Regulating Tools for Hacking: Limitations, Challenges and Possibilities
2025-05-23
Tools developed for the purpose of unilaterally exploiting computer systems and their communications will pose a persistent policy and regulatory problem. Regulation of hacking tools to date, however, has been piecemeal, inconsistent and often incoherent. Some of this incoherence is a result of semantic uncertainty about how to define hacking tools with scholarship, commentary, and regulatory efforts using a variety of terminology to refer to a related set of items that have no clear definitional boundaries or technical coherence. This paper attempts to reconcile these semantic issues with the need to take productive regulatory steps by articulating how hacking tools emerge from multiple sources that have different ecologies of production and distribution creating unique regulatory challenges and dynamics. Reflecting on these challenges can inform better governance of hacking capabilities whilst also identifying clear regulatory constraints that will persist over the long‐term.