:
When using social networking sites:
Online gaming can expose users to:
Data stored on computers or transmitted over networks can face several security threats.
The main threats covered are:
Hacking is gaining unauthorised or illegal access to a computer system.
Phishing uses fake but legitimate-looking emails to trick users into giving away personal information.
A phishing email may:
This can lead to fraud or identity theft.
Smishing = SMS phishing.
Fake text messages are sent to a mobile phone asking the user to:
Vishing = voicemail/voice phishing.
A user receives a voice message or call designed to trick them into giving personal information while believing they are communicating with a genuine organisation.
| Threat | Method |
|---|---|
| Phishing | |
| Smishing | SMS/text message |
| Vishing | Voice/telephone |
Pharming uses malicious code to redirect a user to a fake website without their knowledge.
Unlike phishing, the user does not necessarily need to click a fraudulent email link.
| Phishing | Pharming |
|---|---|
| Usually uses a fake email/message | Uses malicious code |
| User is persuaded to follow a link or give data | User is automatically redirected |
| Relies heavily on tricking the user | Can happen without the user knowingly taking action |
Malware means malicious software designed to damage a system, steal information or interfere with computer operation.
A virus is program code that can copy itself and is intended to damage files or cause a computer to malfunction.
A virus needs an active host/program or trigger to run.
A worm can copy itself and spread across networks.
Unlike a virus, it does not need a user to run an infected host program before it can spread.
Worms can therefore spread quickly between computers and may infect an entire network.
A Trojan horse is malicious software disguised as legitimate software. The user is tricked into running it.
Once installed, it may:
Key logging software records the keys a user presses.
It may capture:
The recorded data can then be sent to a cybercriminal. Anti-spyware software can help detect and remove key loggers.
Adware floods users with unwanted advertisements.
It may:
Ransomware encrypts or locks a user's data and demands payment to restore access.
Regular backups are particularly important because they can reduce the need to pay a ransom if files become inaccessible.
| Virus | Worm |
|---|---|
| Needs a host/trigger | Stand-alone |
| User action may be required | Can spread automatically |
| Can damage files | Can spread rapidly across networks |
Card fraud is the illegal use of a credit or debit card.
Methods covered include:
This involves obtaining information by watching or listening while someone enters or gives sensitive details.
For example, someone may:
Card cloning involves copying data from a payment card.
A skimmer can copy information from a magnetic stripe.
Criminals may combine this with shoulder surfing to obtain the PIN and create a fake card.
The chapter covers several methods:
Biometric authentication identifies a person using unique physical characteristics.
The scanned fingerprint is compared with one stored in a database.
Software measures facial features such as:
These measurements are compared with stored values. Changes in appearance or lighting can reduce accuracy.
A digital certificate helps prove that data or a message comes from a trusted source.
It uses:
Information in a certificate can include:
SSL (Secure Sockets Layer) is a protocol that allows information to be transmitted securely over the internet.
SSL encrypts data being transferred between the user's computer and the web server.
Encryption converts readable data into a form that cannot easily be understood without the correct key.
Encryption is useful for:
A firewall can be hardware or software placed between a computer/network and an external network such as the internet.
The firewall monitors incoming and outgoing traffic. It can:
Authentication means proving who a user is.
Authentication can be based on:
Two-factor authentication (2FA) uses two different authentication methods.
A user ID identifies the user, while the password helps prove that they are authorised to access the system.
A strong password should be difficult to guess. The book recommends including:
Passwords should also:
| Threat | What happens |
|---|---|
| Phishing | Fake email tries to obtain data |
| Smishing | Fake SMS/text message tries to obtain data |
| Vishing | Fake voice/telephone message tries to obtain data |
| Pharming | User is redirected to a fake website |
| Malware | Main idea |
|---|---|
| Virus | Copies itself and damages files; needs a host/trigger |
| Worm | Spreads automatically across networks |
| Trojan horse | Malicious program disguised as legitimate software |
| Spyware/key logger | Secretly collects user information |
| Adware | Displays unwanted advertising |
| Ransomware | Encrypts/locks data and demands payment |
This summary follows the malware distinctions given in the chapter.
Students should be able to: