7m left·0%
Reading Time: 7 min
Last Updated: March 31, 2026
Main Ideas: 4
Reading Time: 7 min
Last Updated: March 31, 2026
Main Ideas: 4

Topic 5.6 Notes – Safe Computing

Verified for 2027 AP® Computer Science Principles Exam
Read aloud
Safe computing is about understanding how your personal data is collected, how it can be misused, and how systems protect (or fail to protect) it. In AP CSP, this topic connects privacy, security, and human behavior. You need to see both sides: why data collection happens and how it creates risk.

1. Personally Identifiable Information and Digital Footprints

Personally Identifiable Information (PII) is any information that identifies, links to, relates to, or describes a specific person.

You should instantly recognize these as PII:

  • Social Security number
  • Age and race
  • Phone number(s)
  • Medical records
  • Financial information (bank accounts, credit cards)
  • Biometric data (fingerprints, facial recognition, eye scans)

But privacy risk goes beyond obvious things.

Devices and websites also collect:

  • Search history (what you’ve looked up)
  • Browsing history and cookies
  • Website visit records
  • IP address
  • Geolocation data (where you are, how you got there, how long you stayed)

Search engines:

  • Store your past searches
  • Suggest results based on that history
  • Use it for targeted marketing (ads tailored to you)

Websites:

  • Track who visits their pages
  • Connect activity across sessions using cookies

Here’s the key idea students miss: separate pieces of harmless-looking data can be aggregated to reveal something personal.

Aggregated data forming a detailed personal profile

Individually, search history, geolocation, social media posts, and an IP address may not seem revealing. Combined, they can paint a detailed personal profile.

For example:

  • Social media post about a concert
  • Location data showing you at a specific stadium
  • Public records with your home address

Together, that can reveal patterns about where you live and when you’re not home.

Once something is online:

  • It can be copied, forwarded, screenshotted
  • It may be used by employers or colleges
  • It is extremely difficult to fully delete

Programs can even track where you’ve been, how you traveled there, and how long you stayed. That level of detail surprises people on tests.

2. Benefits and Risks of Data Collection

Technology enables the collection, use, and exploitation of data about individuals, groups, and institutions.

Benefits

Data collection can:

  • Personalize recommendations (music, videos, shopping)
  • Save payment/shipping info for faster checkout
  • Improve search accuracy
  • Enable location-based services (maps, ride apps)
  • Connect you with friends online

PII can make systems more convenient and customized.

Risks

If protections fail or are ignored:

  • Identity theft using SSN or financial info
  • Stalking using location data
  • Targeted scams based on your activity
  • Data breaches exposing stored user data
  • Profiling by companies or governments

Information may:

  • Be sold or shared
  • Be used beyond its original purpose
  • Be exploited if security is weak

On multiple-choice questions, they often describe a scenario where data improves convenience but increases vulnerability. You’re expected to recognize the privacy vs convenience trade-off.

3. Protecting Computing Resources

Authentication

Authentication verifies identity to prevent unauthorized access.

Strong Passwords

A strong password:

  • Is easy for you to remember
  • Is hard for others to guess
  • Avoids personal info (birthdays, names)
  • Avoids obvious choices (“12345”)
  • Uses varied characters

Weak passwords are one of the most common vulnerabilities tested.

Multifactor Authentication (MFA)

MFA requires at least two categories:

CategoryExample
KnowledgePassword, PIN
PossessionPhone, security token
InherenceFingerprint, facial scan

Each factor adds another layer. If someone steals your password, they still cannot log in without the second factor.

Encryption

Encryption encodes data to prevent unauthorized access. Decryption decodes it.

Two types you must know:

  • Symmetric key encryption
    • One key encrypts and decrypts
    • Both parties share the same key
  • Public key encryption
    • Public key encrypts
    • Private key decrypts
    • Sender does not need the receiver’s private key

The diagram below contrasts these two approaches. Focus on how the left side uses a single shared secret key, and the right side uses a public key to encrypt and a private key to decrypt.

Study guide illustration

Symmetric vs asymmetric key encryption

Public key systems use digital certificates issued by certificate authorities (CAs). These verify ownership of encryption keys using a trust model. No math required for the exam.

System Protection Practices

  • Malware/virus scanning software
  • Regular software updates (patch vulnerabilities)
  • Reviewing app permissions
  • Limiting data collection
  • Backups

All real systems have flaws. Updates fix weaknesses that attackers exploit.

4. How Unauthorized Access Happens

Phishing

Fake messages pretending to be trusted sources. They trick users into revealing passwords or financial info. Malicious links can be disguised.

Keylogging

Software records every keystroke to steal confidential information.

Rogue Access Points

Fake WiFi networks that intercept or modify transmitted data. Common risk on public networks.

Malware and Viruses

Malware is software intended to damage or control systems.

A computer virus:

  • Is malicious
  • Copies itself
  • Often attaches to legitimate files
  • Requires user activation

Common infection sources:

  • Unsolicited email attachments
  • Compromised accounts
  • Untrustworthy free downloads

Most attacks succeed because of human behavior, weak authentication, or unpatched systems.

Key Takeaways

PII includes more than obvious identifiers; location and browsing data can identify you when aggregated.
Separate pieces of data can be combined to reveal sensitive personal details.
Once information is online, complete deletion is extremely difficult.
Data collection creates a trade-off between personalization and privacy risk.
Multifactor authentication must use at least two different categories, not just two passwords.
In public key encryption, the sender uses the recipient’s public key, never the private key.
Regular software updates fix exploitable flaws that attackers actively search for.
Many security breaches succeed by tricking users, not by breaking advanced encryption.

AP® is a trademark registered by the College Board, which is not affiliated with, and does not endorse this website.

Notes

1 credit used · 5/5 remaining