Ethical Hacking: The Security Justification
Bryan C. Smith, William J. Yurcik, D. Doss · 2001
The state of security on the Internet is poor and progress toward increased protection is slow. This has given rise to a class of action referred to as "Ethical Hacking". Companies are releasing software with little or no testing and no formal verification and expecting consumers to debug their product for them. For dot.com companies time-to-market is vital, security is not perceived as a marketing advantage, and implementing a secure design process an expensive sunk expense such that there is no economic incentive to produce bug-free software. There are even legislative initiatives to release software manufacturers from legal responsibility to their defective software.