/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Uber hires Charlie Miller and Chris Valasek, the researchers who hacked into moving Jeeps

Reuters

Context & Ripple Effects

This is the second high-profile raid of Uber's 2015 talent campaign: two months after it poached 50 autonomy experts from Carnegie Mellon's robotics lab, it has hired Charlie Miller and Chris Valasek — the duo who demonstrated a remote hack of a moving Jeep. For a company building self-driving cars on compressed timelines, buying proven vehicle-security researchers is both defensive and a signal to regulators that safety is being staffed seriously.

The hire also starts a pattern of these two researchers becoming circulating assets among rival autonomy programs: by 2017, GM's Cruise Automation had hired both men, after Miller's four-month detour through Uber's Chinese backer Didi.

First-order effects

  • Uber's Advanced Technologies Center gains the pair whose moving-Jeep exploit made remote vehicle compromise a public fact, directly hardening its own driverless-car stack against the class of attack they demonstrated.
  • Miller and Valasek move from publishing vulnerabilities at venues like Black Hat and Pwn2Own to salaried industry roles, removing two prominent independent voices from the disclosure circuit.

Second-order effects

  • Rival autonomy programs copy the playbook rather than cede the advantage — GM's Cruise ultimately hired both researchers out of Didi and Uber, confirming that offensive-vehicle-security talent is now bid over like ML engineers.
  • Automakers exposed by the Jeep work face pressure not just to patch, but to compete with ride-hailing companies for the very researchers who found the flaws, reshaping where vulnerability expertise sits.

Third-order effects

  • If the pattern holds, vehicle-security research becomes a standard recruitment pipeline into autonomous driving, with the same small set of experts cycling between Uber, Didi, GM's Cruise and whoever bids next — concentrating knowledge of attack surfaces inside a handful of companies.
  • The longer arc cuts both ways: Uber's willingness to hire hackers contrasts sharply with its later breach history, including the Lapsus$-linked contractor-account intrusion that exposed internal bug reports, suggesting that staffing elite security talent does not by itself secure an organization's operational perimeter.

The trend: Autonomous-driving programs are absorbing the security-research community into their payrolls, turning vehicle hacking from a disclosure practice into an internal arms race among Uber, Didi and GM's Cruise.