{"id":{"repo_id":"vt","oai_identifier":"oai:vtechworks.lib.vt.edu:10919/52943"},"canonical_url":"https://search.dev.ndltd.org/etd/vt/oai:vtechworks.lib.vt.edu:10919/52943","repository":{"repo_id":"vt","name":"Virginia Tech","base_url":"https://vtechworks.lib.vt.edu/oai/request"},"display":{"title":"The Rhetoric of Commoditized Vulnerabilities: Ethical Discourses in Cybersecurity","abstract":"The field of cybersecurity is relatively uncharted by rhetoricians and sociologists but nevertheless laden with terminological assumptions, violent metaphors, and ethical conflicts. This study explores the discourse surrounding the morally contentious practice of hackers selling software vulnerabilities to third parties instead of disclosing them to the affected technology companies. Drawing on grounded theory, I utilize a combination of quantitative word-level analysis and qualitative coding to assess how notions of right and wrong on this topic are framed by three groups: 1) the hackers themselves, 2) technology companies, and 3) reporters. The results show that the most commonly constructed argument was based on a \"greater good\" ethic, in which rhetors argue for reducing risk to \"us all\" or to innocent computer users. Additionally, the technology companies and hackers assiduously build their ethos to increase their trustworthiness in the public mind. Ultimately, studying this unexplored area of \"gray hat hacking\" has important implications for policymakers creating new cybersecurity legislation, reporters attempting to accurately frame the debate, and information technology professionals whose livelihoods are affected by evolving social norms.","abstract_html":"The field of cybersecurity is relatively uncharted by rhetoricians and sociologists but nevertheless laden with terminological assumptions, violent metaphors, and ethical conflicts. This study explores the discourse surrounding the morally contentious practice of hackers selling software vulnerabilities to third parties instead of disclosing them to the affected technology companies. Drawing on grounded theory, I utilize a combination of quantitative word-level analysis and qualitative coding to assess how notions of right and wrong on this topic are framed by three groups: 1) the hackers themselves, 2) technology companies, and 3) reporters. The results show that the most commonly constructed argument was based on a &quot;greater good&quot; ethic, in which rhetors argue for reducing risk to &quot;us all&quot; or to innocent computer users. Additionally, the technology companies and hackers assiduously build their ethos to increase their trustworthiness in the public mind. Ultimately, studying this unexplored area of &quot;gray hat hacking&quot; has important implications for policymakers creating new cybersecurity legislation, reporters attempting to accurately frame the debate, and information technology professionals whose livelihoods are affected by evolving social norms.","abstract_has_math":false,"creators":["Hoskins, Brittany Noel"],"institution":"Virginia Tech","degree_name":"Master of Arts","degree_level":"masters","degree_discipline":"English","degree_department":"English","school":null,"contributors":[],"advisors":[],"committee_chairs":["Warnick, Quinn"],"committee_members":["Carter-Tod, Sheila L.","Evia Puerto, Carlos"],"year":2015,"date_issued":"2015-06-15","date_published":"2015-06-15","updated_at":"2026-07-22T22:19:10Z","subjects":["Rhetoric","Cybersecurity","Hacking","Business Ethics","Gray Hat"],"languages":[],"rights":["In Copyright"],"rights_urls":["http://rightsstatements.org/vocab/InC/1.0/"],"identifier_entries":[{"key":"dc:identifier.other","label":"Dc Identifier Other","values":["vt_gsexam:5419"],"render_values":[{"text":"vt_gsexam:5419","href":null,"code":true}]}]},"links":{"outbound_url":"http://hdl.handle.net/10919/52943","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.committeechair","label":"Committee Chair","values":["Warnick, Quinn"]},{"key":"dc:contributor.committeemember","label":"Committee Member","values":["Carter-Tod, Sheila L.","Evia Puerto, Carlos"]},{"key":"dc:contributor.department","label":"Department","values":["English"]},{"key":"dc:creator","label":"Author","values":["Hoskins, Brittany Noel"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2015-06-17T08:00:13Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2015-06-17T08:00:13Z"]},{"key":"dc:date.issued","label":"Date","values":["2015-06-15"]},{"key":"dc:publisher","label":"Institution","values":["Virginia Tech"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["English"]},{"key":"thesis:degree_level","label":"Degree Level","values":["masters"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Arts"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["Virginia Polytechnic Institute and State University"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Rhetoric","Cybersecurity","Hacking","Business Ethics","Gray Hat"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["In Copyright"]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://rightsstatements.org/vocab/InC/1.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.other","label":"Dc Identifier Other","values":["vt_gsexam:5419"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["http://hdl.handle.net/10919/52943"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["The field of cybersecurity is relatively uncharted by rhetoricians and sociologists but nevertheless laden with terminological assumptions, violent metaphors, and ethical conflicts. This study explores the discourse surrounding the morally contentious practice of hackers selling software vulnerabilities to third parties instead of disclosing them to the affected technology companies. Drawing on grounded theory, I utilize a combination of quantitative word-level analysis and qualitative coding to assess how notions of right and wrong on this topic are framed by three groups: 1) the hackers themselves, 2) technology companies, and 3) reporters. The results show that the most commonly constructed argument was based on a \"greater good\" ethic, in which rhetors argue for reducing risk to \"us all\" or to innocent computer users. Additionally, the technology companies and hackers assiduously build their ethos to increase their trustworthiness in the public mind. Ultimately, studying this unexplored area of \"gray hat hacking\" has important implications for policymakers creating new cybersecurity legislation, reporters attempting to accurately frame the debate, and information technology professionals whose livelihoods are affected by evolving social norms."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["Master of Arts"]},{"key":"dc:format.medium","label":"Dc Format Medium","values":["ETD"]},{"key":"dc:title","label":"Title","values":["The Rhetoric of Commoditized Vulnerabilities: Ethical Discourses in Cybersecurity"]}]}],"canonical_facts":{"dc:contributor.committeechair":["Warnick, Quinn"],"dc:contributor.committeemember":["Carter-Tod, Sheila L.","Evia Puerto, Carlos"],"dc:contributor.department":["English"],"dc:creator":["Hoskins, Brittany Noel"],"dc:date.accessioned":["2015-06-17T08:00:13Z"],"dc:date.available":["2015-06-17T08:00:13Z"],"dc:date.issued":["2015-06-15"],"dc:description.abstract":["The field of cybersecurity is relatively uncharted by rhetoricians and sociologists but nevertheless laden with terminological assumptions, violent metaphors, and ethical conflicts. This study explores the discourse surrounding the morally contentious practice of hackers selling software vulnerabilities to third parties instead of disclosing them to the affected technology companies. Drawing on grounded theory, I utilize a combination of quantitative word-level analysis and qualitative coding to assess how notions of right and wrong on this topic are framed by three groups: 1) the hackers themselves, 2) technology companies, and 3) reporters. The results show that the most commonly constructed argument was based on a \"greater good\" ethic, in which rhetors argue for reducing risk to \"us all\" or to innocent computer users. Additionally, the technology companies and hackers assiduously build their ethos to increase their trustworthiness in the public mind. Ultimately, studying this unexplored area of \"gray hat hacking\" has important implications for policymakers creating new cybersecurity legislation, reporters attempting to accurately frame the debate, and information technology professionals whose livelihoods are affected by evolving social norms."],"dc:description.degree":["Master of Arts"],"dc:format.medium":["ETD"],"dc:identifier.other":["vt_gsexam:5419"],"dc:identifier.uri":["http://hdl.handle.net/10919/52943"],"dc:publisher":["Virginia Tech"],"dc:rights":["In Copyright"],"dc:rights.uri":["http://rightsstatements.org/vocab/InC/1.0/"],"dc:subject":["Rhetoric","Cybersecurity","Hacking","Business Ethics","Gray Hat"],"dc:title":["The Rhetoric of Commoditized Vulnerabilities: Ethical Discourses in Cybersecurity"],"dc:type":["Thesis"],"thesis:degree_discipline":["English"],"thesis:degree_level":["masters"],"thesis:degree_name":["Master of Arts"],"thesis:institution_name":["Virginia Polytechnic Institute and State University"]},"updated_at":"2026-07-22T22:19:10Z"}