Microsoft has a new blog: hackers at microsoft. No, these hackers are not trying to hack into Google to steal the latest search engine technologies. They are good hackers, the white hat hackers.

I never liked this misuse of the term hacker. This idea of ethical hackers originally came from hackers who enjoyed cracking other people's computer systems, but didn't want to be treated as criminals. Companies hired them to improve the security of their systems. They still liked to be called hackers, because being a hacker is just cool, whereas being a penetration tester or security expert is uncool.

My problem with the term white hat hacker is that it plays down the fact that most hackers are or were criminals. Many script kiddies take famous hackers as an example, because being a hacker is really so cool. I wonder just how long will it take until the first terrorist says that he is just a white hat terrorist.

Anyway, I am curious to know what Microsoft's penetration testers have to tell us. I am sure they know of many security holes in Microsoft products. But will they really blog about this? I guess not. Let's hope it will not be just about promoting Forefront products. I have subscribed to their blog.

  1. Andy Bach 16 years ago

    Er, the ‘black hat’ version is ‘cracker’ ‘hacker’ was long the name of the inventive computer geek who tried to hack the code or the box to do something new, like adding external storage to a TRS-80 (or whatever). Only after some of those folks joined the Dark Side and began wreaking havoc that the term began to get a bad rep. “Ethical hackers” is a way to try and get the term back

    See Eric S Raymond’s “How to be a Hacker”
    There is another group of people who loudly call themselves hackers, but aren’t. These are people (mainly adolescent males) who get a kick out of breaking into computers and phreaking the phone system. … Unfortunately, many journalists and writers have been fooled into using the word `hacker’ to describe crackers; this irritates real hackers no end.

    The basic difference is this: hackers build things, crackers break them.

    If you want to be a hacker, keep reading. If you want to be a cracker, go read the alt.2600 newsgroup and get ready to do five to ten in the slammer after finding out you aren’t as smart as you think you are. And that’s all I’m going to say about crackers.


  2. Andy, ask anyone on the street if a hacker is a good or a bad guy and you will always get the same answer. The meaning of a word can’t be defined by a minority. It is based on the way the majority uses it. Of course, you can always change the way you want to use a certain word, but this doesn’t change its meaning. This is how language works. The words “hacker” and “cracker” refer to the same group of persons, although there is a slight difference in their sense. So those journalists you mentioned used the word „hacker“ absolutely correct. They wanted their readers to understand them. So they had to use the word “hacker” as it is commonly used and not how a small group of people wants it to be used. Hackers are the experts when it comes to hacking, but this doesn’t mean that they can determine the meaning of the word “hacker”.

