The regimes of ethical hacking
Moral projects and the emergence of a market for vulnerability
Dados Bibliográficos
| ID | 20508239 |
|---|---|
| Autores | David Bozzini (0000-0001-9490-776X, University of Fribourg, autor correspondente) |
| Ano | 2025 |
| Páginas | 1-18 |
| Data de publicação | 2025-05-06 |
| Peer Reviewed | Sim |
| Open Access | Sim |
| Tipo | ARTICLE |
| Periódico | Information Communication & Society (JOURNAL) |
| Identificadores do periódico | ISSN: 1369-118X • E-ISSN: 1468-4462 |
| Editora | Informa UK Limited (PUBLISHER • GB) |
| DOI | 10.1080/1369118x.2025.2498683 |
| OpenAlex | W4410180419 |
| Idioma | EN |
| Citações recebidas | 2 |
| Referências citadas | 22 |
This article examines the historical evolution of ethical hacking and vulnerability disclosure practices from the 1990s to the present day. It analyzes three key disclosure regimes and their emergence: full disclosure, responsible/coordinated disclosure, and bug bounty programs. The full disclosure regime is characterized by an adversarial relationship between hackers and companies, with hackers publicly releasing vulnerability information to pressure companies to improve security. The responsible/coordinated disclosure regime formalizes collaboration between hackers and companies, introducing standards and policies to manage the disclosure of vulnerable information. Finally, the bug bounty regime established a market-based model of disclosure that partially commodified vulnerabilities and transformed ethical hacking into a form of gig work. The analysis reveals how these regimes while building upon existing models, enact distinct moral projects and govern interactions between hackers and companies. It highlights how ethical hacking has been transformed through processes of normalization, standardization, and economization and argues that these transformations resulted from complex interactions between hackers and companies shaped by broader socio-cultural trends and pre-existing practices rather than being the result of a simple co-optation by corporate interests. In doing so, this nuanced historical perspective on vulnerability disclosure regimes demonstrates how a political economy perspective contributes to developing a critical cybersecurity research agenda
Business · Computer security · Environmental ethics · Hacker · Internet privacy · Sociology · Computer Science · Digital Economy and Work Transformation · Ethics and Social Impacts of AI · Philosophy · Privacy, Security, and Data Protection
Small Data, Thick Data
Global socio-technical regimes
Hacked
Venture Labor
A history of crypto-discourse
Discourses of Danger and the Computer Hacker
Brief History of Neoliberalism
Diving in magma
Free Labor
Le nouvel esprit du capitalisme
Hacker practice
Moral Views of Market Society
What Can a Critical Cybersecurity Do
Economization, part 2
| Obras citantes distintas | 2 |
|---|---|
| Citações por ano | 2 |
| Intervalo de citações | 2025 - 2026 (2) |
| Velocidade de citação | current |
| Altamente citado | Não |
| Tipos de citação | Neutras: 2 |