Alex Halderman
   HOME

TheInfoList



OR:

J. Alex Halderman (born January 1981) is professor of Computer Science and Engineering at the
University of Michigan , mottoeng = "Arts, Knowledge, Truth" , former_names = Catholepistemiad, or University of Michigania (1817–1821) , budget = $10.3 billion (2021) , endowment = $17 billion (2021)As o ...
, where he is also director of the Center for Computer Security & Society. Halderman's research focuses on
computer security Computer security, cybersecurity (cyber security), or information technology security (IT security) is the protection of computer systems and networks from attack by malicious actors that may result in unauthorized information disclosure, t ...
and privacy, with an emphasis on problems that broadly impact society and public policy.


Education

Halderman was awarded the
A.B. Bachelor of arts (BA or AB; from the Latin ', ', or ') is a bachelor's degree awarded for an undergraduate program in the arts, or, in some cases, other disciplines. A Bachelor of Arts degree course is generally completed in three or four yea ...
'' summa cum laude'' in June 2003, the
M.A. A Master of Arts ( la, Magister Artium or ''Artium Magister''; abbreviated MA, M.A., AM, or A.M.) is the holder of a master's degree awarded by universities in many countries. The degree is usually contrasted with that of Master of Science. Tho ...
in June 2005, and the
Ph.D. A Doctor of Philosophy (PhD, Ph.D., or DPhil; Latin: or ') is the most common degree at the highest academic level awarded following a course of study. PhDs are awarded for programs across the whole breadth of academic fields. Because it is ...
in June 2009, all in Computer Science from
Princeton University Princeton University is a private research university in Princeton, New Jersey. Founded in 1746 in Elizabeth as the College of New Jersey, Princeton is the fourth-oldest institution of higher education in the United States and one of the ...
.


Academic career

As a student at Princeton, Halderman played a significant role in exposing flaws in digital rights management (DRM) software used on
compact discs The compact disc (CD) is a digital optical disc data storage format that was co-developed by Philips and Sony to store and play digital audio recordings. In August 1982, the first compact disc was manufactured. It was then released in October ...
. In 2004, he discovered that a DRM system called MediaMax CD-3 could be bypassed simply by holding down the
shift key The Shift key is a modifier key on a keyboard, used to type capital letters and other alternate "upper" characters. There are typically two shift keys, on the left and right sides of the row below the home row. The Shift key's name originated f ...
while inserting a CD. The company behind the system briefly threatened him with a $10 million lawsuit, landing him on the front page of ''
USA Today ''USA Today'' (stylized in all uppercase) is an American daily middle-market newspaper and news broadcasting company. Founded by Al Neuharth on September 15, 1982, the newspaper operates from Gannett's corporate headquarters in Tysons, Virgi ...
''. Later, in 2005, he helped show that a DRM system called
Extended Copy Protection Extended Copy Protection (XCP) is a software package developed by the British company First 4 Internet (which on 20 November 2006, changed its name to Fortium Technologies Ltd) and sold as a copy protection or digital rights management (DRM) schem ...
functioned identically to a
rootkit A rootkit is a collection of computer software, typically malicious, designed to enable access to a computer or an area of its software that is not otherwise allowed (for example, to an unauthorized user) and often masks its existence or the exis ...
and weakened the security of computers in which audio CDs were played. The ensuing
Sony BMG copy protection rootkit scandal A scandal erupted in 2005 regarding Sony BMG's implementation of copy protection measures on about 22 million CDs. When inserted into a computer, the CDs installed one of two pieces of software that provided a form of digital rights managem ...
led to the recall of millions of CDs, class action lawsuits, and enforcement action by the U.S. Federal Trade Commission. In 2008, Halderman led the team that discovered the cold boot attack against
disk encryption Disk encryption is a technology which protects information by converting it into unreadable code that cannot be deciphered easily by unauthorized people. Disk encryption uses disk encryption software or hardware to encrypt every bit of data that g ...
, which allows an attacker with physical access to a computer device to extract encryption keys or other secrets from its memory. The technique, which was initially effective against nearly every full-disk encryption product on the market, exploits DRAM
data remanence Data remanence is the residual representation of digital data that remains even after attempts have been made to remove or erase the data. This residue may result from data being left intact by a nominal file deletion operation, by reformatting o ...
to retrieve memory contents even after the device has been briefly powered off. One version of the technique involves cooling DRAM modules with freeze spray to slow data decay, then removing them from the computer and reading them in an external device. It has become an important part of computer forensics practice and has also inspired a wide variety of defensive research, such as leakage-resilient cryptography and hardware implementations of encrypted RAM. For their work developing the attack, Halderman and his coauthors received the Pwnie Award for Most Innovative Research and the Best Student Paper Award from the USENIX Security Symposium. At the
University of Michigan , mottoeng = "Arts, Knowledge, Truth" , former_names = Catholepistemiad, or University of Michigania (1817–1821) , budget = $10.3 billion (2021) , endowment = $17 billion (2021)As o ...
, Halderman and coauthors performed some of the first comprehensive studies of Internet censorship in China and in
Iran Iran, officially the Islamic Republic of Iran, and also called Persia, is a country located in Western Asia. It is bordered by Iraq and Turkey to the west, by Azerbaijan and Armenia to the northwest, by the Caspian Sea and Turkmeni ...
, and of underground " street networks" in Cuba. In 2009, he led a team that uncovered security problems and copyright infringement in client-side censorship software mandated by the Chinese government. The findings helped catalyze popular protest against the program, leading China to reverse its policy requiring its installation on new PCs. In 2011, Halderman and his students invented
Telex The telex network is a station-to-station switched network of teleprinters similar to a telephone network, using telegraph-grade connecting circuits for two-way text-based messages. Telex was a major method of sending written messages electroni ...
, a new approach to circumventing Internet censorship, partially by placing anticensorship technology into core network infrastructure outside the censoring country. With support from the
United States Department of State The United States Department of State (DOS), or State Department, is an United States federal executive departments, executive department of the Federal government of the United States, U.S. federal government responsible for the country's fore ...
, which called the technique a "generational jump forward" in censorship resistance, Halderman led a multi-institutional collaboration that further developed the technology and deployed it at ISP-scale under the name Refraction Networking. In 2015, United States Ambassador to the United Nations
Samantha Power Samantha Jane Power (born September 21, 1970) is an American journalist, diplomat and government official who is currently serving as the Administrator of the United States Agency for International Development. She previously served as the 28th ...
brought him to New York to demonstrate the technology at a meeting alongside the General Assembly. In 2012, Halderman and coauthors discovered serious flaws in
random number generators Random number generation is a process by which, often by means of a random number generator (RNG), a sequence of numbers or symbols that cannot be reasonably predicted better than by random chance is generated. This means that the particular ou ...
that weakened the
public-key cryptography Public-key cryptography, or asymmetric cryptography, is the field of cryptographic systems that use pairs of related keys. Each key pair consists of a public key and a corresponding private key. Key pairs are generated with cryptographic alg ...
used for
HTTPS Hypertext Transfer Protocol Secure (HTTPS) is an extension of the Hypertext Transfer Protocol (HTTP). It is used for secure communication over a computer network, and is widely used on the Internet. In HTTPS, the communication protocol is enc ...
and
SSH The Secure Shell Protocol (SSH) is a cryptographic network protocol for operating network services securely over an unsecured network. Its most notable applications are remote login and command-line execution. SSH applications are based on ...
servers in millions of Internet of things devices. They disclosed vulnerabilities to 60 device manufacturers and spurred changes to the
Linux Linux ( or ) is a family of open-source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991, by Linus Torvalds. Linux is typically packaged as a Linux distribution, w ...
kernel. Their work received the Best Paper Award at the USENIX Security Symposium and was named one of the notable computing articles of the year by '' ACM Computing Reviews''. Halderman played a significant role in fixing several major vulnerabilities in the TLS protocol. He was a co-discoverer of the Logjam and
DROWN Drowning is a type of suffocation induced by the submersion of the mouth and nose in a liquid. Most instances of fatal drowning occur alone or in situations where others present are either unaware of the victim's situation or unable to offer as ...
attacks, and conducted the first impact assessment of the
FREAK A freak is a person who is physically deformed or transformed due to an extraordinary medical condition or body modification. This definition was first attested with this meaning in the 1880s as a shorter form of the phrase " freak of nature ...
attack. The three flaws compromised the security of tens of millions of HTTPS websites and resulted in changes to HTTPS server software, web browsers, and the TLS protocol. Since they worked by exploiting remnants of ways in which older versions of the protocol had been deliberately weakened due to 1990s-era restrictions on the
export of cryptography from the United States The export of cryptography from the United States to other countries has experienced various levels of restrictions over time. World War II illustrated that code-breaking and cryptography can play an integral part in national security and the a ...
, they carried lessons for the ongoing public policy debate about cryptographic back doors for law enforcement. Halderman's Logjam work also provided a plausible explanation for a major question raised by the Edward Snowden revelations: how the
National Security Agency The National Security Agency (NSA) is a national-level intelligence agency of the United States Department of Defense, under the authority of the Director of National Intelligence (DNI). The NSA is responsible for global monitoring, collect ...
could be decoding large volumes of encrypted network traffic. By extrapolating their results to the resources of a major government, the researchers concluded that nation-state attackers could plausibly break 1,024-bit Diffie-Hellman key exchange using a purpose-built supercomputer. For a cost on the order of a hundred million dollars, an intelligence agency could break the cryptography used by about two-thirds of all virtual private networks. Snowden publicly responded that he shared the researchers suspicions and blamed the U.S. government for failing to close a vulnerability that left so many people at risk. The work received the 2015 Pwnie Award for Most Innovative Research and was named Best Paper at the ACM Conference on Computer and Communications Security. In 2013, Halderman and his
graduate students Postgraduate or graduate education refers to academic or professional degrees, certificates, diplomas, or other qualifications pursued by post-secondary students who have earned an undergraduate (bachelor's) degree. The organization and str ...
created ZMap, a free and open-source security scanning tool designed for information security research. By making efficient use of network bandwidth, ZMap can scan the Internet's entire IPv4 address space in under an hour, allowing researchers to quantify vulnerable systems, track the adoption of security patches, and even measure the impact of natural disasters that disrupt Internet access. Halderman and collaborators used it to track the OpenSSL Heartbleed vulnerability and raised the global rate of patching by 50% by warning the operators of unpatched web servers. Their work won the Best Paper award at the ACM Internet Measurement Conference. In partnership with
Google Google LLC () is an American Multinational corporation, multinational technology company focusing on Search Engine, search engine technology, online advertising, cloud computing, software, computer software, quantum computing, e-commerce, ar ...
, Halderman's research group used ZMap to study the security of email delivery, highlighting seven countries where more than 20% of inbound Gmail messages arrived unencrypted due to network attackers. To mitigate the problem,
Gmail Gmail is a free email service provided by Google. As of 2019, it had 1.5 billion active users worldwide. A user typically accesses Gmail in a web browser or the official mobile app. Google also supports the use of email clients via the POP and ...
added an indicator to let users know when they receive a message that wasn't delivered using encryption, resulting in a 25% increase in inbound messages sent over an encrypted connection. Halderman and his collaborators were recognized with the 2015 IRTF Applied Networking Research Prize. In order to accelerate the adoption of encryption by web servers, Halderman in 2012 partnered with
Mozilla Mozilla (stylized as moz://a) is a free software community founded in 1998 by members of Netscape. The Mozilla community uses, develops, spreads and supports Mozilla products, thereby promoting exclusively free software and open standards, w ...
and the Electronic Frontier Foundation to found the Let's Encrypt HTTPS certificate authority. Let's Encrypt provides HTTPS certificates at no cost through an automated protocol, significantly lowering the complexity of setting up and maintaining TLS encryption. Since its launch in 2016, Let's Encrypt has grown to protecting more than 150 million web sites. Halderman and his students laid the foundation for the
IETF The Internet Engineering Task Force (IETF) is a standards organization for the Internet and is responsible for the technical standards that make up the Internet protocol suite (TCP/IP). It has no formal membership roster or requirements and a ...
-standard protocol that clients use to interface with the CA, the Automated Certificate Management Environment. He sits on the board of directors of the Internet Security Research Group, the non-profit that operates Let's Encrypt. He is also a co-founder and chief scientist of Censys, a network security company that he says aims to "change the way security works by making it more quantitative, more precise, and more accurate." In 2015, Halderman was part of a team of proponents that included Steven M. Bellovin, Matt Blaze,
Nadia Heninger Nadia Heninger (born 1982) is an American cryptographer, computer security expert, and computational number theorist at the University of California, San Diego. Contributions Heninger is known for her work on freezing powered-down security devic ...
, and
Andrea M. Matwyshyn Andrea M. Matwyshyn is a United States law professor and engineering professor at The Pennsylvania State University. She is known as a scholar of technology policy, particularly as an expert at the intersection of law and computer security and f ...
who successfully proposed a security research exemption to Section 1201 of the Digital Millennium Copyright Act. Halderman was awarded a
Sloan Research Fellowship The Sloan Research Fellowships are awarded annually by the Alfred P. Sloan Foundation since 1955 to "provide support and recognition to early-career scientists and scholars". This program is one of the oldest of its kind in the United States. ...
in 2015 by the Alfred P. Sloan Foundation, and in 2019 he was named an Andrew Carnegie Fellow by the Carnegie Corporation of New York. He was profiled in the November 2016 issue of ''
Playboy ''Playboy'' is an American men's Lifestyle magazine, lifestyle and entertainment magazine, formerly in print and currently online. It was founded in Chicago in 1953, by Hugh Hefner and his associates, and funded in part by a $1,000 loan from H ...
''.


Electronic voting

After the
2016 United States presidential election The 2016 United States presidential election was the 58th quadrennial presidential election, held on Tuesday, November 8, 2016. The Republican ticket of businessman Donald Trump and Indiana governor Mike Pence defeated the Democratic ticket ...
, computer scientists, including Halderman, urged the Clinton campaign to request an
election recount An election recount is a repeat tabulation of votes cast in an election that is used to determine the correctness of an initial count. Recounts will often take place if the initial vote tally during an election is extremely close. Election reco ...
in Wisconsin, Michigan, and Pennsylvania (three swing states where
Trump Trump most commonly refers to: * Donald Trump (born 1946), 45th president of the United States (2017–2021) * Trump (card games), any playing card given an ad-hoc high rank Trump may also refer to: Businesses and organizations * Donald J. T ...
had won narrowly, while Clinton won New Hampshire and Maine narrowly) for the purpose of excluding the possibility that the hacking of electronic
voting machine A voting machine is a machine used to record votes in an election without paper. The first voting machines were mechanical but it is increasingly more common to use '' electronic voting machines''. Traditionally, a voting machine has been defi ...
s had influenced the recorded outcome. On June 21, 2017, Halderman testified before the
United States Senate Select Committee on Intelligence The United States Senate Select Committee on Intelligence (sometimes referred to as the Intelligence Committee or SSCI) is dedicated to overseeing the United States Intelligence Community—the agencies and bureaus of the federal government of ...
. The hearing, titled " Russian Interference in the 2016 U.S. Election", focused on the federal government's role in safeguarding U.S. elections from outside interference. Halderman discussed his own research in computer science and cybersecurity. He discussed one instance where he tampered with a voting machine and demonstrated the ability to change the outcome of an election. He also made three policy recommendations to safeguard U.S. elections: upgrading and replacing obsolete and vulnerable voting machines; consistently and routinely checking that American elections results are accurate; and applying cybersecurity best practices to the design of voting equipment and the management of elections. Halderman fielded questions from the Senators about his research and policy recommendations. At the end of the hearing, Chairman Burr praised Halderman for his work and noted how important his research is. Following the 2020 United States presidential election, Halderman stated that a software glitch during the unofficial vote tally was not caused by fraud, but rather by human error, and said the conspiracy theory that a supercomputer was used to switch votes from Trump to Biden was "nonsense". The subject's
expert witness An expert witness, particularly in common law countries such as the United Kingdom, Australia, and the United States, is a person whose opinion by virtue of education, training, certification, skills or experience, is accepted by the judge as ...
report on voting machine vulnerabilities was filed in a Georgia case under seal, but is sought by litigants in another case and an
election official An election official, election officer, election judge, election clerk, or poll worker is an official responsible for the proper and orderly voting at polling stations. Depending on the country or jurisdiction, election officials may be identified ...
in Louisiana. In 2022, CISA issued the advisory "Vulnerabilities Affecting Dominion Voting Systems ImageCast X" based on research by Halderman.


References


External links


J. Alex Halderman homepage
{{DEFAULTSORT:Halderman, Alex 1980s births Living people American computer scientists Computer security academics Princeton University alumni University of Michigan faculty