Class 11Computer Science · Society, Law and EthicsFull chapter

Societal Impact

The whole chapter in one place — read it, then test yourself. Clear notes, a reference sheet, a practice quiz, and worked NCERT solutions & PYQs.

Digital Footprints and the Netizen

Quick answer Every online action leaves an active or passive data trail that is copied, stored and searchable long after you forget it — which is exactly why a netizen follows net, communication and social media etiquette.

Every time you use the internet you leave data behind. That trail is your digital footprint. It is not one neat file sitting in one place. It is scattered across the servers of every app, website, network and advertiser your device touched, plus the backups those servers keep.

There are two kinds, and the difference is exactly what board questions test.

  • Active digital footprint — data you deliberately put out. A reel you upload, a comment under a YouTube video, a review on Zomato, a form you fill on IRCTC, a resume uploaded to a job portal, a WhatsApp status, a Google Form for a school event.
  • Passive digital footprint — data collected about you without any deliberate act on your part. The IP address and browser details a news site logs the instant the page opens, cookies, location from your phone, which links you clicked and how long you stayed on each page, the Wi-Fi networks your phone tried to join.

Why a footprint is so hard to erase. The internet does not move data, it copies it. When you "send" a photo, your copy stays and a new copy lands on a server, which then replicates to backup machines, caches and content delivery nodes. Anyone who saw it can screenshot it. So deleting your copy removes your copy only. This is a consequence of how the network is built, not a setting you can switch off. Assume that anything you post can outlive your account.

Worked example — one evening of Riya's phone. Riya, a Class 11 student in Nagpur, spends an hour online. Classify each trace.

What happenedTypeWhy
She posts a photo of her science model on InstagramActiveShe chose to upload it
The news site she opened logs her IP address and device modelPassiveLogged automatically on page load
She searches "best coaching for JEE Nagpur"ActiveShe composed and submitted the query herself
Ads for coaching classes follow her to other sitesPassiveThird-party cookies tracked her across sites
She books a train ticket on IRCTCActiveShe filled a form with her own details
Her phone records that she was near the railway station at 8 pmPassiveLocation collected in the background

One row deserves care, because it is the row examiners use to separate careful students from careless ones. The search Riya typed is active — she composed it and pressed enter. What the search engine then quietly records around that query — which results she hovered over, which link she clicked, how long she stayed before coming back — is passive. A single episode routinely produces both kinds of trace at once, so classify the individual action, not the whole event.

Notice that Riya's passive footprint is larger than her active one, and she did not consent to most of it in any meaningful way. That asymmetry is the whole reason data-protection law exists.

Digital society and the netizen. A digital society is one where a large part of ordinary life — banking through UPI, school work, ticket booking, ration and scholarship applications, entertainment, friendships — runs through digital technology. A person who takes part in it is a netizen (net + citizen). Being a netizen is not just about having a data pack; it means carrying the same duties online that you have offline. Those duties are collected under netiquette.

Net etiquette — the general rules:

  • Be ethical. Do not pirate software, films or books. Do not access someone else's account, even if you happen to know the password. Give credit when you use someone's work.
  • Be respectful. Respect privacy — do not forward a private chat, photo or phone number without permission. Respect diversity of religion, region, caste, gender and ability; a "joke" that targets a group is not a joke online any more than it is in class.
  • Be responsible. Do not feed a troll. Do not take part in bullying, even by staying in the group and laughing. Verify before you forward — a forwarded rumour is your message once you send it.

Communication etiquette — for email, chat and video calls:

  • Be precise. Do not waste the reader's time. One clear subject line, the point in the first two lines, no ten-message chat where one message would do, no huge attachments when a link will do.
  • Be polite. No abuse, no sarcasm that cannot be read in text, no ALL CAPS (it reads as shouting). Match the register to the reader — the way you message a friend is not the way you write to a teacher or a college admissions office.
  • Be credible. Say true things, do not exaggerate, and do not send an email under someone else's name. Think before you press Reply All.

Social media etiquette: choose your connections carefully, keep profiles private if you do not need them public, do not overshare (live location, travel plans, school name and section, exam roll numbers), never post someone else's photo without asking, check whether a shocking claim is fake before you share it, and think about how a post will read in five years to a college or an employer.

A workable rule: post only what you would be comfortable seeing pinned on the school notice board with your name on it.

Digital footprint trail of data left behind by all online activity Includes what you post AND what is silently logged about you
Active footprint data you deliberately share — post, comment, form, upload You chose to send it; you rarely control what happens to it afterwards
Passive footprint data collected without deliberate action — IP, cookies, location, click logs Recorded even if you only open a page and read
Netizen net + citizen: a responsible, lawful user of the internet Duties, not just rights
Netiquette pillars be ethical, be respectful, be responsible The NCERT three-way split for net etiquette
Communication etiquette be precise, be polite, be credible Applies to email, chat, forums and video calls alike
Remember
  • A digital footprint is the trail of data left behind by online activity; it is active (you posted it) or passive (it was logged about you).
  • Classify the action, not the episode — the search you type is active, while the click-and-dwell log the site keeps around it is passive.
  • Passive footprints are usually much larger than active ones — IP logs, cookies, location and click history are collected without any deliberate action.
  • Footprints are hard to erase because the internet copies data rather than moving it; deleting your copy does not delete the server's copies, caches, backups or anyone's screenshots.
  • A netizen is a citizen of the internet who carries the same duties online as offline; netiquette covers net etiquette (be ethical, respectful, responsible), communication etiquette (be precise, polite, credible) and social media etiquette.
  • Safe test before posting: would you be happy to see this on the school notice board with your name on it?

Intellectual Property Rights and Licensing

Quick answer Copyright, patent and trademark protect different things for different durations; plagiarism is a failure of credit while copyright infringement is a failure of permission, and open licences such as GPL, Apache 2.0 and Creative Commons are the legal way to say yes in advance.

Ideas are expensive to create and almost free to copy. If anyone could copy a program, a song or a textbook the moment it appeared, very few people would fund making them. Intellectual Property Rights (IPR) fix this by giving a creator a legal monopoly over their creation for a defined period. The bargain has two sides: the creator gets exclusive control, and in exchange the work is disclosed and — for copyright and patents — eventually becomes free for everyone to use. A trademark is the exception to that second half: it can be renewed for as long as it is genuinely in use, because its job is to stop customers being misled rather than to reward creation.

The three you must know.

CopyrightPatentTrademark
ProtectsOriginal expression: books, songs, films, photographs, artistic works and computer programsA new, useful and non-obvious invention — a product or a processA sign that identifies who a product comes from: name, logo, tagline, distinctive packaging
Indian lawCopyright Act, 1957Patents Act, 1970Trade Marks Act, 1999
How you get itAutomatic the moment the work is created; registration is optional and only helps as proofMust be applied for and granted after examinationUsable on claim; registration gives much stronger rights
DurationFor literary works, the author's lifetime plus 60 years, counted from the beginning of the year following the author's death20 years from the date of filing10 years, renewable again and again
Symbol©—™ when claimed, ® when registered

Two points students get wrong. First, copyright protects the expression, not the idea — you may write your own sorting tutorial, you may not copy someone else's tutorial. Second, in India software is protected as a literary work under copyright, not by a patent — a computer program by itself is not patentable here — which is why the licence text bundled with a program matters so much.

Violation of IPR.

  • Plagiarism — presenting someone else's work, words or ideas as your own without acknowledgement. It is primarily an ethical and academic offence, and it can happen even with material that is completely free to use.
  • Copyright infringement — reproducing, distributing, performing or adapting a protected work without permission and without a valid exception. It is a legal offence, and it can happen even when you give full credit.
  • Trademark infringement — using a mark identical or deceptively similar to a registered mark for similar goods or services, so that an ordinary buyer could be confused about who is selling it. The harm being prevented is confusion, not copying as such.

The plagiarism-versus-infringement pair is the most repeated question in this unit, so hold the two axes separately: credit and permission.

Gave credit?Had permission / licence?Verdict
NoNoPlagiarism and copyright infringement
YesNoCopyright infringement only
NoYes (or work is public domain)Plagiarism only
YesYesClean

Indian copyright law does allow limited fair dealing — for private study, research, criticism, review and reporting current events — but that is a narrow exception, not a licence to lift a whole chapter into a project.

Open source software and licensing. Without a licence, the default position for any work is "all rights reserved" — you may not copy it. An open licence is the author saying yes in advance, on stated conditions. Note that "free software" means free as in freedom (to run, study, modify and redistribute), not free of cost; the terms FOSS and FLOSS are used to make that clear.

  • GPL (GNU General Public License) — a copyleft licence. You may use, study, modify and redistribute, but if you distribute a modified version it must also be released under the GPL with its source code available. The freedom is forced to travel down the chain. The Linux kernel is released under version 2 of the GPL.
  • Apache License 2.0 — a permissive licence. You may use, modify and redistribute the code, including inside a closed-source commercial product. You must keep the copyright and licence notices and state the changes you made. It also includes an express patent grant from the contributors, which is why companies like it.
  • Creative Commons (CC) — meant for creative content (text, photographs, music, courseware) rather than code. It is built from four blocks: BY (give attribution), SA (share alike — your version must carry the same licence), NC (non-commercial use only) and ND (no derivatives — do not modify). These combine into six licences, from the very permissive CC BY to the very restrictive CC BY-NC-ND. CC0 is the separate tool by which an author waives rights and places a work as close to the public domain as the law allows. Wikipedia's text, for instance, is available under a Creative Commons Attribution-ShareAlike licence.

Worked example — Ananya builds a school website. Ananya, in Class 11, makes a site for her school's science club. Judge each of her five choices.

What she didVerdictReason
Copied four paragraphs from a science blog and pasted them with no mention of the sourcePlagiarism and copyright infringementNo credit, no permission
Copied two paragraphs from the same blog and wrote the blog's URL underneathCopyright infringement onlyCredit given, but permission still missing
Used a photo marked CC BY but removed the photographer's namePlagiarism and copyright infringementAttribution was the one condition attached to the licence; strip it and she falls outside the licence, so she now has neither credit nor permission
Read three articles and wrote the page in her own words, citing all threeCorrect practiceOwn expression plus acknowledgement
Designed a club logo that closely imitates a well-known sports brand's tickRisk of trademark infringementA deceptively similar mark can confuse people about the source
Copyright automatic right over original expression — Copyright Act, 1957 Software is protected as a literary work; term is life of author + 60 years
Patent granted right over a new, useful, non-obvious invention — Patents Act, 1970 20 years from date of filing; must be applied for, never automatic
Trademark sign identifying the source of goods or services — Trade Marks Act, 1999 TM = claimed, R = registered; 10 years, renewable indefinitely
Plagiarism vs infringement plagiarism = no credit; infringement = no permission Full credit does not cure infringement; a free licence does not cure plagiarism
GPL copyleft — distributed derivatives must also be GPL, with source Keeps the code open all the way down the chain
Apache 2.0 / CC blocks Apache = permissive + patent grant; CC = BY, SA, NC, ND CC is for creative content; CC0 waives rights entirely
Remember
  • Copyright is automatic and protects expression (including computer programs) for the author's lifetime plus 60 years; a patent must be granted and lasts 20 years from filing; a trademark identifies the source of goods and is renewable every 10 years indefinitely.
  • In India a computer program is protected as a literary work by copyright, not by a patent — which is why the bundled licence text decides what you may do with it.
  • Plagiarism is about missing credit and is an ethical offence; copyright infringement is about missing permission and is a legal offence. You can commit either one without the other.
  • Trademark infringement turns on likely customer confusion, not on how much was copied.
  • Open licences are the author's advance yes: GPL is copyleft (derivatives must stay open with source), Apache 2.0 is permissive (closed derivatives allowed, notices kept, patent grant included).
  • Creative Commons combines BY, SA, NC and ND into six licences for creative content; breaking a licence condition such as attribution puts you outside the licence entirely, which turns the use into infringement.

Cyber Crime: Hacking, Phishing, Ransomware and Bullying

Quick answer A cyber crime is any offence where a computer resource is the target, the tool or the scene — hacking, eavesdropping, phishing, ransomware, trolling and bullying all have identifiable warning signs and a defined reporting route in India.

A cyber crime is any criminal offence in which a computer, a computer network or a computer resource is the target of the crime, the tool used to commit it, or the place where it happens. In India these are handled mainly under the Information Technology Act, 2000 (heavily amended in 2008), read together with the general criminal law — the Bharatiya Nyaya Sanhita, which replaced the Indian Penal Code from 1 July 2024.

Hacking. Gaining access to a computer system, network or data without authorisation. The colour labels are worth knowing:

  • White hat — tests security with written permission from the owner and reports the flaws. This is a legitimate profession.
  • Black hat (also called a cracker in older textbooks) — breaks in to steal, damage or extort.
  • Grey hat — breaks in without permission but without malicious intent, often to show off a flaw. Well-meaning or not, it is still unauthorised access and still an offence.

The line is permission, not skill. Logging into a friend's account because you happened to see the password is unauthorised access, even though nothing was "hacked" in a technical sense.

Eavesdropping. Secretly intercepting a communication while it is in transit — reading data that was never meant for you. The everyday routes are open or fake "Free Wi-Fi" hotspots at a railway station or mall, packet sniffing on an unsecured network, and a keylogger quietly installed on a shared computer, which captures your keystrokes before they are ever encrypted. Its lowest-tech relative is shoulder surfing — simply watching over your shoulder as you type a UPI PIN in a queue. Nothing is intercepted on the wire there, but the attacker ends up with the same secret. The defences are encryption (HTTPS everywhere), not entering passwords on untrusted networks, and covering the keypad.

Phishing and fraud emails. A message that impersonates a trusted party — your bank, the income tax department, IRCTC, a courier company, even your own school — to trick you into handing over credentials or clicking a malicious link. Variants: spear phishing (aimed at one named person, using details about them), vishing (a phone call: "I am calling from your bank, kindly confirm the OTP") and smishing (SMS). The recurring signs are:

  • Manufactured urgency and threat — "your account will be blocked in 2 hours".
  • A lookalike domain that is not the real one.
  • A generic greeting, odd grammar, or a logo that is slightly wrong.
  • An unexpected attachment, or a link whose visible text differs from where it actually goes.
  • Any request for OTP, PIN, CVV or password. No Indian bank, no UPI app and no government office ever asks for these.

Worked example — reading a suspicious link with Python. Aditya gets an SMS: "Your IRCTC refund of Rs 1,240 is pending, claim here." Instead of tapping, he pulls the link apart.

link = "http://irctc-refund-status.co.in/login"
print(link.startswith("https://"))
host = link.split("/")[2]
print(host)
print(host.endswith("irctc.co.in"))
print(host.count("-"))

Output:

False
irctc-refund-status.co.in
False
2

Three red flags in four lines: the link is plain http, the real host is irctc-refund-status.co.in which does not end with irctc.co.in, and the brand name has been padded with hyphens so it merely looks familiar. The trick is always the same — the genuine brand name is placed where you read first, while the part that actually decides the destination sits at the end of the host name.

Ransomware. Malware that encrypts your files and demands a payment, usually in cryptocurrency, for the decryption key. It typically arrives through an infected attachment, pirated or cracked software, or an unpatched system exposed to the network. The WannaCry outbreak of May 2017 disrupted organisations across many countries, including in India. Two rules: keep offline backups (ransomware encrypts the connected backup too), and understand that paying guarantees nothing — many victims pay and still do not get their files back, and payment funds the next attack.

Cyber trolling. Deliberately posting provocative, insulting or off-topic messages to upset people or derail a discussion. A troll usually wants a reaction from anyone. The correct response is to not feed it: do not reply, report the account and block.

Cyber bullying. Repeated harassment, threatening, humiliating or targeting of a specific person using digital means — abusive messages, spreading rumours in a class group, circulating morphed photographs, creating a fake profile in someone's name, deliberate exclusion from groups. Because it follows the victim home through the phone, it does not stop at the school gate. It is a crime, not a joke, and silently staying in the group makes a person part of it. Warning signs in a victim: sudden withdrawal, avoiding the phone or school, falling marks, changed sleep.

How to report it in India.

  • cybercrime.gov.in — the National Cyber Crime Reporting Portal. Complaints relating to women and children can be filed there anonymously.
  • 1930 — the national helpline for cyber financial fraud. Call it immediately; the sooner a fraudulent transaction is reported, the better the chance of stopping the money before it is withdrawn.
  • Your local police cyber cell, which can register an FIR.
  • CERT-In (Indian Computer Emergency Response Team), created under Section 70B of the IT Act and working under MeitY, is the national nodal agency for cyber security incidents — it issues advisories and coordinates response, mainly for organisations.

Before reporting anything, preserve evidence: screenshots with date and time, the sender's number or account handle, the full message, transaction IDs. Do not delete the messages in anger.

Cyber crime offence where a computer resource is target, tool or scene Prosecuted under the IT Act, 2000 read with general criminal law
Hacking unauthorised access to a computer resource White hat = permitted; black hat/cracker = malicious; grey hat = still illegal
Eavesdropping secretly intercepting data while it is in transit Open or fake Wi-Fi, packet sniffers, keyloggers; shoulder surfing is the low-tech relative
Phishing fake message impersonating a trusted party to steal credentials Vishing = phone call, smishing = SMS; check the end of the host name
Ransomware encrypts files, demands payment for the key Only an offline backup reliably saves you; paying guarantees nothing
Report it cybercrime.gov.in; helpline 1930 for financial fraud; local cyber cell CERT-In (Section 70B) is the national nodal agency for incidents
Remember
  • Cyber crime = a computer resource is the target, the tool or the scene; India handles it under the IT Act, 2000 (amended 2008) with the general criminal law.
  • Hacking is defined by absence of permission, not by technical difficulty — grey hat access without malice is still an offence; white hat testing requires the owner's written permission.
  • Eavesdropping is interception of data in transit (open Wi-Fi, packet sniffers, keyloggers); shoulder surfing is its low-tech relative — nothing is intercepted on the wire, but the secret is lost all the same.
  • Phishing works on urgency plus a lookalike domain; read a host name from the right-hand end, and remember no bank or government office ever asks for OTP, PIN or CVV.
  • Ransomware encrypts files and demands payment; offline backups and prompt patching are the real defences, and paying guarantees nothing.
  • A troll wants a reaction from anyone; a bully repeatedly targets one specific person. Report at cybercrime.gov.in, call 1930 for financial fraud, and preserve screenshots as evidence.

Cyber Safety, Identity Protection and Malware

Quick answer Safe browsing means reading the domain rather than trusting a padlock; identity protection means minimising what you reveal and never sharing an OTP; and viruses, worms, trojans and adware each spread by a different mechanism, which is what decides the defence.

Cyber safety is the set of habits that keep you, your data and your device out of trouble. It is mostly boring and mostly effective.

Safely browsing the web.

  • Read the address bar, not the padlock. HTTPS and a padlock mean only that the connection to that server is encrypted. They do not mean the site is honest — criminals obtain certificates too. What matters is the domain name itself, read carefully, letter by letter, from the right-hand end.
  • For anything involving money, type the address yourself or use a saved bookmark or the official app. Never reach your bank through a link in a message.
  • Keep the browser and the operating system on automatic updates. Most successful attacks use a hole that was patched months earlier.
  • Avoid pirated software, "cracked" versions and free-download mirror sites. That is the single most common way home computers get infected.
  • On a shared or school computer: log out, do not save passwords, and clear history and cookies afterwards.
  • Cookies are small files a site stores in your browser to remember you. First-party cookies are useful (they keep you logged in). Third-party cookies mostly exist to follow you between sites.
  • Incognito / private mode hides history on that device only. The website, the school network, your employer and your ISP can all still see the visit. It is a privacy tool against the next person using the same computer, nothing more.

Identity protection. Identity theft happens when someone collects enough of your personal data to pretend to be you — open an account, take a loan, or post in your name. Reduce what is available to collect:

  • Use a long passphrase rather than a short complicated password, and never reuse one password across sites. One leaked site then cannot unlock the rest.
  • Turn on two-factor authentication wherever it is offered.
  • Never share an OTP, PIN, CVV or password — not with a caller, not with a "bank official", not with a friend.
  • Share the minimum. Do not post your full date of birth, address, school section, Aadhaar number or a photo of a ticket with a PNR on it. UIDAI offers a masked Aadhaar and a Virtual ID precisely so you can prove identity without handing over the full number.
  • Check what an app asks for. A torch app that wants your contacts and SMS is not a torch app.
  • Review privacy settings on social accounts, and search for your own name occasionally to see what is public.

Confidentiality of information means keeping private data private — your own and other people's. In practice: strong authentication, encryption of sensitive files, access control (only the people who need the data can see it), careful sharing, and secure disposal. That last one is easy to forget: a "deleted" file is usually still recoverable, so an old phone or hard disk must be wiped properly or physically destroyed before it leaves your hands.

Worked example — what should actually appear on screen. A school notice board app displays a student's payment status. Meera checks how much of her data is exposed, and whether her password would survive a leak.

upi_id = "meera.nair@okhdfcbank"
card = "5241 7788 0043 1290"

print("Shown on screen:", upi_id.split("@")[0][:2] + "*****@" + upi_id.split("@")[1])
print("Shown on screen:", "**** **** **** " + card[-4:])

pwd = "meera2010"
weak = ["password", "123456", "meera2010", "qwerty"]
print("In leaked list?", pwd in weak)
print("Has uppercase?", pwd.lower() != pwd)
print("Length:", len(pwd))

Output:

Shown on screen: me*****@okhdfcbank
Shown on screen: **** **** **** 1290
In leaked list? True
Has uppercase? False
Length: 9

Two lessons. First, a well-built system shows only what is needed to recognise a record — the last four digits — and never the whole number; this is data minimisation. Second, Meera's password is her name plus her birth year, it is short, it has no uppercase character, and a pattern like it already appears on public leaked-password lists. Anyone who knows her can guess it in a few tries.

Malware is the umbrella term for malicious software. The types differ mainly in how they spread, and that is what the exam asks.

TypeNeeds a host file?Self-replicating?Typical damage
VirusYes — attaches to a file or programYes, but only when the host runsCorrupts or deletes files, slows the system
WormNo — standaloneYes, spreads across a network by itselfConsumes bandwidth and memory, crashes networks
TrojanNo — it is the file you installedNoOpens a backdoor, steals data, installs other malware
AdwareNo — usually bundled with free softwareNoForced pop-ups, changed homepage and search engine; often tracks you as well

The key contrast: a virus needs a carrier and normally a human action (opening the file, running the program) to travel, while a worm needs neither and can cross a whole network on its own. A trojan spreads because you chose to install it — it looked like a free game, a cracked app or a PDF reader. Closely related are spyware and keyloggers, which quietly record what you do and what you type, and ransomware, covered in the previous section.

Defences that actually work: a reputed antivirus with up-to-date definitions, a firewall to filter network traffic, automatic operating system and application updates, regular offline backups, installing only from official stores and official sites, scanning pen drives before opening them, and disabling autorun on removable media.

HTTPS padlock encrypted connection, not a trusted website Phishing sites use HTTPS too; judge the domain, not the lock
Virus attaches to a host file; runs when the host runs Cannot travel without a carrier and normally a user action
Worm standalone, self-replicating, spreads over the network unaided No host file and no click needed — patching is the main defence
Trojan disguised as useful software; does not self-replicate Usual entry route is pirated or cracked software
Adware forces unwanted ads, pop-ups and homepage changes Bundled with free downloads; frequently spies as well
Incognito mode hides browsing history on that device only Website, school network and ISP still see the visit
Remember
  • The padlock proves the connection is encrypted, not that the site is honest — always read the domain name itself, and reach banking sites by typing the address or using the official app.
  • Incognito mode hides history from the device only; the website, the network and the ISP still see everything.
  • Identity protection = long unique passphrases, two-factor authentication, never sharing OTP/PIN/CVV, and sharing the minimum (masked Aadhaar and Virtual ID exist for this reason).
  • A virus needs a host file and usually a user action; a worm is standalone and self-spreading over a network; a trojan does not replicate at all because the user installs it; adware forces ads and usually tracks.
  • Confidentiality includes secure disposal — a deleted file is generally recoverable, so wipe or destroy storage before handing a device on.

E-Waste, the IT Act and Inclusive Technology

Quick answer Discarded electronics are both toxic and valuable and must go to authorised recyclers under India's EPR-based rules; the IT Act, 2000 with its 2008 amendment is the legal backbone of Indian cyberspace; and gender and disability gaps decide who actually gets to use all of it.

E-waste is discarded electrical and electronic equipment and its parts — phones, laptops, monitors, printers, keyboards, televisions, routers, chargers, batteries and lamps. Electronics are replaced faster than almost anything else in a house, so the pile grows quickly.

Why it cannot go in the ordinary dustbin. Electronics contain lead (older CRT monitors, solder), mercury (some lamps and older backlights), cadmium, hexavalent chromium and brominated flame retardants in the plastic. In informal recycling, cables are burnt in the open to recover copper and boards are dipped in acid to recover gold. That releases toxic fumes, injures the workers — often including children — and leaves heavy metals in the soil and groundwater.

The same devices are also valuable: they contain gold, silver, copper, palladium and aluminium. Recovering metal from discarded electronics, sometimes called urban mining, is cheaper and far less damaging than digging fresh ore. So e-waste is a hazard and a resource at the same time, which is exactly why it must be routed to people equipped to handle it.

Proper disposal, in order of preference:

  1. Reduce — buy what you need, buy durable and repairable equipment, and resist replacing a working device every year.
  2. Reuse — a laptop too slow for you is perfectly good for a junior, a school, or an NGO. Sell or donate it.
  3. Repair or refurbish — a battery or a screen replacement is cheaper than a new device and produces no waste.
  4. Recycle through an authorised recycler or dismantler, or through the manufacturer's take-back or exchange programme. Do not hand it to an informal roadside dealer who will burn it.
  5. Dispose safely — batteries and lamps go to designated collection points, never into household waste.

Before you pass on any device: back up, then wipe. Sign out of every account, remove the SIM and memory card, do a factory reset, and for a computer wipe the drive properly. This is where e-waste meets confidentiality — an unwiped phone handed to a stranger is a data leak, not just a disposal.

India's rules. Electronic waste is regulated by the E-Waste (Management) Rules, 2022, which came into force on 1 April 2023 and replaced the 2016 Rules; they are administered by the Central Pollution Control Board. The central idea is Extended Producer Responsibility (EPR): the producer, not just the consumer, is responsible for collecting back and recycling a target quantity of what it sold, and producers, recyclers and refurbishers must register with the CPCB. Internationally, the Basel Convention, to which India is a party, restricts the movement of hazardous waste across borders so that rich countries cannot simply dump it elsewhere.

Worked example — a class e-waste drive. Class 11-B collects old items for a school collection day and records them.

import statistics
items = ["monitor", "keyboard", "mouse", "CFL bulb", "old phone"]
weight = [4.2, 0.9, 0.1, 0.2, 0.18]

print("Items collected:", len(items))
print("Total weight (kg):", round(sum(weight), 2))
print("Average per item:", round(statistics.mean(weight), 3))
print("Heaviest:", items[weight.index(max(weight))])
print("Lightest:", items[weight.index(min(weight))])

Output:

Items collected: 5
Total weight (kg): 5.58
Average per item: 1.116
Heaviest: monitor
Lightest: mouse

Weight is not the same as hazard. The CFL bulb weighs 0.2 kg and the mouse 0.1 kg, but the bulb contains mercury and must go to a designated collection point, while the old phone at 0.18 kg must be wiped before it leaves the building. A disposal plan is decided by what is inside, not by what the scale says.

The Information Technology Act, 2000. Before it, an email had no clear legal standing in India, so an electronic contract could not be relied on. The IT Act, 2000 — modelled on the UNCITRAL Model Law on Electronic Commerce and in force from 17 October 2000 — gave legal recognition to electronic records and digital signatures, which is what made e-governance, e-filing and e-commerce possible here. It also created the first set of offences and penalties for misuse of computer resources.

The Information Technology (Amendment) Act, 2008 substantially widened it. Among the provisions it introduced or reshaped:

  • Section 43A — a body corporate handling sensitive personal data must maintain reasonable security practices, and pays compensation if negligence causes wrongful loss.
  • Sections 66C and 66D — identity theft, and cheating by personation using a computer resource. This is the pair that covers most phishing and OTP frauds.
  • Section 66E — violation of privacy by capturing or publishing images of a private area without consent.
  • Section 66F — cyber terrorism.
  • Sections 67A and 67B — publishing sexually explicit material, and child sexual abuse material.
  • Section 69 — powers of interception, monitoring and decryption in defined circumstances.
  • Section 70B — CERT-In as the national nodal agency for cyber security incidents.
  • Section 79 — the "safe harbour" framework limiting an intermediary's liability for content posted by users, subject to due diligence.
  • It also made electronic signatures technology-neutral rather than tying the law to one method.

One case is worth remembering because it shows a law being tested against the Constitution: Section 66A, which punished sending "offensive" messages, was struck down by the Supreme Court in Shreya Singhal v. Union of India (2015) for being vague and violating freedom of speech. It is no longer valid law. (Separately, India's dedicated personal-data statute is the Digital Personal Data Protection Act, 2023, which is beyond this syllabus.)

Technology and society: gender issues. Access to a computer is not the same as being allowed to use one comfortably. The gaps commonly seen while teaching and using computers are:

  • Preconceived notions — the assumption that boys are naturally better with machines, which girls then absorb.
  • Fewer role models — if every engineer in the textbook examples and every senior in the lab is male, the subject looks like it belongs to someone else.
  • Less encouragement at home and in class, and less unstructured time to tinker and break things.
  • Unequal hands-on time — in a shared lab, a few confident students take the keyboard and the rest end up watching or writing notes.
  • Unequal access to devices at home, where the one family phone or laptop is often allotted by seniority or gender.
  • Online harassment, which pushes some students out of public participation altogether.

What a school can actually do: rotate roles so everyone types, forms mixed groups, allots lab time by turn rather than by who reaches the machine first, uses examples that name women in computing, lends devices, treats teasing in the lab as a discipline matter, and provides a safe way to report harassment.

Disability issues. The standard barriers are unavailability of suitable teaching material and aids, a shortage of trained or special educators, a curriculum that assumes a mouse-and-screen user, and locomotor difficulties that make the lab itself hard to reach or use.

Assistive technology answers much of this: screen readers (NVDA is free and open source, JAWS is commercial), screen magnifiers, high-contrast and large-text modes, refreshable braille displays and braille printers, text-to-speech and speech-to-text, on-screen keyboards, sticky keys and switch access for students who cannot use a standard keyboard, captions and sign-language video, and alternative pointing devices. In India, the Rights of Persons with Disabilities Act, 2016 requires accessibility, and government websites are expected to follow the Guidelines for Indian Government Websites (GIGW).

Accessibility is also something a Class 11 student can practise while making anything: write alternative text for images, add captions to video, keep colour contrast high, never convey meaning by colour alone, make everything reachable with the keyboard, and avoid flashing content. A page built this way is easier for everyone to use, not only for the people who need it.

E-waste discarded electrical and electronic equipment and its parts Hazardous (lead, mercury, cadmium) and valuable (gold, copper) at once
EPR Extended Producer Responsibility — producer must take back and recycle Core of the E-Waste (Management) Rules, 2022, in force 1 April 2023
Disposal order reduce → reuse → repair → recycle (authorised) → safe disposal Back up and wipe every device before it leaves your hands
IT Act, 2000 legal recognition of electronic records and digital signatures + cyber offences In force 17 October 2000; based on the UNCITRAL Model Law on E-Commerce
IT (Amendment) Act, 2008 added 43A, 66C, 66D, 66E, 66F, 67A/67B, 69, 70B, 79 Section 66A was struck down in Shreya Singhal v. Union of India (2015)
Assistive technology hardware/software that makes computing usable for persons with disabilities Screen readers, magnifiers, braille displays, captions, speech-to-text, switch access
Remember
  • E-waste is both hazardous (lead, mercury, cadmium, chromium) and valuable (gold, silver, copper), so it must be routed to authorised recyclers rather than burnt or acid-stripped informally.
  • Disposal hierarchy: reduce, reuse, repair, recycle through an authorised recycler, then dispose safely — and always back up and wipe a device before passing it on.
  • India's E-Waste (Management) Rules, 2022 (in force 1 April 2023) work through Extended Producer Responsibility, making the producer responsible for take-back and recycling targets; the Basel Convention restricts cross-border hazardous waste movement.
  • The IT Act, 2000 gave legal recognition to electronic records and digital signatures; the 2008 amendment added identity theft (66C), personation fraud (66D), privacy violation (66E), cyber terrorism (66F), data security duties (43A), CERT-In (70B) and intermediary safe harbour (79). Section 66A was struck down in Shreya Singhal v. Union of India (2015).
  • Gender gaps come from preconceived notions, missing role models and unequal hands-on time; disability gaps come from missing aids, untrained teachers and inaccessible design — both are fixed by deliberate practice, not by waiting.

The formula sheet

Every formula in this chapter, in one place — screenshot it before your exam.

trail of data left behind by all online activity
Digital footprint
data you deliberately share — post, comment, form, upload
Active footprint
data collected without deliberate action — IP, cookies, location, click logs
Passive footprint
net + citizen: a responsible, lawful user of the internet
Netizen
be ethical, be respectful, be responsible
Netiquette pillars
be precise, be polite, be credible
Communication etiquette
automatic right over original expression — Copyright Act, 1957
Copyright
granted right over a new, useful, non-obvious invention — Patents Act, 1970
Patent
sign identifying the source of goods or services — Trade Marks Act, 1999
Trademark
plagiarism = no credit; infringement = no permission
Plagiarism vs infringement
copyleft — distributed derivatives must also be GPL, with source
GPL
Apache = permissive + patent grant; CC = BY, SA, NC, ND
Apache 2.0 / CC blocks
offence where a computer resource is target, tool or scene
Cyber crime
unauthorised access to a computer resource
Hacking
secretly intercepting data while it is in transit
Eavesdropping
fake message impersonating a trusted party to steal credentials
Phishing
encrypts files, demands payment for the key
Ransomware
cybercrime.gov.in; helpline 1930 for financial fraud; local cyber cell
Report it
encrypted connection, not a trusted website
HTTPS padlock
attaches to a host file; runs when the host runs
Virus
standalone, self-replicating, spreads over the network unaided
Worm
disguised as useful software; does not self-replicate
Trojan
forces unwanted ads, pop-ups and homepage changes
Adware
hides browsing history on that device only
Incognito mode
discarded electrical and electronic equipment and its parts
E-waste
Extended Producer Responsibility — producer must take back and recycle
EPR
reduce → reuse → repair → recycle (authorised) → safe disposal
Disposal order
legal recognition of electronic records and digital signatures + cyber offences
IT Act, 2000
added 43A, 66C, 66D, 66E, 66F, 67A/67B, 69, 70B, 79
IT (Amendment) Act, 2008
hardware/software that makes computing usable for persons with disabilities
Assistive technology

Test yourself

Tap an answer to check it instantly — you'll see why it's right, and what to revise if it isn't.

0 correct · 0/12 answered
Q1

Predict the output: aadhaar = "1234 5678 9012" masked = "XXXX XXXX " + aadhaar[-4:] print(masked) print(len(masked), aadhaar[:4])

Q2

Predict the output: pwd = "Rahul@123" digits = 0 caps = 0 for ch in pwd: if ch.isdigit(): digits = digits + 1 if ch.isupper(): caps = caps + 1 print(digits, caps) print(pwd.isalnum(), len(pwd) >= 12)

Q3

Predict the output: lic = ["GPL", "Apache", "CC BY", "GPL"] lic.append("MIT") lic.remove("GPL") print(lic) print(lic.count("GPL"), "gpl" in lic)

Q4

Predict the output: import statistics complaints = [4, 7, 4, 9, 6] print(statistics.mode(complaints), statistics.median(complaints)) print(max(complaints) - min(complaints), len(complaints))

Q5

Which of the following is a PASSIVE digital footprint?

Q6

Ishaan copies three paragraphs from a science blog into his school project and clearly writes the blog's URL below them, but never asks the blog owner for permission. Which statement is correct?

Q7

A start-up wants to include an open source library inside its own closed-source paid app, without publishing its own source code. Which licence permits this?

Q8

Aarav's classmates make a group without him, post morphed photographs of him for several weeks and mock him daily. This is best described as:

Q9

Which type of malware is standalone and spreads across a network by itself, without needing a host file and without waiting for a user to click anything?

Q10

Rohit sees https:// and a padlock icon on a page asking for his net-banking password. What should he conclude?

Q11

Which statement about the Information Technology Act, 2000 is correct?

Q12

Extended Producer Responsibility (EPR), the core idea of India's e-waste rules, means that:

NCERT solutions & previous-year questions

Step-by-step model answers — tap a question to reveal the full solution.

NCERT questions 6

1 After finishing his practical, Atharv left the computer laboratory but forgot to sign out from his email account. Later, Revaan started using the same computer. He found that Atharv was still logged in, and he used that account to send inflammatory messages to some of his classmates. Revaan's activity is an example of which cyber crime? Explain.Cyber crime — identity theft and impersonation

Revaan has committed identity theft, carried out through unauthorised access to a computer resource, and used it to impersonate Atharv.

Step 1 — was the access authorised? No. Atharv did not give Revaan permission to use his account. The fact that the session was already open does not create permission, exactly as an unlocked door does not invite you in. Unauthorised access to a computer resource is an offence under the IT Act, 2000.

Step 2 — what did he do with the access? He sent messages that appeared to come from Atharv. This is impersonation, or cheating by personation using a computer resource. Because the messages were inflammatory, the recipients will believe Atharv wrote them, so the harm falls on an innocent person — this is precisely why identity theft is treated seriously.

Step 3 — is it also cyber bullying? If the messages targeted and humiliated particular classmates repeatedly, that element is present too, but the primary offence described in the question is identity theft by unauthorised access.

Lesson for both boys. Atharv should always sign out on a shared or lab computer, avoid saving passwords in the browser, and clear the session before leaving — carelessness of this kind is how most school-level account misuse begins. Revaan's correct conduct was to sign Atharv out, or inform the teacher, and nothing else. If Atharv is blamed for the messages, he should report the incident to the school and, if the harm is serious, at cybercrime.gov.in, preserving screenshots and lab timings as evidence.

2 Rishika found a crumpled paper under her desk. She picked it up and opened it. It contained some text that had been struck off thrice, but she could still make out that the struck-off text was the email ID and password of Garvit, her classmate. What is ethically correct for Rishika to do? (a) Use Garvit's ID and password to log in and check what he is up to. (b) Use the details to open the account and change the password so that Garvit cannot get in. (c) Post the ID and password on social media so everyone knows Garvit is careless. (d) Call Garvit, tell him about the crumpled paper, and advise him to destroy it and change his password. Justify your answer.Cyber ethics and identity protection

Correct answer: (d) — call Garvit, tell him what she found, and advise him to destroy the paper and change his password immediately.

Why (d) is right. Rishika came to know the credentials by accident, not by any wrongdoing. What decides the ethics is what she does next. Telling Garvit removes the risk, protects him, and involves no misuse of information she was never meant to have. It also fixes the underlying problem: a written-down password is exposed the moment the paper leaves his hand, so he must change it whether or not anyone has used it yet.

Why the others are wrong.

  • (a) Logging in "just to check" is unauthorised access. Curiosity is not permission, and no damage needs to be done for the act itself to be an offence. This is the tempting option because it feels harmless — it is not.
  • (b) Changing the password locks the rightful owner out of his own account. That adds damage to unauthorised access and could be treated as a far more serious offence.
  • (c) Publishing someone's credentials publicly exposes his private data to everyone, invites others to break in, and humiliates him. It violates privacy and net etiquette, and it is closer to cyber bullying than to a lesson in carefulness.

General rule to carry forward: information that reaches you by accident does not become yours to use. Report it to the person concerned and stop there.

3 Sourabh has to prepare a project on the topic "Digital India". He decides to collect information from the internet and downloads three web pages containing relevant material. State whether each of the following actions is plagiarism, copyright infringement, both, or neither, and justify your choice. (i) He copies and pastes paragraphs from all three pages into his project and submits it as his own work. (ii) He copies the paragraphs and mentions the URLs of the three web pages at the end. (iii) He reads all three pages, writes the project in his own words, and cites the three sources.IPR violations — plagiarism vs copyright infringement

Keep two questions separate for every case: did he give credit? (that decides plagiarism) and did he have permission or a licence? (that decides copyright infringement).

(i) Copy-paste with no acknowledgement — both plagiarism AND copyright infringement.

  • No credit was given, and the work is presented as his own, so it is plagiarism, an academic and ethical offence for which he can lose marks or the project.
  • The paragraphs are protected by copyright the moment their authors wrote them, and he reproduced a substantial part without permission, so it is also copyright infringement — a legal wrong, independent of the school's rules.

(ii) Copy-paste with URLs cited — copyright infringement only.

  • Citing the sources removes the plagiarism charge, because he is no longer claiming the words as his own.
  • But acknowledgement is not permission. Reproducing whole paragraphs still needs a licence or a valid fair-dealing exception. Quoting a short extract with quotation marks for the purpose of criticism or review may fall within fair dealing; lifting three full sets of paragraphs does not.

(iii) Read, rewrite in his own words, cite the sources — neither.

  • The expression is his own, and copyright protects expression rather than the underlying facts and ideas, so nothing is being reproduced.
  • He acknowledged where the information came from, so there is no question of plagiarism.

Conclusion: (iii) is the correct way to work. If Sourabh genuinely needs the original words, he should quote a short passage in quotation marks with an in-text citation, or use material offered under an open licence such as Creative Commons and follow its attribution condition.

4 What is a digital footprint? Explain its two types with examples. Is it possible to completely erase a digital footprint? Give reasons.Digital footprints

Definition. A digital footprint is the trail of data a person leaves behind as a result of their activity on the internet. It is not stored in one place; it is spread across the servers, logs and backups of every website, app, network and advertiser the person's device interacted with.

Type 1 — Active digital footprint. Data you deliberately share.

  • Posting a photograph or a reel on a social media account.
  • Writing a comment on a YouTube video or a review on a shopping site.
  • Filling a booking form on IRCTC, or a scholarship application form.
  • Uploading a resume to a job portal, or sending an email.

Type 2 — Passive digital footprint. Data collected about you without any deliberate act on your part.

  • The IP address, browser and device details a website records the moment the page loads.
  • Cookies, especially third-party cookies that follow you from site to site.
  • Location data collected in the background by the phone.
  • Which links you clicked, in what order, and how long you stayed on each page.

Can it be erased completely? No, and it is important to understand why.

  1. The internet copies rather than moves. When you post something, your device does not surrender the data; a copy is created on a server, which then replicates to backups, caches and content delivery nodes. Deleting your copy or your account removes only what is under your control.
  2. Other people hold copies. Anyone who saw the post can screenshot, download or re-share it. You have no authority over their copies.
  3. Logs are kept by law and by practice. Service providers retain access logs for security and legal reasons; those logs are not yours to delete.
  4. Archives and search caches may preserve pages long after the original is taken down.

What you can do instead: reduce the footprint at the source. Post less and think before posting, keep accounts private, refuse unnecessary app permissions, clear cookies, log out of shared computers, use privacy settings, and periodically search your own name to see what is publicly visible. The practical rule is that prevention works and deletion mostly does not.

5 Preeti celebrated her birthday with her family and uploaded selected photographs of the party on a social networking site so that her friends could see them. A few days later, she found that one of her friends had downloaded those photographs, edited them into embarrassing images and circulated them in the class group, and that others were mocking her about them. Identify the cyber offence involved, state what Preeti should do, and mention two precautions that could have reduced the risk.Cyber bullying and social media etiquette

Identification of the offence. This is cyber bullying. A specific person is being repeatedly humiliated through digital means. Two additional wrongs are stacked on top of it:

  • Violation of privacy — her photographs were taken from her account, altered and circulated without her consent.
  • Morphing of images, which is a distinct and serious matter under Indian law and is treated far more strictly when the target is a woman or a child.

Note also that the friends who forwarded the images and joined the mocking are not innocent bystanders; forwarding makes the content their message too, and staying in the group to enjoy it is participation.

What Preeti should do, in order.

  1. Do not retaliate or delete. A reply in anger helps no one, and deleting the group chat destroys the evidence.
  2. Preserve evidence. Take screenshots showing the images, the sender's name or number, and the date and time. Note the group name and members.
  3. Tell a trusted adult — a parent and a class teacher. She has done nothing wrong and has no reason to hide it; secrecy is what lets bullying continue.
  4. Report and block on the platform, and use its reporting tool to have the images taken down.
  5. File a complaint at the National Cyber Crime Reporting Portal, cybercrime.gov.in, which allows complaints relating to women and children to be filed anonymously, or approach the local police cyber cell.

Two precautions that reduce the risk.

  • Restrict the audience. Keep the account private and share personal photographs only with a small, chosen list rather than with the public or with every acquaintance. Review the friend list periodically.
  • Post less, and post later. Share fewer personal images, avoid pictures that reveal the house, school uniform, address or the fact that the family is away, and disable automatic downloads by others where the platform allows it.

Neither precaution shifts the blame onto Preeti — the wrong is entirely the friend's — but both shrink the amount of material available to misuse.

6 What is e-waste? Why is careless disposal of e-waste harmful? List the methods of proper e-waste management.E-waste management

What it is. E-waste, or electronic waste, is discarded electrical and electronic equipment and its components — mobile phones, laptops, desktops, monitors, printers, keyboards, televisions, routers, chargers, batteries and lamps — that have reached the end of their useful life or have been replaced. Because electronic goods are replaced faster than most other household items, e-waste accumulates quickly.

Why careless disposal is harmful.

  • Toxic content. Electronics contain lead (in older CRT monitors and in solder), mercury (in some lamps and older display backlights), cadmium, hexavalent chromium, and brominated flame retardants in the plastics.
  • Soil and water contamination. Dumped in a landfill, these heavy metals leach into the soil and reach the groundwater, entering the food and water supply.
  • Air pollution and human harm. In informal recycling, cables are burnt in the open to recover copper and circuit boards are dipped in acid to recover gold. This releases toxic fumes and acid waste, and directly injures the workers — often including children — who handle it without protection.
  • Loss of valuable material. Electronics also contain gold, silver, copper, palladium and aluminium. Burning or dumping destroys resources that could have been recovered far more cleanly than by mining fresh ore.
  • Data risk. A discarded phone or hard disk that was not wiped is a leak of personal data, because deleted files usually remain recoverable.

Methods of proper e-waste management, in order of preference.

  1. Reduce — buy only what is needed, prefer durable and repairable equipment, and do not replace a working device merely because a newer model exists.
  2. Reuse — donate or sell a device that still works. A laptop too slow for one user is perfectly usable for a junior student, a school or an NGO.
  3. Repair and refurbish — replacing a battery, a screen or a keyboard extends the life of the device and generates no waste at all.
  4. Recycle through authorised channels — hand the item to a registered recycler or dismantler, or to the manufacturer's take-back or exchange programme, never to an informal roadside dealer who will burn it.
  5. Dispose safely — take batteries and lamps to designated collection points; they must never go into ordinary household waste.

Two things to do before parting with any device: back up whatever you need, then sign out of all accounts, remove the SIM and memory card, and factory-reset or wipe the storage.

Legal framework in India. E-waste is regulated by the E-Waste (Management) Rules, 2022, in force from 1 April 2023 and administered by the Central Pollution Control Board. Their central mechanism is Extended Producer Responsibility (EPR), under which the producer must arrange take-back and meet recycling targets for the products it sold. At the international level, the Basel Convention, to which India is a party, restricts the movement of hazardous waste across national borders.

Previous-year board questions 4

Q1 Differentiate between copyright, patent and trademark. Give one example of each. 2020 (board pattern, 3 marks)

All three are intellectual property rights, but they protect different things, are obtained in different ways and last for different periods.

BasisCopyrightPatentTrademark
ProtectsOriginal expression — books, songs, films, photographs, artistic work and computer programsA new, useful and non-obvious invention, whether a product or a processA sign that identifies the source of goods or services — a name, logo, tagline or distinctive packaging
How obtainedAutomatic on creation; registration is optional and serves as evidenceMust be applied for and granted after examinationCan be claimed on use; registration gives far stronger protection
Indian statuteCopyright Act, 1957Patents Act, 1970Trade Marks Act, 1999
DurationFor literary works, the author's lifetime plus 60 years20 years from the date of filing10 years, renewable indefinitely
PurposeReward and control over one's own expressionEncourage invention by trading a monopoly for public disclosurePrevent customers from being confused about who made the product

Examples.

  • Copyright — the text and illustrations of the NCERT Computer Science textbook, or the source code of a program a student writes.
  • Patent — a newly invented water purification process, or a new type of battery cell chemistry.
  • Trademark — the name and logo of a brand such as Amul, or of a bank, printed on its products.

Key distinction to state in one line: copyright protects how something is expressed, a patent protects how something works, and a trademark protects who it comes from.

Q2 (a) Ms. Kavita is not able to understand the difference between identity theft and phishing. Explain both terms to her with one example each. (b) State any two net etiquettes she should follow while communicating online. 2021 (board pattern, 4 marks)

(a) Identity theft. Identity theft occurs when someone obtains a person's personal details — name, date of birth, account number, Aadhaar or PAN details, photographs, login credentials — and uses them to pretend to be that person, usually to gain a financial or other benefit. The essential element is impersonation after the data has been obtained.

Example: A stranger collects Kavita's photograph, date of birth and PAN details from a document she uploaded carelessly, and uses them to apply for a loan in her name. Kavita finds out only when the recovery notice reaches her.

Phishing. Phishing is a technique by which an attacker sends a fake message that impersonates a trusted organisation — a bank, a courier company, IRCTC, the income tax department — in order to trick the victim into revealing confidential information or clicking a malicious link. The essential element is a deceptive message used to make the victim hand over the data.

Example: Kavita receives an SMS reading "Your bank KYC will expire today, update immediately" with a link to a page that looks exactly like her bank's login page. She types her user ID, password and OTP into it, and the money is transferred out.

The relationship between them. Phishing is one of the common methods used to commit identity theft. Phishing is how the data is obtained; identity theft is what is done with it afterwards. Identity theft can also happen without any phishing — for instance through a lost document, a data leak, or shoulder surfing.

(b) Two net etiquettes for Kavita.

  1. Be respectful of privacy. Do not forward someone else's private message, photograph, phone number or document without their permission, and do not share your own confidential details in a group.
  2. Be credible and verify before forwarding. Do not pass on a message merely because it sounds alarming. Once she forwards it, it becomes her message. Checking a claim before sharing is the single most effective way to stop rumours spreading.

(Either of these may be replaced by: be polite and avoid abusive language or ALL CAPS; be ethical and do not use pirated software or someone else's account; be responsible and never take part in trolling or bullying.)

Q3 State any two objectives of the Information Technology Act, 2000. Mention any three changes brought in by the Information Technology (Amendment) Act, 2008. 2023 (board pattern, 5 marks)

Objectives of the Information Technology Act, 2000 (any two):

  1. To give legal recognition to electronic records and digital signatures. Before this Act, an email or an electronic document had no clear standing in Indian law, so an electronic contract could not be relied upon. Recognising electronic records is what made e-governance, e-filing and e-commerce practically possible in India.
  2. To facilitate electronic filing of documents with government agencies and the electronic storage of records, replacing the requirement of paper wherever the law demanded it.
  3. To define cyber offences and prescribe penalties for unauthorised access, damage to computer systems, tampering with source documents and similar misuse.
  4. To provide a legal framework for authentication through certifying authorities, and an adjudication and appellate mechanism for disputes.

The Act was modelled on the UNCITRAL Model Law on Electronic Commerce and came into force on 17 October 2000.

Three changes brought in by the IT (Amendment) Act, 2008 (any three):

  1. Data protection duty on companies (Section 43A). A body corporate handling sensitive personal data must maintain reasonable security practices and procedures, and is liable to pay compensation if its negligence causes wrongful loss to a person.
  2. New offences covering modern frauds. Identity theft (Section 66C) and cheating by personation using a computer resource (Section 66D) were introduced — these are the provisions used against most phishing and OTP frauds. Violation of privacy (Section 66E) and cyber terrorism (Section 66F) were also added.
  3. Recognition of electronic signatures in a technology-neutral form, so the law is not tied to one particular method of signing.
  4. Creation of CERT-In as the national nodal agency (Section 70B) for responding to cyber security incidents and issuing advisories.
  5. An intermediary liability framework (Section 79), giving service providers limited protection for content posted by users, provided they observe due diligence.

Point worth adding for full marks: the amendment also inserted Section 66A on "offensive" messages, but that section was struck down as unconstitutional by the Supreme Court in Shreya Singhal v. Union of India (2015) for being vague and violating freedom of speech. It is no longer valid law, and quoting it as live law is a common mistake.

Q4 Ms. Sunita teaches Computer Science in a school. She notices that girls in her class hesitate to use the lab computers, and that a student with a visual impairment is unable to follow her lessons. Identify any two gender-related issues and any two disability-related issues in teaching and using computers, and suggest one practical solution for each category. 2024 (board pattern, 4 marks)

Two gender-related issues.

  1. Preconceived notions. The widespread assumption that boys are naturally better at machines and programming. Girls absorb this belief, stop volunteering answers and start treating a mistake in the lab as proof that the subject is not for them.
  2. Unequal hands-on time and lack of role models. When computers are shared, a few confident students take the keyboard while the rest watch or write notes, so the students who most need practice get the least. This is reinforced when every example, senior and role model shown in class is male, making the field look like it belongs to someone else. Related factors are less encouragement at home and unequal access to the family's single device.

Practical solution. Sunita should allot lab time and roles by rotation rather than by who reaches the machine first, so that every student — girl or boy — must type, run and debug the program herself in a fixed turn. She should pair this with mixed-gender groups, examples that name women in computing, and a clear rule that teasing anyone for a mistake in the lab is a discipline matter.

Two disability-related issues.

  1. Unavailability of suitable teaching material and aids. Notes, diagrams and on-screen demonstrations assume a student who can see the screen; there is no accessible version for a student who cannot.
  2. Lack of trained teachers and a supporting curriculum, together with physical barriers — a curriculum that assumes mouse-and-screen use, and lab layouts or fixed benches that are hard to reach or use for students with locomotor difficulty.

Practical solution. Sunita should install a screen reader — NVDA is free and open source — on the lab machines, and teach in a way that works with it: read aloud what she types, describe every diagram in words, share notes as accessible text rather than as photographs of the board, and use high-contrast, large-text display settings. She should also make the student's workstation reachable and ask the school for training in assistive tools. The Rights of Persons with Disabilities Act, 2016 requires accessibility, so this is an obligation and not a favour.

Point worth adding: accessible practice helps everybody. Captions on a video help a student in a noisy room, high contrast helps in a bright lab, and clearly described diagrams help students revising from notes at home.

Part of Priodemy for School

Interactive CBSE lessons, Class 8–12 — free with every school on Priodemy EduSuite. Explore more chapters and labs on the Priodemy for School hub.

Ask AI