Glossary

Glossary terms

Antivirus

A specialized computer program that operates in real-time as a digital immune system, responsible for monitoring, detecting, blocking, and removing malicious files before they can compromise digital identity or cause data loss.

Authenticator Apps

Dedicated software (such as Google or Microsoft Authenticator) that generates temporary, offline verification codes to add a layer of security to accounts, eliminating the risks associated with traditional SMS.

Bark

A commercial parental control application based on artificial intelligence that target-scans chats, messages, and social networks to detect signs of cyberbullying or grooming, notifying the parent only in case of a real threat to protect the minor's privacy.

Behavioral Monitoring / Heuristics

Advanced antivirus technology that analyzes the actions performed by software in real-time instead of just searching for known code signatures, blocking anomalous behaviors caused by zero-day threats or mutating viruses.

Better Internet for Kids

A European Union strategic and non-regulatory policy framework established to fund safer internet centers, promote digital literacy, and foster the empowerment of minors online.

Biometrics

Local authentication systems (such as Face ID or fingerprint scanning) that utilize the user's biological traits stored within the device's secure hardware to unlock sessions or authorize the use of passkeys.

CIE (Italian Electronic Identity Card)

A physical and cryptographic digital identity support that demonstrates the multi-factor approach, requiring a PIN code (something you know) and the smart card or smartphone (something you have) to access institutional services.

Cloud Storage

Internet-based storage networks that transfer and preserve personal data, documents, and photographs on external, remote servers, decoupling them from a single physical device but requiring constant synchronization.

Contextual Security

A modern protection logic that analyses the metadata and timing of a login attempt (the "digital letterhead"), raising authentication barriers only when it detects geographical or behavioural anomalies compared to the user's normal routine.

Cookies (and Tracking/Profiling Cookies)

Small fragments of text stored inside browsers, divided into necessary technical cookies and optional commercial profiling cookies, used by data brokers to map families' browsing habits and create market dossiers.

Credential stuffing

An automated cyberattack technique in which criminals use scripts to massively test databases of stolen emails and passwords across thousands of other websites, exploiting the widespread habit of credential reuse.

Cyberbullying

Repeated bullying, harassment, and aggressive behavior carried out over time by online users against minors through the use of social media and messaging platforms.

Deepfake

Hyper-realistic multimedia content (in video, image, or audio format) generated through artificial intelligence tools capable of cloning human likenesses and voices, used by cybercriminals to orchestrate hyper-personalized family scams.

Dictionary attack

A variant of brute-force attacks in which a hacker employs a list of real words or common phrases, supported by artificial intelligence and specialized software, to attempt to guess a user's access key in sequence.

Digital Services Act (DSA)

A European regulation that establishes strict protections for minors on online platforms, banning manipulative designs and imposing default protection systems to counter the spread of harmful content.

DNS (Domain Name System)

A digital registry that translates website names typed by users into machine-readable numerical IP addresses; filtered DNS versions allow connections to dangerous domains to be blocked directly at the home router level.

Dwell time

A tracking parameter used by social media algorithms to measure to the millisecond how long a user stops scrolling on a post, exploited to outline psychological profiles and create cycles of digital dependence.

Encryption

A mathematical process that transforms readable information into a scrambled, incomprehensible code, ensuring the confidentiality and integrity of personal data both in transit over networks and within storage servers.

ePrivacy

A European Union regulatory framework focused on protecting privacy, data protection, and confidentiality within the electronic communications sector.

EUDI Wallet (European Digital Identity Wallet)

An institutional digital wallet issued by European governments to host citizens' identities and connect to future online age-verification systems without exposing demographic data unrelated to the request.

Evil twin

Counterfeit Wi-Fi hotspots set up by attackers with names identical or similar to legitimate public networks to trick users into connecting, thereby intercepting their credentials and data traffic.

Family Link (Google)

A centralized parental control application within the Android ecosystem that establishes a communication channel between the parent's and the child's phone to manage screen time, approve apps, and monitor geographical location.

Firewall

A cyber security barrier integrated into operating systems tasked with examining and filtering inbound and outbound data flows to prevent unauthorized access to the home network.

Forced consent

A digital tracking and aggressive marketing tactic where a website or social platform blocks access to its services unless the user selects extended data sharing or indiscriminate acceptance of all cookies.

GDPR (General Data Protection Regulation)

A European data protection regulation that establishes legal ownership of information for individual citizens, guaranteeing rights of access, control, restriction, and the right to be forgotten on corporate servers.

Generative Artificial Intelligence

Advanced computational models used by cybercriminals to create dynamic attacks and error-free phishing messages, and integrated into commercial chatbots that store and analyze texts and files entered by users in prompts.

Grooming

A manipulative and psychological online practice used by malicious adults against children or adolescents, often disguised behind false identities within games or social networks.

HTTP (Hypertext Transfer Protocol)

An obsolete network protocol for data exchange that does not apply any encryption, transmitting information in plain text and exposing it to interception and manipulation by third parties along the path.

HTTPS (Hypertext Transfer Protocol Secure)

A secure communication protocol that integrates the TLS protocol to encrypt the transit channel of data between the user's browser and the destination server, preventing local interceptions.

In-app purchases

Financial transactions that occur within applications or video games downloaded onto digital devices, often used as bait for financial fraud against minors.

IP Address (Internet Protocol Address)

A unique numerical code assigned to each device connected to a network, used both to route communications and by security systems as verification metadata for access authenticity.

Keylogger

A type of malicious software or surveillance tool that silently records every keystroke made on a digital device, frequently used by cybercriminals to steal sensitive data such as passwords, private messages, and financial credentials.

Malvertising

The insertion of malicious advertisements into legitimate and famous websites, capable of silently infecting visitors' devices without requiring explicit interaction.

Malware

A generic term grouping all malicious computer programs (including viruses, trojans, spyware, and ransomware) designed to compromise devices or steal personal information.

Man-in-the-Middle (MitM)

A network cyberattack where a malicious actor positions themselves between the victim's device and the web access point to intercept, decrypt, or alter the transmitted data flow.

Metadata

Structured, hidden information embedded within digital files; in the case of photographs, it includes sensitive details such as the exact time, camera model, and GPS coordinates of the location.

MFA Fatigue

A fraudulent tactic based on mass-sending repeated push notifications for access authorization to the victim's smartphone, hoping they will approve the request by mistake or simply to clear their screen.

Multi-Factor Authentication (MFA) / Two-Factor Authentication (2FA)

Multi-level security protocols structured to validate the user's identity through a combination of three distinct pillars: something you know (the passphrase), something you have (the smartphone), and something you are (biometric data).

Parental Control

Software systems and network filters acting at the operating system or router level to restrict access to entire categories of content unsuitable for minors and regulate device usage schedules.

Passkeys

Modern digital credentials that eliminate the use of textual passwords, replacing them with a cryptographic public-and-private key system linked to the user's device and activated via local biometrics.

Passphrase

An extended string composed of a sequence of words or an entire sentence, characterized by high mathematical entropy that makes it unassailable by cracking software, while remaining easy for the human mind to remember.

Password Manager (Digital Vault)

Digital safes protected by end-to-end encryption dedicated to the automatic generation, storage, and secure filling of long, complex, and unique login credentials for each web service.

Phishing

A cyber scam spread through deceptive communications via email, SMS (Smishing), or phone calls (Vishing) designed to replicate the aesthetics of trusted brands and induce the victim to enter passwords or payment details on fake portals.

Public-key cryptography

The mathematical infrastructure behind passkeys that relies on a public key stored on the website's server and a private key residing exclusively on the user's device, neutralizing phishing attempts.

Qustodio

A cross-platform parental control application that combines application blocking tools, web filters based on semantic categories, monitoring of searched videos, and SOS alarm systems with active geographical location.

Ransomware

A class of malware that holds the infected device's files hostage by irreversibly encrypting them, subsequently demanding a ransom payment from the victim to obtain the decryption key.

Scareware

Deceptive warnings and pop-ups designed to generate immediate panic and an artificial sense of urgency in the user, showing fake system infection messages to prompt them to buy useless software or surrender personal data.

Screen Time

A native control panel (present, for example, in Apple systems) that allows monitoring device usage and configuring usage restrictions, app limits, and downtime protected by a dedicated parental passcode.

Session tokens

Temporary digital credentials generated by web servers to keep a user logged into a service without forcing them to continuously type their password; if intercepted by criminals, they can allow unauthorized access to the account.

Signature Matching

A traditional scanning method used by antivirus programs that analyses the digital signature of a downloaded file, comparing it against a static database of already known and catalogued threats.

SIM swapping

A cyber fraud where criminals, using social engineering techniques on phone carriers, manage to transfer the victim's mobile number to a new SIM card in their possession, intercepting security codes sent via SMS.

Smart Home

A domestic ecosystem composed of connected appliances and smart objects that requires strict permission control and turning off hardware listening modules to prevent the monetization of private habits.

Smishing

A subcategory of phishing activities conducted exclusively through sending fraudulent SMS text messages to the victim's mobile phone.

Social Engineering

A set of manipulative techniques based on the study of human psychology aimed at inducing victims to perform imprudent actions or reveal confidential data by exploiting emotional levers such as anxiety, fear, or urgency.

Spear-phishing

A targeted evolution of classic phishing that uses real personal information about the victim (such as name or recent purchase details) gathered from the web to structure highly personalized and extremely convincing bait.

SPID (Public Digital Identity System)

An Italian digital identification infrastructure that adopts multi-factor protocols to guarantee secure and certified access to Public Administration portals.

Spyware

Malicious software configured to operate in the background without the user's knowledge, aiming to collect private data, monitor movements via GPS, or activate the microphone and camera to record the surrounding environment.

Stalkerware

Commercial applications for covert monitoring that require disabling the operating system's native defenses (rooting or jailbreaking) to hide, creating severe structural vulnerabilities that expose data to external leaks and hacking.

Synthetic Identity Theft

A fraud technique where criminals combine a minor's real, unblemished data (such as identification codes or birth dates) with entirely fabricated elements, creating a "ghost" profile to open fraudulent credit lines.

Trojan

Harmful software disguised as legitimate applications, text documents, or free video games, designed to trick users into voluntarily installing it on their device, opening a breach for data theft.

Vishing

A variant of phishing executed through direct voice calls, where scammers use social engineering and sometimes voice cloning to impersonate bank operators or relatives in distress.

VPN (Virtual Private Network)

A software service that creates an encrypted communication tunnel between the user's device and the internet, masking the IP address and protecting sensitive data from interception when connecting to public or unsecured Wi-Fi networks.

Windows Defender

A security and antivirus suite natively integrated within the Microsoft Windows operating system, developed to offer basic protection and a system firewall at no additional cost.

Zero-Knowledge Architecture

A structural security model applied to personal password managers where data is encrypted on the device and the service provider holds no master key, making account recovery impossible in case of loss.

Zero-Knowledge Proofs (ZKP)

Advanced cryptographic protocols used in modern age-verification systems (like the European EUDI Wallet) that allow a software to answer a specific question (e.g., "Is the user of legal age?") by providing a binary answer without transmitting or revealing the underlying demographic data to the external server.