"How to Hire a Hacker: Dealing with Dangerous Experts and Distributed Risks in the Dot-Com Decade"

Paper

This paper examines the relationships between computer hackers, American corporations, academics, and security professionals in the 1990s. It charts the course of corporate debates about how to best manage the many novel security risks presented by networked computing, how to ward off hackers lurking in the wires — and whether or not private actors could employ hackers themselves in defense of their networks. Throughout these debates, computer executives, journalists, and computer professionals weighed the question of how to employ a dangerous expert, the hacker, who was theoretically best equipped to repel other cybercriminals. These debates yielded a new category, “ethical” or “white hat” hacking, in which authorities asked if hackers could be “reformed” and employed by managers as mercenaries guarding and governing private networks in cyberspace. But the hacker’s status was never fully settled, and each iterative attempt to incorporate hackers into formal organizations yielded new debates about the political economy of the information age, including the differences between criminality in the physical world and cyberspace, the tensions between old models of corporate security and the newfound, distributed risks inherent in networked computing, and the evolving concept of merit in the growing industry of computer security. The hacker, as this paper shows, was an avatar for a whole range of questions about the gig economy, new risks, and the model employee for the digital age.