COVER ยท BASICS

Hack and exploit

Breaking in or following the rules exactly

What is it?

In everyday speech both are called “hacked”. Technically they are two different events, and cover products often treat them differently.

HackSomebody obtains something they are not entitled to: a key, a password, access to a machine. A boundary was crossed.
ExploitSomebody calls the program like anyone else - in an order or at a scale nobody thought of. No boundary was crossed. There was none.

An example

Hack: An employee is deceived and hands over a key. With it the assets can be moved. That is a break-in, even though no door was forced.

Exploit: A contract pays out before it updates the balance. Somebody calls the payout several times within the same operation. Every single call is permitted, the program does what it says - and at the end it is empty.

Where does a risk come from?

From confusing the two. Anyone who believes they are covering themselves against “hacks” may be covering the rarer case.

A hack presupposes that somewhere there is a place with special rights - a key, an account, an access. An exploit needs none of that. It cannot be seen in the program until somebody has found it, and it can be carried out remotely, by anyone, without preparation.

Why this matters for cover

Because many wordings cut along exactly this line.

A product can cover flaws in the code and exclude attacks on keys. Or the other way round. Or both, but only under certain conditions. Which event is meant is decided by this distinction - and, when it matters, by how the incident is classified.

That is why each risk article says which of the two cases applies.

NEXT

Where this leads