White Hat Hacker

A white hat hacker searches for security vulnerabilities in computer systems with the owner's permission, so they can be reported and fixed. The difference from criminal attackers lies not in skill, but in permission and intent.

A white hat hacker is someone who deliberately searches for weaknesses in computer systems. However, they do this on behalf of, or with the explicit permission of, the operator. If they find a flaw, they don’t exploit it but report it instead. The operator can then fix the error before anyone else exploits it. The name comes from old Western films, in which the good guys wore white hats. The counterpart is the black hat hacker, who breaks into systems to enrich themselves or cause damage.

The white hat is a question of permission

Technically, white hats and criminals often do the same thing. They try out passwords, look for programming errors, and test whether a website can handle unexpected input. The difference lies in two points: the permission beforehand and the handling of the discovery afterward. Without this permission, breaking into other people’s systems is a criminal offense in Germany, regulated under Section 202a of the Criminal Code.

For companies, such tests are important because software is never free of errors. A large program consists of millions of lines of instructions, and inevitably, errors are hidden within that volume. Some of these can be exploited. It is significantly cheaper to learn about a vulnerability from a paid tester than from the press after a data theft.

A third type is often mentioned in the news: the grey hat hacker. They search without permission, but still report their findings instead of selling them. Legally, they take on the same risk as a criminal, even though their intention is good.

From assignment to patch

It starts with a written contract. This specifies exactly which systems may be tested and which may not. Such commissioned attacks are called penetration tests, or pentests for short. The tester first gathers information: Which servers are reachable, what software is running on them, how old is it?

Afterward, they deliberately try out attacks. A classic example is SQL injection: instead of a name, the tester enters a command for the database into a search field. If the site reacts to this, an attacker might be able to read out all stored customer data. Other tests target people instead of technology, for example with fake emails sent to employees.

At the end, there is a report with all findings, ranked by severity. A deadline of 90 days is common: this gives the manufacturer time to fix the error before the vulnerability is made public. This approach is called responsible disclosure. The fix itself is called a patch and reaches you as a security update.

Bug bounties, authorities, and AI models

Many large companies pay rewards for reported vulnerabilities. Such programs are called bug bounties. Google, Apple, and Microsoft pay out double-digit million-dollar amounts every year through these. For particularly severe vulnerabilities in iPhones, sums in the millions are possible. Platforms like HackerOne connect companies and testers worldwide.

This role now also exists for AI systems. There it is called red teaming: experts try to get a chatbot to give dangerous or false answers. OpenAI, Google, and Anthropic employ their own teams for this and invite external testers. EU legislation even explicitly requires such tests for particularly powerful AI models.

A common misconception is that white hats are lone geniuses in hoodies. In practice, it’s a normal profession with training, certifications, and reporting obligations. Authorities such as Germany’s Federal Office for Information Security (BSI) even hire such experts themselves. When the news reports that a security vulnerability was discovered in time, someone from this group is almost always behind it.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.