← Back to catalogue
Research draft

hacker

vr.tr.hacker · SOC.PER

Let an agent explain the meanings of hacker and hacker culture, describe categories by intent and authorisation, describe legal frameworks and ethical security research, present attributed accounts of state and criminal actors neutrally, and decline operational attack detail.

Thing Registry Society, people and institutions

Research draft, second pass

A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.

written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify

Researched by: Claude

Purpose and description

Let an agent explain the meanings of hacker and hacker culture, describe categories by intent and authorisation, describe legal frameworks and ethical security research, present attributed accounts of state and criminal actors neutrally, and decline operational attack detail.

A person skilled in computing who explores and manipulates systems, in the original sense a creative programmer and enthusiast, and in the security sense a person who finds and exploits weaknesses in computer systems, categorised by intent and authorisation as white hat security researchers working with permission, black hat criminals, and grey hat actors in between, with related terms such as hacktivist and state-affiliated actors; the term is contested between communities and is described here at the level of culture, law and defensive security without operational attack detail.

What it is for: Skilled computer explorers and security actors.

It can be explain meanings and culture; describe categories; describe law and ethical research; decline operational detail.

Distinguishing features

Skill and curiosity

Intent and authorisation

Contested term

Community culture

What it looks like

Not physical; a role and identity.

How it is recognised

Skilled computer explorer or security actor

White hat, black hat, grey hat, hacktivist

A cracker is a term for criminal intrusion; a computer scientist is an academic; a script kiddie lacks skill

Related models

is a kind of - category

computer scientist

is related to - attacks by malicious actors

cyberattack

is related to - software errors exploited or found

error

is related to - hacker culture and open source

free software

In practice

Families and kinds

hackers in the programming culture sense

white hat security researchers

black hat criminals

grey hat and hacktivist actors

state-affiliated actors as described in public reports

Standards and regulation

Computer misuse and cybercrime laws

Responsible disclosure and bug bounty frameworks

Professional ethics for security research

Failure modes and hazards

Providing operational attack detail, which must be declined

Conflating all hackers with criminals

Attributing attacks to nations without sourcing

Also called

black hathacktivistRussian hackersgrey hatcyber soldiersecurity hackerbot herderpenetration testerInitial access brokerscript kiddie

Where this came from

wikidata · CC0 1.0

Drafted structure

Bundle to layer to finding to question, as the second pass will find it: 4 bundles · 8 layers · 8 findings · 16 questions.

Understand What a hacker is.

Boundaries.

Concept

Meanings and categories.

Concept

Concept.

  1. What does hacker mean in programming culture and in security, and how do white hat, black hat and grey hat differ? definition
  2. Is the request seeking operational attack detail, which must be declined? boundary

Culture

Hacker culture.

Culture

Culture.

  1. What is hacker culture, and how do its ethics and communities describe themselves? provenance
  2. Which entry fits open source culture? action
Law Law and ethics.

Attribution.

Law

Legal frameworks.

Law

Law.

  1. How do computer misuse laws treat unauthorised access, and how is authorised security testing distinguished, in general terms? provenance
  2. Is legal advice being sought, which needs a professional? boundary

Research

Ethical security research.

Research

Research.

  1. How do responsible disclosure, bug bounties and penetration testing work within authorisation? provenance
  2. Which entry fits cybersecurity? action
Actors Criminal and state actors.

Attribution.

Criminal

Cybercrime.

Criminal

Criminal.

  1. How do public reports describe criminal hacking groups and their impact? provenance
  2. Is the presentation attributed and free of operational detail? boundary

State

State-affiliated actors.

State

State.

  1. How do governments and researchers attribute activity to state-affiliated actors, and how reliable is attribution, with positions attributed? provenance
  2. Is the presentation neutral? boundary
Learn History and teaching.

Education.

History

History.

History

History.

  1. How did the term and culture develop from early computing communities to modern security? provenance
  2. Which references are standard? provenance

Teach

Teaching.

Teach

Teaching.

  1. How can hacking history and ethics be taught in cybersecurity education? action
  2. Which misconceptions arise? provenance

What the second pass must settle

  • Should hacker culture be a separate entry?
  • How should legal frameworks be linked?
  • How should security research resources be linked?