Virtuous Human Hacking: The Ethics of Social Engineering in Penetration-Testing

Computers and Security 83:354-366 (2019)
  Copy   BIBTEX

Abstract

This paper offers a virtue ethics analysis of social engineering in penetration-testing. It begins by considering previous research on this topic and argues that such attempts misconstrue or more often overlook this Aristotelian tradition. It articulates the core tenets of virtue ethics and applies them to an analysis of white hat social engineering. A virtue ethics analysis requires that individuals and the firms that initiate the penetration-test be placed within a larger communal context which obligates individuals who are potential human hacking victims to participate in the constitution and flourishing of larger communities. As such, for virtue ethics consent is not a necessary condition for the positive ethical status of white hat social engineering. If methods are consistent with moderation (i.e. the golden mean) manipulation at lower orders within the hierarchy of communities can be justified if it can reasonably be understood as part of an individual's participatory obligation and the results of this participation is essential to ensure the eudaimonia of the larger community. Nevertheless, the golden mean requires that robust mitigation strategies lessen the degree of harm inflicted on social engineering victims. Where possible, a degree of consent should be attained as part of this mitigation. Finally, penetration-testing firms must be able to demonstrate that a robust ethical training program governs its use of social engineering.

Links

PhilArchive



    Upload a copy of this work     Papers currently archived: 91,532

External links

Setup an account with your affiliations in order to access resources via your University's proxy server

Through your library

Similar books and articles

Virtue as the basis of engineering ethics.Douglas J. Crawford-Brown - 1997 - Science and Engineering Ethics 3 (4):481-489.
The good engineer: Giving virtue its due in engineering ethics.Charles E. Harris - 2008 - Science and Engineering Ethics 14 (2):153-164.
Engineering Ethics: Contemporary and Enduring Debates.Deborah G. Johnson - 2020 - New Haven [Connecticut]: Yale University Press.
Professional Engineers.Spyridon Stelios - 2020 - Business and Professional Ethics Journal 39 (2):253-268.

Analytics

Added to PP
2021-04-04

Downloads
30 (#528,775)

6 months
6 (#509,125)

Historical graph of downloads
How can I increase my downloads?

Author's Profile

Joseph Hatfield
United States Naval Academy

Citations of this work

No citations found.

Add more citations

References found in this work

No references found.

Add more references