Once a hacker, always a hacker

Hackers are unfit to serve as security experts

Should we hire criminal hackers as security experts? This is the second of a two-part attack on the idea from a 1995 debate in which I participated.

Consider the message you would be giving some thirteen year old proto-hacker. These kids, like most kids, are tremendously susceptible to peer pressure. They already find criminal hacking attractive because it's viewed as today's counter-culture — something fairly harmless (compared with, say, dealing drugs) but exciting because it's illegal.

Now imagine that the older creeps can announce that they've just been hired by The Man (ie, authority figures) to work in counter-intelligence, snooping in foreign companies' files for money (you don't imagine they'd keep it quiet, do you?). Oh man — not only is criminal hacking glittering with the allure of the forbidden now, but you can hope to earn money with it from the government!

Billboard porn hacker busted

The children and emotionally-arrested adolescents involved in criminal hacking already have a love/hate attitude towards The Man. Many of them claim that they'd like to work for security firms when (if) they grow up. This myth that criminal hacking is a reasonable basis for work in security would become even more pernicious if it were known that more hackers had in fact been solicited and used by government or corporate organisations. Using such people would reinforce the attractiveness of criminality.

Consider the outcry if the military in a democracy actively solicited murderers to be soldiers. The great challenge of military training is to temper savagery with honor; to provide a moral framework within which war is viewed as undesirable, killing as regrettable. A soldier who lies is a stain on his unit’s honor. A soldier who steals is a wretch who deserves expulsion. And a soldier who breaks his word is a traitor to his country. And so how shall we deal with people whose entire way of life is to lie and to steal and to cheat?

I say they're unfit to serve.

At the most fundamental level of all, the end does not justify the means. To use criminals, to honour them, to praise them, to pay them: this would be yet another blow against morality and decency.

And it would be a blow without even the excuse of necessity. We do not need criminal hackers. Information security can be strengthened using the skills of honest people — hackers, if you like, but not criminal hackers. We should be encouraging children who enjoy using computers to learn more, to learn deeper.

We need school teachers who have more than merely a superficial knowledge of the user interface: we need teachers with a thorough grounding in computer science. We need books for children to teach operating systems fundamentals and database theory in an enjoyable, challenging way; we need recognition for the gifted — support for the oddballs who prefer trackballs to basketballs.

We need donations of computer equipment and texts from companies who see that helping kids learn is a wise investment in everyone's future. Why not donate used mainframes and servers to help kids learn about operating systems and networks? Let's give brilliant kids with a knack for security summer jobs so they can use their skills to help society instead of feeling marginalized.

What we don't need is reward for dishonesty and praise for sociopathy.

In the Hacker Debate at the InfoWarCon 95, someone asked me if I recommended blackballing all hackers who engaged in illegal activity in their adolescence. I answered that no, there should not be a lifetime ban on criminal hackers — as long as they show that they understand their moral and legal obligations to society and their employers or clients. If a person shows by their actions that they have matured and now repudiate their former lifestyle, by all means give them a chance. Keep them under supervision, avoid putting them in temptation's way, and be on your guard — but by all means welcome recovering hackers back to society.

Just don't solicit people because they are or were criminal hackers.


Comment

What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.

Characters remaining: 500

Add your commentComments

Jack Daniel | Published: 18:09 GMT, 04 December 2009

I think your position assumes this is a black-or-white issue and it is not nearly that simple. I also object to the misuse of the term "hacker", but we've already lost that battle. While I agree that hiring a former professional computer criminal may not be a great idea, there are a lot of good people who do break the law regularly- as an enormous amount of legitimate security research is technically illegal or otherwise forbidden under strict interpretations of DMCA, EULAs, and such.

Related Security news

Anglia Water signs managed security service contract with SU53

Contract includes upgrade of SAP Governance, Risk Management and Compliance (GRC) solutions

PandaLabs: Hackers create 57,000 malicious pages per week

64 percent of the fake websites are designed to look like legitimate bank websites

Norton releases 2011 version of security software

Norton also announces new application - Norton Power Eraser

Security vendor demonstrates insider attack on VMware ESX

VMware can prevent attacks demonstrated by BeyondTrust



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

IT Manager's guide to buying an anti-spam solution

With these ten critical questions as your guide, you can cut through the marketing hype and zero in on the key features and benefits that should guide your decision.

Download Whitepaper

Unleashing cloud performance

While cloud services aim to eliminate cost and complexity from the world of enterprise IT, the unintended consequences of these services may do exactly the opposite if not carefully planned for.

Download Whitepaper

Online PC backup

This paper looks at the need for laptop and desktop data protection and, based upon recent IDC research, the key requirements firms should consider in evaluating enterprise-level online PC backup solutions.

Download Whitepaper

Protecting your business, customers, and the bottom line

Download this whitepaper to find out more about how you can protect your business from malware.

Download Whitepaper

Techworld UK - Technology - Business

Oracle Video

Enabling agile and intelligent businesses

 Changing markets, competitive pressures and evolving customer needs are placing increasing pressure on IT to deliver greater flexibility and speed. Explore truly flexible SOA foundations with this Oracle video.

Watch
AMD LGF

AMD Opteron™ Resource Centre

Set the foundations for higher speed processing, low energy consumption whilst delivering flexibility and value to your organisation.

Learn More

Win an iPad

How do you view and share technology related content and information? Tell us in our 2010 Media Usage Survey and you could win an iPad.

Complete the survey here

Site Map

IDG Network

* *