A simple observation:

"White Hat Hacker" is NOT synonymous with "Ethical Hacker"

You can legally protect an unethical corporation and in doing so, you are an accomplice to their unethical actions.

You can ethically hack to protect people and still be conducting illegal activities.

Do not conflate the two terms.

#hacking #infosec

@tinker

Can you give an example of an ethical hacker that isn't a white hat?

#hacking #infosec

@chiclet - Sure! The two most common examples of Ethical Hackers that are not Corporate / Legal "White Hat" Hackers are:

  • Folks who hack software that affects people's safety and security (even without permission) and report those vulnerabilities, either to the corporation directly or publicly - with the intent to have the vulnerability patched. Regardless of where the software sits (thick client on hacker's box or web app on a corp's servers), this has often been met with lawsuits and criminal charges against the ethical hacker.

  • Folks who hack with the intent to destroy, sabotage, or otherwise hinder unethical corporations. Phineas Fisher was an example of this. Hacked Gamma Corp and Hacking Team which were making malware and spyware used by despotic governments to track journalists, activists, and other enemies of the despotic state.

Edit to mention: There are other examples, these are just to two prominent examples. It can help to step back even from hacking. Think of examples where breaking the law is the ethical thing to do. Harboring slaves pre-US Civil war. Harboring Jews during Nazi Germany. These were illegal things that were the ethical thing to do. Now find similar examples in regards to hacking. What is something that you can hack for an ethical purpose but is also against the law.

#hacking #infosec

@tinker @chiclet Another (good) example: Hacking for the right to repair - like that episode with the locked down train software in Poland.

https://gizmodo.com/hackers-hit-with-legal-threats-after-they-fixed-a-brick-1851097424

Hackers Hit With Legal Threats After They Fixed a 'Bricked' Polish Train

The hackers claim Polish trains were deliberately bricked by the manufacturer and they were just providing a service. “It’s DRM gone wild.”

Gizmodo