1.
CHAPTER 5
2. SOCIAL, ECONOMIC, ETHICAL AND LEGAL IMPLICATIONS OF
COMPUTERS
Introduction
Computers have had many effects on individuals in society. They have impacted on the way
individuals work, socialize and run their lives. As a result of computers, an individual's values
are now in constant flux. The moral and ethical framework that guides an individual is constantly
changing as is the economic and legal framework within which lives are led.
3. Social and Economic Effects of Computers
The widespread use of computers has affected people and organizations in many ways. Some of
the effects of computers include:
The introduction of computers have made some jobs outdated leading to unemployment
New jobs have been created like engineering to build machines, software programming to
write programs for the computers, etc
There is reduction in working hours as a result of automation of some tasks which can lead
to reduction of salaries.
The introduction of computers has led to retraining or reskilling as many employees have to
be trained on how to use a computer.
Automation of tasks can lead to difficult jobs becoming easy so anyone can do them. As a
result, a skilled employee suddenly is the proud possessor of skills that no-one needs any
more.
Automation of tasks has led to an increase in productivity thereby improving the profit of
the organization.
Computers have led to new types of crimes like phishing, identity theft, piracy etc
The post office has become more of a bill paying center than a communication center as it
is now faster and cheaper to communicate online through emails and chats.
More information can be stored on very little space
Privacy has become a concern as confidential data stored in computers or distributed on
networks can be intercepted by hackers and crackers.
4. Computer Crimes
A computer crime is any illegal act that involves the computer either as the target of the crime or
as a tool used in committing the crime. When the computer is the target of the criminal act, the
crime is said to be a computer-related crime. When it is a tool used to commit the crime, the crime
is referred to as a computer-assisted crime.
Page 1 of 10
4.1. Types of Computer Crimes
4.1.1. Phishing
Phishing is the criminally fraudulent process of acquiring or attempting to acquire sensitive
information such as usernames, passwords and credit card details by masquerading as a
trustworthy entity in an electronic communication. The phisher sends out an e-mail that pretends
to come from a bank or corporation with which the victim has an account.
The e-mail message tells the victim to click on a link in order to handle some kind of urgent
business. In reality, both the message and the link are counterfeit, and the victim ends up giving
their password or credit card information to the phisher, or at the very least, visiting a web site
that disseminates malware.
4.1.2. Software Piracy
Software piracy or copyright infringement is the illegal (unauthorized) reproduction of
copyrighted or patented software for personal use, for sale or free distribution. It is the most
widely practiced type of computer crime. Software piracy occurs more easily with the ability to
post files for downloading all over the world. However, another more costly copyright
infringement occurs when trademarks and logos of corporations are posted on non-authorized
web sites. Some criminals utilize the trademarks and logos to appear to be a legitimate site to
perpetrate fraud. Many corporations have employees or consulting contractors who constantly
crawl the web to sniff out illegal usage of trademarks and logos.
4.1.3. Malware Attacks
Malware (malicious software) is any software that could harm a computer system, interfere with
a user's data, or make the computer to perform actions without the owner's knowledge or
permission. Examples are virus, worms, Trojan horse, spyware and logic bombs.
4.1.4. Denial of Service
A denial or degradation of service (DoS) is an attack to a computer system that puts it out of
action by overloading it with data in a way that the system was never prepared to handle. A DoS
attack makes the system unavailable to its intended users. A distributed denial-of-service (DDoS)
attack is one in which a multitude of compromised systems attack a single target, thereby causing
denial of service for users of the targeted system.
4.1.5. Social Engineering
Social engineering refers to a non-technical kind of intrusion that relies heavily on human
interaction and often involves tricking other people to break normal security procedures. A person
using social engineering to break into a computer network might try to gain the confidence of an
authorized user and get them to reveal information that compromises the network's security.
Social engineers often rely on the natural helpfulness of people as well as on their weaknesses.
4.1.6. Cyber Stalking
Cyber stalking is a crime in which the attacker harasses a victim using electronic communication,
such as e-mail or instant messaging (IM), or messages posted to a web site or a discussion group.
Cyber stalking messages differ from ordinary spam in that a cyber-stalker targets a specific victim
Page 2 of 10
with often threatening messages, while the spammer targets a multitude of recipients with simply
annoying messages.
4.1.7. Cyber Terrorism
Cyber terrorism can be defined as an act of terrorism committed through the use of cyberspace
or computer resources. As such, a simple propaganda in the Internet, that there will be bomb
attacks during the holidays can be considered cyber terrorism.
Other types of crimes are: scamming, theft of computer equipment, pharming, spoofing, and
phreaking.
4.2. Measures to Combat Computer Crimes
The following measures can be used to combat computer crimes:
Install strong doors and locks to computer rooms to prevent computer equipment theft.
Use access control mechanisms that will ensure confidentiality, integrity and availability.
Encrypt confidential data stored in computers or transmitted over communication networks.
Install antivirus software and update it regularly
Install intrusion detection systems to help detect any unauthorized access to the system.
Install firewalls to prevent unauthorized access to local networks.
5. Computer Systems Security
Computer system security is the process of preventing and detecting the unauthorized use of
computer systems. Prevention helps stop unauthorized users from accessing any part of the
computer system by controlling access to the system, while detection helps determine whether or
not someone attempted to break into the system, if they were successful, and what they may have
done.
Computer security has three main goals, confidentiality, integrity and availability, which can be
conveniently summarized by the acronym "CIA":
Confidentiality ensures that information is not accessed by unauthorized persons. In other
words, it ensures that information is kept secret or private.
Integrity ensures that information is not altered by unauthorized persons in a way that is not
detectable by authorized users. That means that there is an external consistency in the system
- everything is as it is expected to be.
Availability ensures that the system is accessible and useable upon appropriate demand by
authorized users. In other words, this means preventing denial-of-service.
Different mechanisms used to ensure the security of computer systems are authentication,
encryption, firewalls, digital signatures, etc.
5.1. Authentication
Authentication is the process of determining if someone is who they declare to be. In simple
terms, it is proving someone’s identity. Authentication can be obtained by the user providing
something they know (password), something they have (smart card) or something they are
(biometrics).
Page 3 of 10
5.1.1. Passwords
A password is a secret sequence of characters that is required to login to a system, thus preventing
unauthorized persons from gaining access to the system. When authentication is done through
the use of a password, knowledge of the password is assumed to guarantee that the user is
authentic. Passwords can be guessed or cracked and so if anyone is using a password to protect
their system, the following guidelines will help make it more secure:
Don’t choose an obvious password (like your name, date of birth or name of relative)
Keep your password secret. Don’t share it!.
Change your password regularly but not too often.
Make your password at least eight characters long.
Do not use common or proper words of phrases - these can be found using a dictionary
cracker.
Use a mixture of upper and lower case letters and numbers.
5.1.2. Smart Card
A smart card is a small card that holds user authentication information. When the card is inserted
into a card reader, electrical fingers wipe against the card. The information in the card is read and
used to authenticate the person. Cards can be stolen and so are not as reliable as biometrics.
5.1.3. Biometrics
Biometrics is the science and technology of measuring and analyzing biological data. In computer
security, it refers to the use of measurable biological characteristics such as fingerprints, eye
retinas, iris patterns, facial patterns, voice patterns, hand measurements and DNA, to identify a
person. It is the safest authentication technique.
Assignment: What do you understand by access control?
Answer: The limitation and control of access to a system through identification and
authentication. Or The process of limiting access to a system only to authorized users. This
can be achieved through identification and authentication.
5.2. Encryption
Encryption is the process of transforming a message using an algorithm into a form unreadable
by anyone except the intended recipient. The original message is known as plaintext, the
algorithm is cipher and the encrypted text is ciphertext. To read an encrypted message, one must
have access to a key that will enable them to decrypt it.
Encryption ciphers can be grouped into two: substitution and transposition ciphers.
5.2.1. Substitution Ciphers
A substitution cipher is one in which the letters of the original message are replaced by other
letters according to a key. Many substitution ciphers use only one alphabet, and are called
monoalphabetic ciphers. This means that we substitute one and only one letter for a particular
letter in the message.
Page 4 of 10
For example, every T in the message is replaced by the same substitute letter or symbol. Such a
cipher scheme is easy to remember, but is also vulnerable to "cracking" using frequency analysis
(letter counting).
In order to make substitution ciphers more secure, more than one alphabet can be used. Such
ciphers are called polyalphabetic ciphers, meaning that the same letter of a message can be
represented by different letters when encoded. Such a one-to-many correspondence makes the
use of frequency analysis much more difficult in order to crack the code. Examples of substitution
ciphers are Caesar cipher and Vigenere cipher.
a. The Caesar Cipher
The Caesar or shift cipher, named after Roman emperor Julius Caesar, is a monoalphabetic
substitution cipher in which each letter is translated into the letter a fixed number of positions
after it in the alphabet table. A key number k is agreed upon by the sender and the receiver, then
the standard alphabet is shifted k positions so that the k-th letter in the alphabet is substituted for
letter A, the k+1st for B, [Link] alphabet is wrapped to maintain a one-to-one correspondence.
Example:
Suppose k = 3
Plain text letter: ABCD… WXYZ
Cipher text letter: DEFG…ZABC
Hence, the message: COMPUTING GIVES INSIGHT
Is translated into: FRPSXWLQJJLYHV LQVLJKW
b. The Vigenere Cipher
The Vigenere cipher is a polyalphabetic cipher based on using successively shifted alphabets, a
different shifted alphabet for each of the 26 English letters. The procedure is based on the table
below and the use of a keyword. The letters of the keyword determine the shifted alphabets used
in the encoding process. SEE NEXT PEAPER
5.2.2. Transposition Ciphers
A transposition cipher is one in which the letters of the original message are rearranged without
otherwise changing them.
a. Columnar Transposition
A columnar transposition cipher enters the plaintext into a rectangle of a predetermined width
and extracts cipher text by columns from left to right.
E N J O Y
T H E B E
Example 1: A U T Y O
Plaintext: ENJOY THE BEAUTY OF SCIENCE F S C I E
Ciphertext: ETAFN NHUSC JETCE OBYI YEOE N C E
T H E F U T
U R E I S B
Example 2: Key: ORANGE Plaintext: THE FUTURE IS BRIGHT R I G H T
O R A N G E
Ciphertext: TUR HRI EEG FIN UST TB
b. Rail Fence Cipher
Page 5 of 10
Rail fence writes the plaintext in a zig-zag pattern in two or more rows and forms the ciphertext
by reading off the letters row by row from the first.
Example 1:
R N
Plaintext: WE ARE HAVING FUN A E I G
Cipher text: RN AEIG EHVFN WAU E H V F N
W A U
Example 2:
Cipher text: SL IIIFE HSAEC TRN S L
I I I F E
H S A E C
T R N
Plaintext: THIS IS RAIL FENCE
5.3. Firewall
A firewall is a system designed to prevent unauthorized access to or from a private network.
Firewalls are implemented in either hardware or software form, or a combination of both. They
prevent unauthorized Internet users from accessing private networks connected to the Internet.
All messages entering or leaving the network must pass through the firewall which examines
each message and blocks those that do not meet the specified security criteria. Some Operating
Systems like Windows XP, 7 and Mac OS X, have built-in firewalls.
5.4. Intrusion Detection
Intrusion detection is the art and science of sensing when a system or network is being used
inappropriately or without authorization. An intrusion-detection system (IDS) monitors system
and network resources and activities and, using information gathered from these sources, notifies
the authorities when it identifies a possible intrusion.
5.5. Digital Signatures
A digital signature is a computed digest of a message that is encrypted and sent with the message.
The recipient decrypts the signature and compares it with the received text. If they match, the
message is authenticated and proved intact from the sender.
Digital signatures also ensure non-repudiation. Non-repudiation is the prevention of either the
sender or the receiver denying a transmitted message. A system must be able to prove that certain
messages were sent and received.
5.6. Fault Tolerance
6. Computer Ethics
Ethics refers to the principles of right and wrong that individuals, acting as free moral agents, use
to make choices that guide their own behavior. Ethical principles place a value on human acts
according to whether they are good or bad.
Computer ethics refers to standards of good conduct applied within the use of computers. It
defines principles for judging computing acts whether they are good or bad.
Page 6 of 10
6.1. Fundamental Principles of Computer Ethics
The fundamental principles of computer ethics formulated by the Computer Ethics Institute (CEI)
as the“ten commandments” of computer ethics are:
1. Thou shall not use a computer to harm other people.
2. Thou shall not interfere with other people’s computer work.
3. Thou shall not snoop around in other people’s files.
4. Thou shall not use a computer to steal.
5. Thou shall not use a computer to bear false witness.
6. Thou shall not copy or use proprietary software for which you have not paid.
7. Thou shall not use other people’s computer resources without authorization or proper
compensation.
8. Thou shall not appropriate other people’s intellectual output.
9. Thou shall think about the social consequences of the program you write or the system you
design.
[Link] shall use a computer in ways that show consideration and respect for your fellow
humans.
6.2. Netiquette
Netiquette is short for network etiquette. It is a set of rules about acceptable behavior when
communicating over the Internet. Some basic rules of netiquette are:
Avoid flaming i.e. using obscene or inappropriate language in your emails or posts
Avoid using capital letters in your emails/comments, it is considered like YOU ARE
SHOUTING and it is harder to read.
Avoid sloppiness i.e. avoid spelling and grammatical errors. Re-read and edit your
emails/comments before you send/post
Do not send huge file attachments unless they are requested
Always fill the subject field of an email before you send
Do not format your emails with colored text or background color. They may cause them
hard to read.
Legislation
Legislation is the act of making and passing [Link] laws that govern the use of computers
area the Data Protection Act, the Computer Misuse Act, the Copyright, Design and Patent Act,
and the Health and Safety Act.
6.3. The Data Protection Act
It is aimed at protecting the rights of individuals to privacy. Some Data Protection Act rules are:
1. If an organization holds data on individuals, it must be registered under the act.
2. Personal data should be processed fairly and lawfully
3. Personal data should not be disclosed in anyway other than lawfully and within the
registered purpose.
4. Personal data should be adequate and relevant and not excessive for the required purpose.
5. Personal data should be kept accurate and kept up to date
6. Data must be processed in accordance with the right of the data subject
Page 7 of 10
7. Appropriate security measures must be taken against unauthorized access
6.4. The Computer Misuse Act
This act makes it an offence to access any computer to which you do not have an authorized right
to use. It introduces three criminal offences:
1. Unauthorized access to computer material.
2. Unauthorized access with intent to commit or facilitate commission of further offences.
3. Unauthorized modification of computer material.
6.5. Copyright, Design and Patent Act
This Act is designed to protect all types of intellectual property and ensure that authors or creators
of a piece of work receive both credit and compensation.
Copyright is a statutory grant that protects original work. Something that is copyrighted is
not to be reproduced, published or copied without permission from the copyright holder.
Ideas are not protected by copyright; only the specific presentation of the idea is
copyrightable.
Design is the appearance or construction of something. A design is not immediately
protected. It must be registered with the appropriate institution,
A Patent is a grant to inventors that give them exclusive monopoly over their invention. It
gives them the right to stop others from producing, selling or using their invention. Unlike
copyrights, patents protect the ideas or design of the invention rather than any tangible form
of the invention.
6.6. Health and Safety Act
The original Act and its many added regulations cover the range of hazards an employee may
face like handling hazardous material. Some of the regulations that apply to the computing
industry are:
Display Screen Equipment Regulations
They cover the precautions that must be taken when an employee uses a visual display unit. The
regulation covers items such as the chair which must be adjustable, the desk which must be at the
appropriate height, the monitor which must be adjustable and the lighting which must be
appropriate.
Moving and Handling Regulations
These regulations lay down the rules for safe moving of heavy objects. All employees involved
in such activities must receive proper training on avoiding injury when moving heavy objects.
Control of Substances Hazardous to Health (COSHH)
These regulations cover the safe storage and use of hazardous materials. This includes items such
as laser printer toners and anyone involved in replacing such items must be made aware of the
potentially toxic nature of toners.
Assignment: State what you understand by the following terms.
i) Digital inclusion
ii) Digital divide.
Page 8 of 10
7. Computers in the Workplace
It is important to note that in as much as the computer is a very vital tool for everyone’s daily
use, it can also be a very harmful tool if poorly used. Using the computer for prolonged periods
of time can lead to physical health risks. For this reason, users must ensure that they follow health
measures and apply safety precautions as they use the computers to avoid computer related
disorders.
7.1. Computer Related Disorders
CRDs are health problems associated with prolonged computer usage. They include repetitive
strain injury, carpal tunnel syndrome, eyestrain and headache.
7.1.1. Repetitive Strain Injury
Medically defined as cumulative trauma disorder (CTD), it is a debilitating health condition
resulting from overusing the hands to perform a repetitive task such as typing, clicking a mouse
or writing. RSI results in damage to muscles, tendons and nerves of the neck, shoulder, forearm
and hand which can cause pain, weakness, numbness or impairment of the motor control.
Symptoms are tightness, discomfort, stiffness, burning sensation in the hands, wrists, fingers,
forearms and elbows. Tingling, coldness and numbness of the hand with loss of strength and
coordination occur. There is pain in the upper back, shoulders and neck and need for massage.
7.1.2. Carpal Tunnel Syndrome
7.1.3. Computer Vision Syndrome
7.2. Ergonomics
Ergonomics refers to the application of scientific knowledge to the workplace in an effort to
improve the well-being and efficiency of workers. Simply put, it is the study of human factors
related to things people use. These factors include workstation layout, sitting posture, lighting,
viewing distance etc.
7.2.1. Workstation Layout
Workstation layout has to do with the arrangement of the computer and related products, in the
workplace. Appropriate placement of workstation components and accessories allows one to
work in neutral body position which will enable them perform more efficiently, work more
comfortably and safe. The layout for a comfortable and productive workstation involves the
following:
a. Desk or Work Surface Areas
Limited space on the work surface may cause users to place components and devices in
undesirable positions. This may lead to awkward postures as you reach for a mouse/keyboard or
look at a monitor that is to the side. Working with your neck turned to the side prolonged periods
load neck muscles unevenly and increase fatigue and pain.
b. Areas under the Work surface
Inadequate clearance or space under the work surface due to poor design may result in discomfort
and performance inefficiencies.
Page 9 of 10
c. Placement of components
Placing components e.g. mouse, telephone, far away from you can cause you to repeatedly reach
out for them resulting in strain on the shoulder, arm and neck.
7.2.2. Sitting Posture
Working with the body in a neutral position is important. It reduces stress and strain on the
muscles, tendons and skeletal system thereby reducing your risk of developing musculoskeletal
disorders. For a good sitting posture the following points are vital:
The monitor should be set so that your neck will be straight
Your elbows should stay close to the body and be bent at about 90o, with your upper arms
hanging naturally from the side.
Keep your hands in line with the fore arms so your wrists are straight. You may use a wrist
rest or arm rest to help keep your wrists straight and your arm muscles from being
overworked. Performing task without a wrist rest may increase the angle to which user’s
wrists are bent. Increasing the angle of bend increases contact stress and irritation on tendons
and tendon sheaths.
Your feet should be fully supported by the floor or a footrest should be used if the heights
of your table and chair are not adjustable.
Your back should be fully supported with a lumbar support when sitting vertical or leaning
back slightly.
Your thighs should be parallel to the floor
Regardless of how good your working posture is, working in the same posture or sitting still for
prolonged periods is not healthy. You should change your working position frequently by
Making small adjustments to your chair or backrest
Stretching your fingers, arms and torso
Walking around a few minutes periodically
7.2.3. Lighting
When a computer work environment is planned both overall lighting and positioning of lights
and windows must be considered. Overhead lights and windows are sources of glare that may
mask whatever is shown on the screen resulting in visual fatigue and discomfort. There are three
types of glare: direct, indirect and masking.
Direct glare occurs when there are bright light sources directly in the operator’s field of view.
Windows are often a source of direct glare.
Indirect glare occurs when light from windows or overhead lights is reflected off shiny
surfaces in the field of view.
Light from sources directly overhead causes masking glare on the screen.
The use of light absorbing blinds and curtains will help reduce both direct and indirect glare.
Placing the monitor in an appropriate position can help reduce overhead or masking glare. Glare
can also be prevented using an anti-glare screen filter.
Page 10 of 10