The Paradox of Grey Hat Hackers (windowsitpro.com)
v3rgEz writes: Troy Hunt, a security researcher who tracked breached websites, reflects on the recent "grey hat" hacking of VTech, in which a hacker downloaded millions of kids' photos, chat logs, and more, to blow the whistle on a serious vulnerability. The attacker went way beyond responsible disclosure, offering the data directly to a reporter, but the ensuing publicity got VTech to clean up their act and maybe helped parents better understand the dangers of lax security. Is grey hat ok when it's done for the greater good?
A hacker group hacked my school's website last year... They posted about it on their facebook page and the kids from my school commented on the post. They responded that they were doing this to help the school website be more secure by showing one of the bugs. They even "backed up" our server data supposedly. If they hadn't pointed out the security bug by hacking the website and replacing it with a page showing their logo and asking us to like their facebook page (and playing pretty EPIC music by the way) our website could have been more at risk to another hacker with perhaps not so benevolent intentions. To think if this was a credit card company or something you would want to know if there were security issues or bad stuff could happen.
Hacking in and blowing the whistle without doing any damage can earn the same jail time as making a mess that cannot be ignored so at least the Judicial system does not see it as any worse.
Is it OK?
The people embarrassed or inconvenienced will always say no even if it is "white hat" hacking and even if it is to the great benefit of society as a whole.
Someone will always say no, it's not OK - so run like Snowden even if you are exposing crimes.
P.S. The sad reality is a lot of web platforms are shit that is full of holes run by people that don't care. Exposing a hole is like pointing out a starlet is not wearing pants - both to be expected and will get you in trouble if you provide evidence.
You will not win any medals by pointing out a way to get into a poorly secured website and even well intentioned reports have landed people in deep shit.
> Is grey hat ok when it's done for the greater good?
Yes. It's great for all the people who benefit. It sucks for the person who put their liberty at risk to bring those benefits to people.
I should use this sig to advertise my book ISBN-13 : 978-1501515132.
This dichotomy is the whole point for the Grey Hat moniker. There is no Black and White, it is always shades of Grey,.
One man's Black Hat is another's White Hat. Where many Black Hats believe they are fighting for the greater good and conducting Illegal activities but for ethical reasons and also so called White Hats acting legally but unethically while taking the corporate dollar.
When I was a kid, I didn't believe my mother when she told me not to touch the hotplate. The pain of burning my palm was a memorable lesson, though. Here, it's the difference between "I could have deleted your hard disk" and "So your hard disk has been formatted? Well, if you can explain to me how this could have come about, I might even provide you with a backup copy." It may not feel quite right to think of hacker kids as educators of the general public -- wasn't that a transient phase of the 80's? -- but while the current state of general irresponsibility in matters of systems security persists, we do need the occasional burnt palm.
On learning of a vulnerability, most companies have demonstrated one of two responses:
1) Ignore it, or
2) Attack the messenger.
Given that corporate climate of "hostile indifference" to their own flaws, grey-hats fill a very necessary niche. No more of this kumba-ya "tee hee, would you mind fixing this embarassing massive security breach, Mr. Fortune-500 CIO" bullshit - Just name and shame right up front.
The "nice" way would work well if anyone cared; until it makes the NYT, though - No one cares. So lets stop giving Russian hackers an extra six months to exploit known problems, and skip right on to the NYT solution.
Old discussion, rehashed. /. could use a "re-post my comment from 2002" feature.
There are two sides, and they will never reconcile. Some people think (based on past experience) that corporations generally won't take security seriously unless it impacts their business or their image, so only disclosure works. Other people think (based on past experience) that disclosure reads to the creation of exploit toolkits which leads to higher damage to more people and gives vendors not enough time to fix a problem. And a few especially delusional people think that a timer on disclosure and a few rules to make the whole thing "responsible" solves the unsolvable problem (it doesn't. Vendors will a good track record already fix quickly, vendors with a bad track record merely consider the delay additional time they don't have to do anything.)
And I think that pretty much sums it up, everything else is just elaboration.
Assorted stuff I do sometimes: Lemuria.org
Snowden was down to choices really do nothing more and just give up or release at least as much of what he had as he did.
He tried the official channels was ignored. The 'public' as a whole was not prepared to listen without some demonstration made. People who thought the NSA and more broadly the intelligence complex was up to no good already had reason to suspect much of what Snowden disclosed. We knew this from inferences that could be drawn about data center sizes, power being used, purchases of equipment that were public, whisperings form employees at various telco and equipment vendors etc. There was just no solid proof. It was to easy to get everyone who was speaking out dismissed as conspiracy nutters by a public that just wanted to feel 'safe'
Any foreign intel operators probably knew even more and were not the least bit surprised, they were most likely operating already under the assumption the NSA monitoring capabilities were at least at the level the Snowden releases indicated. If the officials want us to believe any real harm was done, I say its on them to show some proof of that!
The only harm Snowden did to the NSA and its efforts was political. Had he released any less nobody would have paid attention.
Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html