PERSPECTIVES FROM THE CAMPUS
One of the strengths of Indiana is that we bring together a variety of perspectives from the plethora of areas that touch the field of cyber, especially through the colleges, universities, and other institutions of higher education throughout our state. Hence the name, “Perspectives from the Campus”, we invite experts – immersed in the pursuit of educating their students – to offer their knowledge for finding solutions in cybersecurity that benefit all Hoosiers.
In the latest installment of this series, David Dungan, who serves as the executive director at the Center for Security Services and Cyber Defense at Anderson University, discusses what’s behind the term “hacker” and why the color of their hat is critically vital to understanding the work (be it good or bad) that they’re doing.
By David Dungan
In baseball, there’s an expression that says, “you can’t tell the players without a scorecard”.
The same is true, you might say, when it comes to cybersecurity. You can’t tell a hacker without knowing the color of their hat.
That’s because the word “hacker” is often misunderstood. There are many different kinds of hackers, and learning to distinguish between them can equip you to make more informed and effective decisions. Borrowed from the old Western movies, where heroes wore white hats and villains wore black, security experts use “hats” to describe the different intentions and methods hackers may have. Understanding these categories highlights why it is valuable for security professionals to also think like a hacker.
White Hat
Bruce Schneier, a well-known security expert, once said “I believe the best computer security experts have the hacker mindset.” We call these people white hat hackers, more professionally known as pentesters or ethical hackers. They find and fix vulnerabilities before criminals can exploit them, shaping their careers around “thinking like the bad guy” but with the goal of keeping our data and systems safe.
Black Hat
Black hat hackers, on the other hand, are motivated by profit, power, and disruption. They exploit security flaws to steal data, spread malware, or cause damage. Unlike white hats, their work is illegal and harmful, often resulting in significant financial or reputational loss for their victims.
Grey Hat
Grey hat hackers fall somewhere in the middle; they don’t always play by the rules, but act with what they believe to be good intentions. They often uncover security flaws without permission from the company or individual, usually offering to disclose the discovery for profit, or simply for gratification. Adrian Lamo, known as the “Homeless Hacker” falls into this grey hat category; he successfully hacked several major companies, offering to fix these vulnerabilities for free, but was instead met with legal action for unauthorized access.
Additional Colors
- Red Hat hackers are a mix of white and black hat hackers and act like the vigilantes of the hacking world. The goal of red hat hackers is to fight back against black hat hackers and stop them from causing harm.
- Green Hat hackers are new to the world of hacking. These hackers aren’t the most skilled or knowledgeable but are dedicated and determined to learn, finding their place in the community.
- Blue Hat hackers are security professionals hired by an organization to test new software or other products prior to release.
- Purple Hat hacker is someone who attacks their own systems to learn and improve their hacking skills in a controlled environment. Some also categorize a purple hat as a combination of blue hat -- the kind who tests products before they are released -- and red hat -- but only ones who legally focus on finding black hats.
At a time when cybercriminals and nation state hackers continue to use a wide range of tactics in an effort to try and compromise everything from our emails to the critical infrastructure that’s supports our communities, it’s reassuring to know that our lineup card includes some all-stars – when it comes to cyber resilience – who are hackers committed to doing good.