Uber hires Charlie Miller and Chris Valasek, the researchers who hacked into moving Jeeps
Context & Ripple Effects
This is the second high-profile raid of Uber's 2015 talent campaign: two months after it poached 50 autonomy experts from Carnegie Mellon's robotics lab, it has hired Charlie Miller and Chris Valasek — the duo who demonstrated a remote hack of a moving Jeep. For a company building self-driving cars on compressed timelines, buying proven vehicle-security researchers is both defensive and a signal to regulators that safety is being staffed seriously.
The hire also starts a pattern of these two researchers becoming circulating assets among rival autonomy programs: by 2017, GM's Cruise Automation had hired both men, after Miller's four-month detour through Uber's Chinese backer Didi.
First-order effects
- Uber's Advanced Technologies Center gains the pair whose moving-Jeep exploit made remote vehicle compromise a public fact, directly hardening its own driverless-car stack against the class of attack they demonstrated.
- Miller and Valasek move from publishing vulnerabilities at venues like Black Hat and Pwn2Own to salaried industry roles, removing two prominent independent voices from the disclosure circuit.
Second-order effects
- Rival autonomy programs copy the playbook rather than cede the advantage — GM's Cruise ultimately hired both researchers out of Didi and Uber, confirming that offensive-vehicle-security talent is now bid over like ML engineers.
- Automakers exposed by the Jeep work face pressure not just to patch, but to compete with ride-hailing companies for the very researchers who found the flaws, reshaping where vulnerability expertise sits.
Third-order effects
- If the pattern holds, vehicle-security research becomes a standard recruitment pipeline into autonomous driving, with the same small set of experts cycling between Uber, Didi, GM's Cruise and whoever bids next — concentrating knowledge of attack surfaces inside a handful of companies.
- The longer arc cuts both ways: Uber's willingness to hire hackers contrasts sharply with its later breach history, including the Lapsus$-linked contractor-account intrusion that exposed internal bug reports, suggesting that staffing elite security talent does not by itself secure an organization's operational perimeter.
The trend: Autonomous-driving programs are absorbing the security-research community into their payrolls, turning vehicle hacking from a disclosure practice into an internal arms race among Uber, Didi and GM's Cruise.