{"id":9110,"date":"2021-03-08T05:00:37","date_gmt":"2021-03-08T10:00:37","guid":{"rendered":"https:\/\/jolt.richmond.edu\/?p=9110"},"modified":"2021-02-23T15:45:42","modified_gmt":"2021-02-23T20:45:42","slug":"hacking-software-free-and-legal","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2021\/03\/08\/hacking-software-free-and-legal\/","title":{"rendered":"Hacking Software: Free and Legal?"},"content":{"rendered":"<p>By\u00a0Ken Kajihiro<\/p>\n<p>&nbsp;<\/p>\n<p>Should hacking software be free and legal?\u00a0 If you are reading this and thinking <em>well, surely, hacking software is only available to cybersecurity professionals and is illegal for the public to own<\/em>; you would be wrong!\u00a0 Hacking software is free and legal for the public to own!<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn1\" name=\"_ftnref1\">[1]<\/a>\u00a0 A simple Google search will result in many free and legal hacking software resources posted online for the public to download.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn2\" name=\"_ftnref2\">[2]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>How is this possible?!\u00a0 It is illegal to knowingly access a computer <em>without authorization<\/em> from its owner.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn3\" name=\"_ftnref3\">[3]<\/a>\u00a0 Thus, as long as you are given the authorization to hack into someone\u2019s computer it is not illegal.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn4\" name=\"_ftnref4\">[4]<\/a>\u00a0 In fact, many businesses, organizations, and even Federal government agencies <em>authorize<\/em> and <em>pay<\/em> ethical hackers to hack into their computer systems with the goal of identifying vulnerabilities in their cybersecurity defenses before bad actors have the opportunity to exploit them.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn5\" name=\"_ftnref5\">[5]<\/a>\u00a0 An ethical hacker is one who uses their hacking skills \u201cfor good by helping [entities] protect themselves.\u201d<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn6\" name=\"_ftnref6\">[6]<\/a>\u00a0 These ethical hackers may or may not be actively employed by said businesses, organizations, or Federal government agencies, but may operate through what is commonly called a \u201cbug bounty program.\u201d<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn7\" name=\"_ftnref7\">[7]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>The idea behind the \u201cbug bounty program\u201d is to make ethical hacking more lucrative than illegal or malicious hacking by allowing hackers to report their successful hacks to an entity in exchange for rewards or, most commonly, monetary compensation.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn8\" name=\"_ftnref8\">[8]<\/a>\u00a0 For example, Microsoft is offering numerous bounties in their Microsoft Bug Bounty Program, with a bounty award of up to $250,000 for a single ethical hack.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn9\" name=\"_ftnref9\">[9]<\/a>\u00a0 Google, alone, has paid out more than $15 Million since the inception of Google\u2019s Vulnerability Rewards Program in 2010, Google\u2019s version of the bug bounty program.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn10\" name=\"_ftnref10\">[10]<\/a>\u00a0 Many ethical hackers use free and legal hacking software resources posted online to participate in the various bug bounty programs.<\/p>\n<p>&nbsp;<\/p>\n<p>To answer the initial question, should hacking software be free and legal, we must first answer the question, do bug bounty programs actually work?\u00a0 In 2014, Google was hacked, despite having a bug bounty program; approximately 5 million Gmail passwords were leaked.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn11\" name=\"_ftnref11\">[11]<\/a>\u00a0 In 2016, Uber was hacked, despite having a bug bounty program; approximately 57 million riders and drivers had their data stolen.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn12\" name=\"_ftnref12\">[12]<\/a>\u00a0 In 2020, Twitter was hacked, despite having a bug bounty program; approximately 130 high-profile Twitter accounts and $121,000 in Bitcoin were stolen.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn13\" name=\"_ftnref13\">[13]<\/a>\u00a0 Also, in 2020, Microsoft was hacked, despite having a bug bounty program; Microsoft\u2019s source code was viewed by hackers.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn14\" name=\"_ftnref14\">[14]<\/a>\u00a0 These incidents may indicate that bug bounty programs do not work.<\/p>\n<p>&nbsp;<\/p>\n<p>However, before concluding, let us take a look at some hacks where companies did not have a bug bounty program.\u00a0 In 2017, Equifax was hacked; more than 148 million people had their personally identifiable information stolen \u2013 that is more than 40 percent of the population of the United States \u2013 costing Equifax in total more than $4 Billion.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn15\" name=\"_ftnref15\">[15]<\/a>\u00a0 In 2018, Marriot was hacked; approximately 500 million worldwide travelers had their hotel reservation data stolen.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn16\" name=\"_ftnref16\">[16]<\/a>\u00a0 In 2019, MGM Resorts was hacked; more than 142 million worldwide travelers had their hotel reservation data stolen.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn17\" name=\"_ftnref17\">[17]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Do bug bounty programs actually work?\u00a0 Unfortunately, the answer is an inevitable \u201cmaybe.\u201d<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn18\" name=\"_ftnref18\">[18]<\/a>\u00a0 That\u2019s kind of how security works; you just do not know whether your security is working because either a breach in security has not occurred, or hackers do not even try to breach your security because they know it has already been screened for vulnerabilities, or the hack that did occur was just unavoidable.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn19\" name=\"_ftnref19\">[19]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>This being said, back to the initial question: should hacking software be free and legal?\u00a0 Congress could simply ban and make hacking software resources illegal to the public \u2013 forcing all websites to remove their free, public hacking software resources.\u00a0 However, we must think about how, or more so, <em>where<\/em> computer software can be developed.\u00a0 Answer: anywhere; including at home.\u00a0 Apple Inc. was created in Steve Jobs\u2019 grandma\u2019s house.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn20\" name=\"_ftnref20\">[20]<\/a>\u00a0 Facebook was created in Mark Zuckerberg\u2019s college dorm room.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn21\" name=\"_ftnref21\">[21]<\/a>\u00a0 The same can be said of hacking software: if it\u2019s not publicly available, bad actors would make the hacking software themselves.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn22\" name=\"_ftnref22\">[22]<\/a>\u00a0 In addition, some countries have seen a reverse impact of the laws created to regulate hacking software and increase public safety \u2013 overall cybersecurity awareness and innovation have decreased, leaving the public more vulnerable with the laws than without the laws.<a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftn23\" name=\"_ftnref23\">[23]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>In conclusion, a ban on hacking software resources may do nothing but shift the power from the public to the bad actors.\u00a0 Although it is unclear whether the bug bounty programs work, at least the safety of the public is in the hands of the public.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref1\" name=\"_ftn1\">[1]<\/a> Silvia Mazzetta, <em>Top 15 Free Hacking Tools for Ethical Hackers<\/em>, Ma-No Web Design (June 19, 2020), https:\/\/www.ma-no.org\/en\/security\/top-15-free-hacking-tools-for-ethical-hackers.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref2\" name=\"_ftn2\">[2]<\/a> <em>Id.<\/em>; Henry HMFIC, <em>Best Hacker Tools of 2021<\/em>, Concise AC, https:\/\/www.concise-courses.com\/hacking-tools\/top-ten (last visited Feb. 19, 2021).<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref3\" name=\"_ftn3\">[3]<\/a> 18 U.S.C. \u00a7 1030(a)(1) (2021).<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref4\" name=\"_ftn4\">[4]<\/a> <em>See<\/em> <em>id.<\/em><\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref5\" name=\"_ftn5\">[5]<\/a> Roger Grimes, <em>What is Ethical Hacking?\u00a0 How to Get Paid to Break into Computers<\/em>, IDG Communications, Inc. (Feb. 27, 2019), https:\/\/www.csoonline.com\/article\/3238128\/what-is-ethical-hacking-and-how-to-become-an-ethical-hacker.html.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref6\" name=\"_ftn6\">[6]<\/a> Katie Brigham, <em>How Hackers are Making Millions \u2013 Legally<\/em>, CNBC LLC (Jan. 18, 2020), https:\/\/www.cnbc.com\/2020\/01\/17\/why-companies-like-google-facebook-and-uber-pay-hackers-millions.html.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref7\" name=\"_ftn7\">[7]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref8\" name=\"_ftn8\">[8]<\/a> <em>Id.<\/em>; Megan Kaczanowski, <em>What is a Bug Bounty Program?\u00a0 How Bug Bounties Work and Who Should Use Them<\/em>, FreeCodeCamp (Dec. 7, 2020), https:\/\/www.freecodecamp.org\/news\/whats-a-bug-bounty-program\/#:~:text=Bug%20bounty%20programs%20allow%20independent,hardware%20flaws%2C%20and%20so%20on.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref9\" name=\"_ftn9\">[9]<\/a> <em>Microsoft Bug Bounty Program<\/em>, Microsoft, https:\/\/www.microsoft.com\/en-us\/msrc\/bounty?rtc=1 (last visited Feb. 19, 2021).<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref10\" name=\"_ftn10\">[10]<\/a> Eric Griffith &amp; Kyle Kucharski, <em>7 Huge Bug Bounty Payouts<\/em>, PC Mag Digital Group (May 14, 2019), https:\/\/www.pcmag.com\/news\/7-huge-bug-bounty-payouts#:~:text=The%20largest%20single%20payout%20last,in%20Google&#8217;s%20Cloud%20Platform%20console.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref11\" name=\"_ftn11\">[11]<\/a> Kashmir Hill, <em>Google Says Not to Worry About 5 Million \u2018Gmail Passwords\u2019 Leaked<\/em>, Forbes (Sept. 11, 2014), https:\/\/www.forbes.com\/sites\/kashmirhill\/2014\/09\/11\/google-says-not-to-worry-about-5-million-gmail-passwords-leaked\/?sh=658dc3617a8d; Griffith &amp; Kucharski, <em>supra<\/em> note 10.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref12\" name=\"_ftn12\">[12]<\/a> <em>Uber Fined $148m for Failing to Notify Drivers they had been Hacked<\/em>, Guardian News (Sept. 26, 2018), https:\/\/www.theguardian.com\/technology\/2018\/sep\/26\/uber-hack-fine-driver-data-breach; <em>Uber Bug Bounty Program<\/em>, HackerOne, https:\/\/hackerone.com\/uber?type=team (last updated Feb. 12, 2021).<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref13\" name=\"_ftn13\">[13]<\/a> Rob Sobers, <em>134 Cybersecurity Statistics and Trends for 2021<\/em>, Inside Out Security, https:\/\/www.varonis.com\/blog\/cybersecurity-statistics (last updated Feb. 1, 2021); <em>Twitter Bug Bounty Program<\/em>, HackerOne, https:\/\/hackerone.com\/twitter?type=team (last updated May 30, 2019).<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref14\" name=\"_ftn14\">[14]<\/a> <em>Microsoft Internal Solorigate Investigation<\/em>, Microsoft (Dec. 31, 2020), https:\/\/msrc-blog.microsoft.com\/2020\/12\/31\/microsoft-internal-solorigate-investigation-update; <em>Microsoft Bug Bounty Program<\/em>, <em>supra<\/em> note 9.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref15\" name=\"_ftn15\">[15]<\/a> Josh Fruhlinger, <em>Equifax Data Breach FAQ: What Happened, Who was Affected, What was the Impact?<\/em>, IDG Communications, Inc. (Feb. 12, 2020), https:\/\/www.csoonline.com\/article\/3444488\/equifax-data-breach-faq-what-happened-who-was-affected-what-was-the-impact.html; Sobers, <em>supra<\/em> note 13.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref16\" name=\"_ftn16\">[16]<\/a> Lily Hay Newman, <em>The Worst Hacks of 2018<\/em>, Wired (Dec. 31, 2018), https:\/\/www.wired.com\/story\/worst-hacks-2018-facebook-marriott-quora.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref17\" name=\"_ftn17\">[17]<\/a> Catalin Cimpanu, <em>A Hacker is Selling Details of 142 Million MGM Hotel Guests on the Dark Web<\/em>, ZD Net (July 14, 2020), https:\/\/www.zdnet.com\/article\/a-hacker-is-selling-details-of-142-million-mgm-hotel-guests-on-the-dark-web.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref18\" name=\"_ftn18\">[18]<\/a> <em>See<\/em> George Hulme, <em>Metasploit Review: Ten Years Later, Are We Any More Secure?<\/em>, TechTarget, https:\/\/searchsecurity.techtarget.com\/feature\/Metasploit-Review-Ten-Years-Later-Are-We-Any-More-Secure (last updated Oct. 2012).<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref19\" name=\"_ftn19\">[19]<\/a> Mike Elgan, <em>How to Know if Your Cybersecurity Tools are Actually Working<\/em>, Security Intelligence (Aug. 30, 2019), https:\/\/securityintelligence.com\/articles\/how-to-know-if-your-cybersecurity-tools-are-actually-working.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref20\" name=\"_ftn20\">[20]<\/a> Megan Chovanec, <em>My Grandma\u2019s Los Altos Garage is Where Apple was Created<\/em>, Insider Inc. (Jan. 31, 2015), https:\/\/www.businessinsider.com\/my-grandmas-los-altos-garage-is-where-apple-was-created-2015-1.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref21\" name=\"_ftn21\">[21]<\/a> Marguerite Ward, <em>Mark Zuckerberg Returns to the Harvard Dorm Room Where Facebook was Born<\/em>, CNBC LLC (May 25, 2017), https:\/\/www.cnbc.com\/2017\/05\/25\/mark-zuckerberg-returns-to-the-harvard-dorm-where-facebook-was-born.html.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref22\" name=\"_ftn22\">[22]<\/a> Hulme, <em>supra<\/em> note 18.<\/p>\n<p><a href=\"applewebdata:\/\/A16EF258-E93B-4003-8C36-2BC58AECE241#_ftnref23\" name=\"_ftn23\">[23]<\/a> <em>Id.<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-9112\" src=\"https:\/\/jolt.richmond.edu\/files\/2021\/02\/white_hat_grey_hat_black_hat_hackers-300x169.png\" alt=\"\" width=\"300\" height=\"169\" srcset=\"https:\/\/blog.richmond.edu\/jolt\/files\/2021\/02\/white_hat_grey_hat_black_hat_hackers-300x169.png 300w, https:\/\/blog.richmond.edu\/jolt\/files\/2021\/02\/white_hat_grey_hat_black_hat_hackers-768x432.png 768w, https:\/\/blog.richmond.edu\/jolt\/files\/2021\/02\/white_hat_grey_hat_black_hat_hackers-480x270.png 480w, https:\/\/blog.richmond.edu\/jolt\/files\/2021\/02\/white_hat_grey_hat_black_hat_hackers.png 845w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Image Source:\u00a0https:\/\/www.itpro.co.uk\/hacking\/30282\/what-is-ethical-hacking-white-hat-hackers-explained<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By\u00a0Ken Kajihiro &nbsp; Should hacking software be free and legal?\u00a0 If you are reading this and thinking well, surely, hacking software is only available to cybersecurity professionals and is illegal for the public to own; you would be wrong!\u00a0 Hacking software is free and legal for the public to own![1]\u00a0 A simple Google search will [&hellip;]<\/p>\n","protected":false},"author":4744,"featured_media":9112,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[51366],"tags":[],"class_list":["post-9110","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-post"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/blog.richmond.edu\/jolt\/files\/2021\/02\/white_hat_grey_hat_black_hat_hackers.png","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-2mW","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/9110","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4744"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=9110"}],"version-history":[{"count":1,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/9110\/revisions"}],"predecessor-version":[{"id":9113,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/9110\/revisions\/9113"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media\/9112"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=9110"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=9110"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=9110"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}