Hack and exploit
Breaking in or following the rules exactly
What is it?
In everyday speech both are called “hacked”. Technically they are two different events, and cover products often treat them differently.
| Hack | Somebody obtains something they are not entitled to: a key, a password, access to a machine. A boundary was crossed. |
|---|---|
| Exploit | Somebody calls the program like anyone else - in an order or at a scale nobody thought of. No boundary was crossed. There was none. |
An example
Hack: An employee is deceived and hands over a key. With it the assets can be moved. That is a break-in, even though no door was forced.
Exploit: A contract pays out before it updates the balance. Somebody calls the payout several times within the same operation. Every single call is permitted, the program does what it says - and at the end it is empty.
Where does a risk come from?
From confusing the two. Anyone who believes they are covering themselves against “hacks” may be covering the rarer case.
A hack presupposes that somewhere there is a place with special rights - a key, an account, an access. An exploit needs none of that. It cannot be seen in the program until somebody has found it, and it can be carried out remotely, by anyone, without preparation.
Why this matters for cover
Because many wordings cut along exactly this line.
A product can cover flaws in the code and exclude attacks on keys. Or the other way round. Or both, but only under certain conditions. Which event is meant is decided by this distinction - and, when it matters, by how the incident is classified.
That is why each risk article says which of the two cases applies.
Where this leads
-
The exploit case in its most common form.
-
The other case: somebody gains control they should not have.