Abstract:
One of the important topics in the field of information technology is hacking information systems, i.e. finding the security vulnerabilities of a system to infiltrate and access its information, which can be done with different motives and can follow desirable or undesirable consequences at both individual and public levels and in different fields. This is why hackers are classified into different types, such as white hats, gray hats, and black hats. The purpose of this descriptive-analytic research is to investigate the legitimacy of hacking in Islamic jurisprudence. The findings of the present study show that hacking does not have the same jurisprudential results and varies based on the intentions and actions of the hackers. White hat hackers are legitimate, but black hat hackers are illegitimate. The most important component in analyzing the legitimacy of a hack is "more expediency" and the most important factor in its illegality is "unauthorized violation of the rights of others". Hence, if for the most important expediency, there is no other way but to hack information systems, action is not forbidden.
Machine summary:
Therefore, if a conflict occurs between the public interest of society and secondary rulings, the interest of society will take precedence according to its level of importance; such as the permissibility of eavesdropping (istiraq al-sam') through hacking individuals' information systems to achieve a more important interest, despite its inherent prohibition (Misbah, 1369, 79; Ibn Farhun, 1406, Vol. 2, 187).
The result of such an approach is the prohibition of hacking information systems, unless we accept that the ruling of the permissibility of disposing of computer data by its owners causes harm to individuals or public interests, in which case, hacking information systems will be a legitimate matter due to the precedence of the rule "لاضرر" over the rule of authority (Tasallut) (Ibn Qudamah, Vol. 5, 52; Isfahani, 1419, Vol. 1, 441-442); especially if it results in significant harm (Muhaqqiq Sabzawari, 1381, Vol. 2, 556).
Based on this, if there is no way to prevent the activities of immoral information systems or those that violate national security other than hacking them, this action will be permissible and perhaps even obligatory according to the rule of the obligation to repel probable harm (Doha International Fiqh Academy, Fatwa No. 114097, dated 2008/10/30); because in the conflict between the rights of the owners of the information systems in question and the preservation of the moral, psychological, economic, and cultural security of society, the principle is to prioritize the more important over the less important.
Accordingly, accessing individuals' personal information and data through hacking information systems is an instance of violating their privacy, and since black-hat hackers perform this act with malicious motives, it is a forbidden act (Fatwas of seven Shia scholars regarding virtual spaces, code 124561, dated 1395/05/31; Al-Shaykh Al-Munajjid, Fatwa number 118501, dated 2009/11/24).