SynfraCore
Synfracore
Start Learning
Navigation

Academies

Platform

RoadmapsLabsCertificationsInterviewPYQsAI AssistantCareer
Start Learning Free Learning Roadmaps

Digital Safety & Privacy β€” Overview

What it covers and why it matters

πŸ“„
Last updated Aug 2026
Expert Content

Digital Safety & Online Privacy

Before you start: no prior technical background is needed. (Note: legal section details β€” IT Act sections, penalties, DPDP Act specifics β€” reflect India law as of authoring; verify current provisions before relying on them for anything legal, as laws and amendments change.)

Why This Exists (The Hook)

A phishing email doesn't need to fool a security expert β€” it only needs to fool one tired, distracted person for ten seconds, out of thousands of attempts. Attackers exploit exactly that asymmetry: they only need to succeed once, while you need to be careful every single time. Digital safety exists to shrink that asymmetry back in your favor β€” recognizing the small number of attack patterns (urgency, impersonation, requests for OTP/passwords) that cover the overwhelming majority of real attacks, so you can catch them reflexively instead of needing to analyze every message from scratch.

Analogy β€” Think of digital safety like locking your car and not leaving valuables visible, not building a bunker. Most car break-ins are opportunistic β€” an unlocked door or a visible laptop on the seat, not a determined thief defeating a serious security system. Removing the easy opportunity (locking doors, hiding valuables) stops the overwhelming majority of real-world attempts, even though a truly determined, resourced attacker could theoretically still get in. Strong unique passwords, 2FA, and recognizing phishing are your "locked doors" β€” they don't make you invincible, but they stop the vast majority of real attacks, which are opportunistic, not targeted.

Try it (2 minutes) β€” Reason through why "no legitimate organisation asks for your OTP, password, or CVV" is treated as an absolute rule rather than a rule of thumb, without looking anything up: an OTP exists specifically to prove that a request is coming from you, the account owner, at the moment of a legitimate transaction you initiated. If someone calling and claiming to be from your bank asks you to read them the OTP that just arrived, what are they actually trying to do with it β€” and why would a genuine bank employee, who already has access to your account internally, have no legitimate reason to need a code that exists purely to prove YOUR identity to THEM?


Most Common Online Threats

Phishing
Fake messages impersonating trusted entities to steal credentials
Social Engineering
Manipulating people directly -- fake bank calls, fake job offers
Password Attacks
Brute force, credential stuffing, shoulder surfing
Malware
Ransomware, spyware, adware -- damages or steals from your device

Phishing

Fake emails/messages impersonating trusted entities (bank, UIDAI, IRCTC, IT Department) to steal credentials.

Spotting phishing:

β€’Sender email domain doesn't match organisation (e.g. support@incometax-helpdesk.xyz vs incometax.gov.in)
β€’Urgent language: "Your account will be suspended in 24 hours"
β€’Links that look legitimate but redirect differently (hover over link to check real URL)
β€’Requests for OTP, password, CVV β€” no legitimate organisation asks for these
β€’Poor grammar, generic greeting ("Dear User" instead of your name)

Phishing variants:

β€’Smishing: Via SMS β€” fake delivery OTP, fake bank alert
β€’Vishing: Via voice call β€” fake bank/TRAI/CBI officer
β€’Spear phishing: Targeted, personalised β€” uses your name, role, employer

Social Engineering

Manipulating people rather than systems. Common scenarios:

β€’"I'm from your bank's fraud department. To reverse an unauthorised transaction, please share the OTP sent to your phone." β€” Always hang up and call the official bank number.
β€’Fake job offers asking for advance deposits, document fees
β€’Fake lottery/prize money β€” "You've won β‚Ή25 lakhs, pay β‚Ή500 processing fee"

Password Attacks

β€’Brute force: Try all combinations β€” countered by strong passwords and account lockout
β€’Dictionary attack: Try common words/passwords β€” countered by complex passwords
β€’Credential stuffing: Use passwords stolen from one breach to try on other sites β€” countered by unique passwords per site
β€’Shoulder surfing: Watching you type β€” use privacy screens in public

Malware

Malicious software that damages or steals from your device:

β€’Virus: Attaches to files, spreads when file is shared
β€’Ransomware: Encrypts your files, demands payment. Notable: WannaCry (2017), encrypted 200,000+ systems
β€’Spyware: Logs keystrokes, takes screenshots, reads messages
β€’Adware: Displays unwanted ads, may lead to malicious sites
β€’RAT (Remote Access Trojan): Attacker can remotely control your device

Protective Measures

Passwords & Authentication

β€’Strong password: 12+ characters, mix of uppercase, lowercase, numbers, symbols
β€’Passphrase: Easier to remember β€” "Chai@Morning!2024" is strong and memorable
β€’Never reuse passwords: Each account needs a unique password
β€’Password manager: LastPass, Bitwarden, 1Password β€” stores and generates strong passwords
β€’Two-Factor Authentication (2FA): Even if password is stolen, attacker can't login without second factor

- Authenticator app (Google Authenticator, Authy) β€” better than SMS OTP

- Hardware key (YubiKey) β€” strongest

- SMS OTP β€” better than nothing, but vulnerable to SIM swap attacks

Device Security

β€’Screen lock: PIN/pattern/biometric. Auto-lock after 30 seconds.
β€’Encryption: Android: Settings β†’ Security β†’ Encrypt. iPhone: automatic when passcode set.
β€’Software updates: 85% of successful attacks exploit known vulnerabilities with patches available. Update immediately.
β€’Antivirus: Microsoft Defender (Windows) β€” adequate. Malwarebytes for scanning. Avoid fake antivirus pop-ups.
β€’Firewall: Enable Windows Firewall or Mac firewall.

Network Security

β€’Home Wi-Fi: Use WPA3 (or WPA2 minimum). Change default router password. Hide SSID optional but not essential.
β€’Public Wi-Fi: Never access banking or email on open public Wi-Fi without VPN
β€’VPN (Virtual Private Network): Encrypts traffic between your device and VPN server. NordVPN, ProtonVPN, ExpressVPN. Free VPNs often log and sell data β€” avoid.
β€’HTTPS: Always check for padlock + https:// before entering any personal data on a website.

India-Specific Digital Laws

IT Act 2000 & Amendments

Sec 43: Damage to computer system β€” civil penalty up to β‚Ή1 crore

Sec 66: Computer related offences β€” imprisonment up to 3 years and/or fine

Sec 66A (struck down): Offensive online communication β€” removed by Supreme Court in Shreya Singhal (2015)

Sec 66C: Identity theft β€” imprisonment up to 3 years, fine β‚Ή1 lakh

Sec 66D: Cheating by personation using computer β€” same penalties

Sec 66E: Violation of privacy (capturing/transmitting private images without consent) β€” imprisonment up to 3 years

Sec 67: Obscene material online β€” imprisonment up to 5 years

Sec 69: Government power to intercept/monitor β€” requires Home Secretary order

Sec 79: Safe harbour for intermediaries β€” platforms not liable for user content if they comply with takedown notices

DPDP Act 2023 (Digital Personal Data Protection)

β€’Data fiduciary must obtain explicit consent for personal data processing
β€’Data principal rights: right to information, correction, erasure, grievance redressal, nomination
β€’Significant Data Fiduciaries (large companies): additional obligations
β€’Data Protection Board: adjudicates disputes
β€’Penalties: up to β‚Ή250 crore for violations

How to Report Cybercrime in India

Cybercrime Portal: cybercrime.gov.in

Cyber Helpline: 1930 (national helpline for financial fraud β€” report within 24 hours to block money)

Local police: File FIR at nearest police station. Cyber cells in major cities.

Golden rule for financial fraud: If money has been transferred fraudulently, call 1930 IMMEDIATELY. Banks can flag and hold fraudulent transactions if reported within a few hours.


Privacy Settings β€” Quick Actions

Google Account: myaccount.google.com β†’ Data & Privacy β†’ review what's saved

Facebook: Settings β†’ Privacy β†’ restrict post visibility, disable location

WhatsApp: Settings β†’ Privacy β†’ Who can see last seen, profile photo, status β†’ set to Contacts only

Instagram: Settings β†’ Privacy β†’ Private Account β†’ approve followers

LinkedIn: Settings β†’ Privacy β†’ restrict who sees your connections, activity

App permissions (Android/iOS): Settings β†’ Apps β†’ review camera, microphone, location permissions. Revoke any app that doesn't need them.

Share:
Join our Community
Health & wellness tips, coding Q&A β€” join learners growing together
β†’
Up Next
πŸ”€
Digital Safety & Privacy β€” Fundamentals
Core concepts and foundational knowledge
Also Worth Exploring
← Back to all Digital Safety & Privacy modules
Fundamentals β†’