Authorisation first
No system, no data, no person is in scope without an explicit yes.
HACKERS values curiosity, rigorous testing, and unconventional thinking. Those capabilities must be paired with consent, accountability, safety, and public benefit.
Authorise / Test / Improve
Study the failure. Understand the system. Build the defence. Create the better alternative.
No system, no data, no person is in scope without an explicit yes.
Curiosity is not a defence. If people can be hurt, stop.
Test in sandboxes. Write the boundary before the experiment.
Translation, summarisation, and decoding do not confer trust.
A fluent sentence is not a mandate to act.
Tools should be able to do less, not more, than the brief implies.
Money, identity, safety, and public records require a named person.
Finding a weakness is a duty to disclose in scope — not a trophy.
Ask who is harmed if the idea works at scale.
The work ends in a better alternative, or it is not our work.
If any box stays empty, you do not have a brief. You have a temptation.
Members, fellows, staff, and partners of HACKERS agree that unconventional thinking is a public capability, not a private weapon.
We study breakthroughs, loopholes, and failures as systems-thinking case studies. We do not teach unauthorised access, theft, fraud, evasion, disruption, or operational exploitation of real systems.
External data remains untrusted after every transformation. Content is never authority. High-impact actions require named human approval. Responsible disclosure is the only legitimate path from a found weakness to a public story.
Authorise. Test. Improve.