2025/05/06 by David Bozzini · 1 voice · 2 citations
Social Sciences · #Digital Economy and Work Transformation #Ethics and Social Impacts of AI #Privacy, Security, and Data Protection
paper · pdf · doi:10.1080/1369118x.2025.2498683
openalex publication_date 2025/05/06 · openalex created_date 2025/10/10 · openalex updated_date 2026/06/15
This article examines the historical evolution of ethical hacking and vulnerability disclosure practices from the 1990s to the present day. It analyzes three key disclosure regimes and their emergence: full disclosure, responsible/coordinated disclosure, and bug bounty programs. The full disclosure regime is characterized by an adversarial relationship between hackers and companies, with hackers publicly releasing vulnerability information to pressure companies to improve security. The responsible/coordinated disclosure regime formalizes collaboration between hackers and companies, introducing standards and policies to manage the disclosure of vulnerable information. Finally, the bug bounty regime established a market-based model of disclosure that partially commodified vulnerabilities and transformed ethical hacking into a form of gig work. The analysis reveals how these regimes while building upon existing models, enact distinct moral projects and govern interactions between hackers and companies. It highlights how ethical hacking has been transformed through processes of normalization, standardization, and economization and argues that these transformations resulted from complex interactions between hackers and companies shaped by broader socio-cultural trends and pre-existing practices rather than being the result of a simple co-optation by corporate interests. In doing so, this nuanced historical perspective on vulnerability disclosure regimes demonstrates how a political economy perspective contributes to developing a critical cybersecurity research agenda.