Skip to main content

Unit 5 · Topic 5.6

5.6 Safe Computing

Your personal information is valuable, to you, to companies and to criminals. This topic covers what counts as personally identifiable information, how data about you is collected and combined, how passwords, multifactor authentication and encryption protect you, and the tricks attackers use to get in.

Key terms

  • personally identifiable information (PII)
  • multifactor authentication
  • encryption (symmetric and public key)
  • phishing
  • malware
  • rogue access point

Personally identifiable information

Personally identifiable information (PII) is information about a person that identifies them, links to them or describes them. Examples include your name, Social Security number, age, race, phone number, home address, medical and financial records, and biometric data like your fingerprint or face.

Lots of data gets collected as you go about your day. Search engines keep a history of what you search for. Websites record who visited their pages. Phones, apps and networks can track your location: where you went, how you got there and how long you stayed.

Separate scraps can be combined, or aggregated, into a detailed picture. Your location history, browsing history and cookies (small files a website saves in your browser to remember you) may each seem harmless, but together they can reveal where you live, where you go to school and what you're interested in. Posts on social media can be combined with other sources the same way.

Uses and risks

Some uses help you. Saved addresses and payment details make checkout faster, and search history lets a site recommend things you're likely to want. Companies also use it for targeted advertising.

Other uses can hurt you. PII can be used to steal your identity, stalk you or plan other crimes. Data that companies or governments collect can be exploited if they ignore privacy protections or suffer a breach. And information you post can travel in ways you didn't intend: an email gets forwarded, a post gets shared, and a future employer may see it. Once something is online, it's very hard to delete completely.

Protecting accounts and data

Authentication is how a system checks that you are who you say you are. A strong password is easy for you to remember but hard for anyone else to guess, even someone who knows you, so avoid your pet's name or your birthday. A long passphrase of unrelated words works well.

Multifactor authentication (MFA) grants access only after you give at least two separate kinds of proof: something you know (a password or PIN), something you have (your phone or a security key) and something you are (a fingerprint or face). Each factor is a separate layer, so stealing a password alone isn't enough.

Encryption scrambles data so only someone with the right key can read it; decryption turns it back. Symmetric encryption uses one key both to lock and to unlock. Public key encryption uses a pair: anyone can use your public key to encrypt a message to you, but only your private key, which you never share, can decrypt it. Certificate authorities are trusted organizations that issue digital certificates confirming who owns a public key; your browser relies on them when it shows a secure (HTTPS) connection. You won't be tested on the math behind encryption.

Other habits matter too: install software updates, because every real system has flaws that attackers can exploit and updates patch them; run antivirus and anti-malware software; and review app permissions so programs collect only the data you're comfortable sharing.

How attackers get in

ThreatHow it works
PhishingA fake message or site tricks you into giving up personal information, such as a login, which is then used to get into accounts like email or banking
Malicious links and attachmentsDisguised links or files in emails, messages or web pages, sometimes sent from a friend's hacked account
KeyloggingA program secretly records every key you press to capture passwords and other private details
MalwareSoftware meant to damage a system or take some control of it; untrustworthy free downloads often contain it
Computer virusMalware that copies itself, often hiding inside a legitimate program, and runs without permission
Rogue access pointA wireless access point set up without permission, such as a fake café Wi-Fi network or an unapproved one plugged into a school network. It can give outsiders a way into a secure network and let an attacker intercept, read or change data sent over it

Worked examples

Try each one yourself first, then open the solution.

  1. Example 1

    Naming the authentication factors

    To sign in to a school account, a student types a password, then approves a prompt on her phone. A second school asks for a password and then a security question (her first pet's name). Which of these is multifactor authentication, and why?

    Show the solution
    1. Step 1: Sort each piece of proof into a category. A password is something you know. A phone that receives the prompt is something you have. A security answer is something you know.
    2. Step 2: First school: something you know plus something you have, which is two different categories, so it's MFA.
    3. Step 3: Second school: two things you know. Someone who steals or guesses both pieces of knowledge gets in, so it adds less protection and isn't MFA in the usual sense.

    Answer: The first school uses MFA (knowledge plus possession); the second uses two knowledge factors, so it isn't true multifactor authentication.

  2. Example 2

    Recognizing phishing

    A student gets an email: "Your school account will be closed in 24 hours. Click here and enter your password to keep it active." The link goes to a site whose address is close to, but not the same as, the school's. What kind of attack is this, and what should the student do?

    Show the solution
    1. Step 1: The message creates urgency and asks for a password through a link. Its goal is to trick the student into giving up personal information.
    2. Step 2: That is phishing. The look-alike web address is a disguised malicious link.
    3. Step 3: The student shouldn't click or enter anything. Instead, they should go to the school's site by typing its real address, or report the email to the school's tech staff. MFA would also limit the damage if a password were stolen.

    Answer: It's a phishing attack; don't click the link or enter the password, check the account through the real site, and report the message.

Common mistakes

  • Thinking only secret numbers like a Social Security number count as PII. Age, phone number and even combined browsing data can identify you.
  • Swapping the keys in public key encryption. The public key encrypts; only the private key decrypts.
  • Treating a password plus a security question as strong multifactor authentication. Both are things you know, so a thief who learns both gets in. MFA normally combines proof from at least two different categories.
  • Mixing up phishing (tricking a person) with malware (harmful software) and rogue access points (fake or unauthorized wireless networks).

On the exam

  • Expect questions that describe a scenario and ask which attack is happening, which data is PII, or which action best protects a user.
  • Public key questions usually test who uses which key: the sender encrypts with the receiver's public key, and only the receiver's private key decrypts.
  • The reading passage may ask about the privacy risks of the data an innovation collects; name the specific data and how it could be misused.

Connected topics

Videos

  • AP CS Principles Exam Review - Privacy and Security

    Flavio KupermanWatch on YouTube (opens in a new tab)

  • The Internet: Cybersecurity & Crime

    CodeAIWatch on YouTube (opens in a new tab)

  • AP CSP Topic 5.6 - Safe Computing! - Explanations and 10 MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

  • AP CSP Exam Review: Data Encryption, Public & Private Keys

    Computer Science CoachWatch on YouTube (opens in a new tab)

  • The Internet: Encryption & Public Keys

    CodeAIWatch on YouTube (opens in a new tab)

  • Cybersecurity: Crash Course Computer Science #31

    CrashCourseWatch on YouTube (opens in a new tab)

Check yourself

4 questions on 5.6 Safe Computing. Pick an answer to see if you got it, and why.

Question 1 of 4

Which two of the following are examples of personally identifiable information (PII)? Select two answers.

Select two answers. 0 of 2 chosen

Question 2 of 4

A person's phone location history, the cookies on their browser and their search history are each collected by different companies. Which statement best describes the privacy risk?

Question 3 of 4

Which of the following best describes a strong password?

Question 4 of 4

Which of the following is an example of multifactor authentication?

0 of 4 answered