A Free Educational Resource Created by Carnegie Mellon University to Empower You to Secure Your Part of Cyberspace

Black Hat

A person who compromises a computer system's security without authorization, typically maliciously

A person who has extensive knowledge and experience about computers and computer systems, especially in the case of computer and network security, is generally referred to as a "hacker." Though originally it just meant a computer expert, the common usage of the term hacker today is for a person who uses his skills with malicious intent. This created a controversy with many members of the computing world, who protested against what they viewed as a subversion of the term. Thus the terms "black hat" and "white hat" came into existence, to illustrate the moral difference between those who use their talents for "good" and "evil."

A black hat uses his hacking skills for malicious or personal purposes, for example, stealing information from a company's server without authorization or shutting down critical services. On the other hand, a white hat uses the same skills to benefit others, e.g., testing the company's defenses after receiving authorization. The white hat will inform the company of any weakness he finds in the system and might offer ways to block them, whereas the black hat uses any weaknesses he finds for personal benefit. The terms comes from old Western movies, where heroes often wore white cowboy hats and the "bad guys" wore black ones.

Security conferences called the Black Hat Briefings are held annually. They take place regularly in Las Vegas, Tokyo and Amsterdam and involve seminars, conferences and workshops from the world's leading security experts on many topics in the field. A more underground hacker convention called DEFCON takes place yearly in Las Vegas. It is considered to be the largest underground hacker gathering, and involves teams of hackers competing against each other in hacking competitions, apart from the more mundane workshops and talks.

References

My home page