Uber hires Charlie Miller and Chris Valasek, the researchers who hacked into moving Jeeps
Uber hires two security researchers to improve car technology — Uber Technologies Inc [UBER.UL] has hired two top vehicle security researchers, the company said on Friday, additions to its staff …
Context & Ripple Effects
This hire completes a year-long build-out of Uber's security function: months after luring Facebook veteran Joe Sullivan in as its first-ever chief security officer, Uber now brings Charlie Miller and Chris Valasek in house — the same pair who showed a Jeep could be compromised while driving. For a company pushing into car technology, hiring the people who proved connected cars are hackable converts an embarrassment for automakers into internal capability.
The arc matters because it didn't end here: Uber followed with a structured HackerOne bug bounty program rewarding outside researchers, and by mid-2017 GM's Cruise Automation had hired both men away from Didi and Uber — evidence that vehicle-security talent had become a contested asset across the autonomous-driving race.
First-order effects
- Uber gains in-house expertise in remotely compromising moving vehicles — precisely the skill set its self-driving and connected-car programs need to defend against, working directly under CSO Joe Sullivan's new security organization.
- The researchers who demonstrated the Jeep vulnerabilities shift from exposing automakers' flaws to being paid to find them before attackers do.
Second-order effects
- Rival autonomy programs must respond in kind: when GM's Cruise later hired both Miller and Valasek, it confirmed that poaching proven car-hackers had become standard practice among companies racing to put software-driven vehicles on roads.
- Formalizing researcher relationships — via the HackerOne bounty with rewards up to $10K and disclosed network details — turns Uber's infrastructure from a target outsiders probe covertly into one they report on for pay.
Third-order effects
- If the pattern holds, vehicle cybersecurity becomes a talent arms race: elite offensive researchers move between mobility platforms as strategic hires, and the ability to attract them becomes part of what separates credible autonomous-vehicle players from the rest.
- It also foreshadows a structural risk the corpus later confirmed — when a 2022 Uber breach showed an attacker accessing the HackerOne vulnerability reports themselves, the external-research apparatus itself became an attack surface companies have to defend.
The trend: As cars become networked computers, ride-hailing and autonomous-vehicle firms are competing to recruit the white-hat researchers who once embarrassed automakers, making vehicle-security talent a strategic asset rather than an adversarial threat.