Chris Valasek

{{Short description|American cyber security professional (born 1982)}}

{{Infobox scientist

|name = Chris Valasek

|image =

|image_size =

|caption = Chris Valasek

|birth_date = {{birth date and age|1982|06|02}}

|birth_place = Ford City, Pennsylvania, USA

|alma_mater = University of Pittsburgh

|fields = Computer Science

|known_for = Summercon Organizer, Automotive Hacking

}}

Chris Valasek is a computer security researcher with Cruise Automation,{{Cite web |last=Weise |first=Elizabeth |title=GM's self-driving car unit Cruise hires famous car hackers |url=https://www.usatoday.com/story/tech/talkingtech/2017/07/31/gms-self-driving-car-unit-cruise-hires-famous-car-hackers/525651001/ |access-date=2025-03-26 |website=USA TODAY |language=en-US |quote=Charlie and Chris are getting the band back together.}} a self-driving car startup owned by GM, and most recently known for his work in automotive security research.{{cite news|url=https://www.reuters.com/article/us-uber-tech-security-idUSKCN0QX2BQ20150828|title=Uber hires two security researchers to improve car technology|date=August 28, 2015|work=[Reuters]}}

Career

Prior to his current employment, he worked for:

Education

Valasek holds a Bachelors in Computer Science from University of Pittsburgh. He currently lives in Pittsburgh, Pennsylvania.

Security Research

= Microsoft Windows =

Valasek has publicly demonstrated many security vulnerabilities, with particular focus on Microsoft Windows heap exploitation.

His 2009 presentation "Practical Windows XP/2003 Heap Exploitation"{{cite journal |last=McDonald |first=John |last2=Valasek |first2=Chris |date=2009-07-25 |title=Practical Windows XP/2003 Heap Exploitation |url=http://www.blackhat.com/presentations/bh-usa-09/MCDONALD/BHUSA09-McDonald-WindowsHeap-PAPER.pdf |journal=Black Hat Briefings |pages=84 |access-date=2017-03-01 |via=Black Hat Briefings}} at Black Hat presented a novel approach to gaining elevated access in a Windows environment.

Later research, such as his 2010 paper "Understanding the Low Fragmentation Heap: From Allocation to Exploitation"{{cite journal |last=Valasek |first=Chris |date=2010-07-25 |title=Understanding the Low Fragmentation Heap |url=http://illmatics.com/Understanding_the_LFH.pdf |journal=Illmatics.com |pages=86 |access-date=2017-03-01 |via=Black Hat Briefings}} demonstrated ways to circumvent vendor mitigations to the approaches outlined in his prior work.

= Automotive Security =

In 2013, he and Charlie Miller demonstrating a number of attack vectors against ECUs in automotive control networks.{{cite magazine|url=https://www.forbes.com/sites/andygreenberg/2013/07/24/hackers-reveal-nasty-new-car-attacks-with-me-behind-the-wheel-video/|title=Hackers Reveal Nasty New Car Attacks--With Me Behind The Wheel (Video)|date=2013-07-24|author=Andy Greenberg|author-link=Andy Greenberg|magazine=Forbes}} Together with Miller, they have produced a survey of remote attack surfaces in then-current model year automobiles, an important first step in establishing the state of the art of automotive security and safety research.{{cite journal |last=Miller |first=Charlie |last2=Valasek |first2=Chris |title=A Survey of Remote Automotive Attack Surfaces |url=http://illmatics.com/remote%20attack%20surfaces.pdf |journal=Black Hat USA 2014 |pages=92 |access-date=2017-03-01 |via=Black Hat Briefings}}{{cite magazine|url=https://www.wired.com/2014/08/car-hacking-chart/|title=How Hackable Is Your Car? Consult This Handy Chart|date=2014-08-06|author=Andy Greenberg|magazine=Wired}}

= Summercon =

Chris has been involved with the conference as part of the Summercon planning committee since 2003.{{Cite web |title=.:: Phrack Magazine ::. |url=https://phrack.org/issues/68/18 |access-date=2025-04-06 |website=phrack.org |quote=SummerCon enjoyed a stand in Pittsburgh for two years where Redpantz became a member of the planning committee and began to emcee.}} He is currently listed as Chairman Emeritus{{Cite web |title=ORGANIZERS – Summercon |url=https://www.summercon.org/organizers/ |access-date=2025-04-06 |website=www.summercon.org |quote=Chris Valasek Chairman Emeritus}} on the Summercon Organizer page.

References

{{Reflist}}