GM's Cruise Automation hires Didi's Charlie Miller and Uber's Chris Valasek, the security researchers who had previously hacked into moving jeeps
Johana Bhuiyan / Recode :
Context & Ripple Effects
This is the second time Charlie Miller and Chris Valasek's Jeep-hacking fame has triggered a hiring move: Uber first signed the pair in 2015 right after the moving-Jeep hack, and Didi then pulled Miller to lead security at its new Mountain View AI lab in March 2017. Cruise now takes both researchers off the two ride-hailing rivals in one stroke.
The hire slots into a busy year for Cruise's technical bench — months before it named AG Gangadhar, an Uber veteran, as CTO — and signals that GM's self-driving unit is treating vehicle security as a hiring priority, not an afterthought, as it moves toward driverless operation.
First-order effects
- Cruise gains the two best-known automotive security researchers in the field, while Uber and Didi each lose security leadership — Didi's Mountain View lab loses the head it hired just months earlier.
Second-order effects
- Uber and Didi must rebuild their vehicle-security teams from a very small pool of credentialed talent, and rival AV programs now compete directly for researchers whose public hack credentials double as recruiting currency.
Third-order effects
- The pattern — hackers turned in-house defenders — points to security research becoming a standard embedded function of every autonomy program, a shift later reflected in dedicated automotive-cybersecurity ventures like Upstream's $62M raise drawing institutional backing.
The trend: Autonomous-vehicle developers are absorbing the security-research community in-house, turning the researchers who exposed connected-car vulnerabilities into competitive hires.