Welcome to Topic 3: Operating Online

In today's world, we spend a lot of time connected to the internet. Whether you are gaming, shopping, or chatting with friends, you are constantly sending and receiving data. While the internet is amazing, it also comes with certain "digital dangers." In this chapter, we will explore the risks to your data and the clever ways we can protect ourselves. Don't worry if it sounds technical—we will break it down step-by-step!

1. Risks to Your Data and Information

Before we can defend ourselves, we need to know what we are up against. Here are the main threats you need to know for your exam:

Unauthorised Access

This is often called hacking. It happens when someone gains access to your computer, accounts, or files without your permission. Think of it like someone picking the lock to your front door to look through your private diary.

Malware (Malicious Software)

Malware is software specifically designed to cause deliberate damage or disrupt a computer system. This includes viruses that can delete files, or software that slows your computer down to a crawl.

Accidental Deletion

Not all risks are from "bad guys." Sometimes, the biggest risk is human error. Accidental deletion happens when a user clicks the wrong button and deletes important work or photos by mistake.

Theft of Personal Data (Phishing and Pharming)

These two sound similar, but they work differently. It is very important to know the difference:
Phishing: You receive a fake email or message (the "bait") that looks like it’s from a real bank or website. It asks you to click a link and enter your password or credit card details.
Pharming: This is more "invisible." It is a malicious script that redirects you to a fake website, even if you typed the correct web address into your browser. You think you are at your real bank, but you are actually on a fake site designed to steal your info.

Key Takeaway: Risks can be deliberate (hacking/malware) or accidental (deletion). Phishing uses fake messages, while Pharming uses fake website redirection.

2. Methods to Secure Data Online

How do we fight back? We use a "layered" defense. Here are the tools and habits that keep us safe:

Technical Shields

Firewalls: A piece of software or hardware that acts as a filter. It monitors data entering and leaving your network and blocks anything suspicious. Think of it as a security guard at the gate of your computer.
Encryption: This involves "scrambling" data so that if a hacker steals it, they can't read it. Only someone with the correct "key" can unscramble it back into readable information.
Secure Websites: Look for the padlock icon in the browser bar and HTTPS in the web address. This means the connection between you and the site is encrypted.

Authentication (Proving it's you)

Passwords and PINs: The most common way to lock an account. Strong passwords use a mix of letters, numbers, and symbols.
Biometrics: Using physical traits to log in, such as fingerprints or facial recognition. These are very hard for hackers to copy!
Security Questions: Asking for information only you should know, like "What was the name of your first pet?"
CAPTCHA Tests: Those "I am not a robot" boxes or image grids. They are designed to tell humans and automated "bots" apart.

Software Protection

We use specific software to fight different types of malware:
Anti-virus: Scans for and removes viruses that could damage your system.
Anti-adware: Stops annoying pop-up adverts from appearing.
Anti-spyware: Prevents software from "spying" on what you type (like passwords) or what websites you visit.

Access Rights and File Permissions

In a school or office, not everyone should see everything. Access rights ensure that a student can only see their own files, while a teacher can see everyone's. File permissions can be set to "Read Only" (you can see it but not change it) or "Read/Write" (you can edit it).

Safe Habits

Backup Procedures: This is the best defense against accidental deletion or malware damage. Always keep a second copy of your data in a different place (like the cloud or an external drive).
Smart Browsing: Never open email attachments from people you don't know and avoid following suspicious web links.

Key Takeaway: Security is about using software (firewalls, anti-virus), identity checks (biometrics, passwords), and good habits (backups) together.

3. Online Payment Systems

When we buy things online, we need to protect our money. There are several ways this is handled:

Bank Cards: Using credit or debit cards directly on a site.
Third-party Payment Systems: Services (like PayPal) that act as a "middleman." You pay the third party, and they pay the shop. This means you don't have to share your actual bank details with every single website you buy from.
Contactless Payments (NFC): Near-Field Communication (NFC) allows you to pay by tapping your phone or card near a reader. It is very fast and uses short-range radio waves to transmit data securely.

How are payments protected?

Payments are protected using encryption so hackers can't "sniff" your card details while they travel across the internet. Most banks also use two-factor authentication, where you might have to enter a code sent to your phone to finish a purchase.

Key Takeaway: Third-party systems add a layer of privacy, while NFC is used for short-range contactless payments.

Quick Review: Common Mistakes to Avoid

Mistake: Thinking a Firewall and Anti-virus are the same thing.
Correction: A Firewall stops hackers/data from getting in; Anti-virus finds and kills bad software that is already trying to run on your computer.
Mistake: Mixing up Phishing and Pharming.
Correction: Phishing = Private message (Email). Pharming = Farming/redirecting you to a fake site.
Mistake: Forgetting that "Accidental Deletion" is a risk.
Correction: You don't always need a hacker to lose data; sometimes a simple mistake is the biggest risk!

Note: For more on how these risks affect businesses, see the chapter "Impact of the internet on organisations". To learn more about laws protecting your data, see "Implications of using digital technologies".