Geohot
   HOME

TheInfoList



OR:

George Francis Hotz (born October 2, 1989), alias geohot, is an American
security hacker A security hacker or security researcher is someone who explores methods for breaching or bypassing defenses and exploiting weaknesses in a computer system or network. Hackers may be motivated by a multitude of reasons, such as profit, pro ...
, entrepreneur, and
software engineer Software engineering is a branch of both computer science and engineering focused on designing, developing, testing, and maintaining software applications. It involves applying engineering principles and computer programming expertise to develop ...
. He is known for developing
iOS jailbreaks Ios, Io or Nio (, ; ; locally Nios, Νιός) is a Greek island in the Cyclades group in the Aegean Sea. Ios is a hilly island with cliffs down to the sea on most sides. It is situated halfway between Naxos and Santorini. It is about long and ...
, reverse engineering the
PlayStation 3 The PlayStation 3 (PS3) is a home video game console developed and marketed by Sony Computer Entertainment (SCE). It is the successor to the PlayStation 2, and both are part of the PlayStation brand of consoles. The PS3 was first released on ...
, and for the subsequent lawsuit brought against him by Sony. From September 2015 onwards, he has been working on his
vehicle automation Vehicular automation is using technology to assist or replace the operator of a vehicle such as a car, truck, aircraft, rocket, military vehicle, or boat. Assisted vehicles are ''semi-autonomous'', whereas vehicles that can travel without a ...
machine learning Machine learning (ML) is a field of study in artificial intelligence concerned with the development and study of Computational statistics, statistical algorithms that can learn from data and generalise to unseen data, and thus perform Task ( ...
company comma.ai. Since November 2022, Hotz has been working on tinygrad, a deep learning framework.


Education

Hotz attended the Academy for Engineering and Design Technology at the
Bergen County Academies Bergen County Academies (BCA) is a tuition-free public magnet high school located in Hackensack, New Jersey, that serves students in the ninth through twelfth grades from all of Bergen County, in the U.S. state of New Jersey. The school was fo ...
, a
magnet A magnet is a material or object that produces a magnetic field. This magnetic field is invisible but is responsible for the most notable property of a magnet: a force that pulls on other ferromagnetic materials, such as iron, steel, nickel, ...
public high school A state school, public school, or government school is a primary school, primary or secondary school that educates all students without charge. They are funded in whole or in part by taxation and operated by the government of the state. State-f ...
in
Hackensack, New Jersey Hackensack is the most populous municipality in and the county seat of Bergen County, New Jersey, Bergen County, in the U.S. state of New Jersey.
. Hotz is an alumnus of the Johns Hopkins Center for Talented Youth program. Hotz also briefly attended
Rochester Institute of Technology The Rochester Institute of Technology (RIT) is a private university, private research university in Henrietta, New York, a suburb of Rochester, New York, Rochester. It was founded in 1829. It is one of only two institute of technology, institut ...
and
Carnegie Mellon University Carnegie Mellon University (CMU) is a private research university in Pittsburgh, Pennsylvania, United States. The institution was established in 1900 by Andrew Carnegie as the Carnegie Technical Schools. In 1912, it became the Carnegie Institu ...
.


Security research


iOS

In August 2007, seventeen-year-old George Hotz became the first person reported to remove the
SIM lock A SIM lock, simlock, network lock, carrier lock or (master) subsidy lock is a technical restriction built into GSM and CDMA mobile phones by mobile phone manufacturers for use by service providers to restrict the use of these phones to specific co ...
on an iPhone."Machine Politics: The man who started the hacker wars."
,"
The New Yorker ''The New Yorker'' is an American magazine featuring journalism, commentary, criticism, essays, fiction, satire, cartoons, and poetry. It was founded on February 21, 1925, by Harold Ross and his wife Jane Grant, a reporter for ''The New York T ...
", May 7, 2012. Retrieved April 30, 2012
He traded his second unlocked 8 GB iPhone to Terry Daidone, the founder of CertiCell, for a
Nissan 350Z : The Nissan 350Z (known as Nissan Fairlady Z (Z33) in Japan) is a two-door, two-seater sports car that was manufactured by Nissan, Nissan Motor Corporation from 2002 until 2009 and marks the fifth generation of Nissan's Nissan Z-car, Z-car line. ...
and three 8 GB iPhones. In October 2009, Hotz released
blackra1n blackra1n is a program that jailbreaks versions 3.1, 3.1.1 and 3.1.2 of Apple's operating system for the iPhone and the iPod Touch, known as iOS. The program uses a bug in the USB code of the firmware for the iPhone and the iPod Touch, allow ...
. It was compatible with all iPhone and iPod Touch devices running iOS 3.1.2. On July 13, 2010, Hotz announced the discontinuation of his jailbreaking activities, citing demotivation over the technology and the unwanted personal attention. Nevertheless, he continued to release new software-based jailbreak techniques until October 2010.


PlayStation 3

In December 2009, Hotz announced his initial intentions to breach security on the
PlayStation 3 The PlayStation 3 (PS3) is a home video game console developed and marketed by Sony Computer Entertainment (SCE). It is the successor to the PlayStation 2, and both are part of the PlayStation brand of consoles. The PS3 was first released on ...
. On January 22, 2010, he announced that he had gained read and write access to the machine's system memory as well as
hypervisor A hypervisor, also known as a virtual machine monitor (VMM) or virtualizer, is a type of computer software, firmware or hardware that creates and runs virtual machines. A computer on which a hypervisor runs one or more virtual machines is called ...
level access to the machine's CPU. On January 26, 2010, Hotz released the exploit to the public. On March 28, 2010, Sony responded by announcing their intention to release a PlayStation 3
firmware update A patch is data that is intended to be used to modify an existing software resource such as a program or a file, often to fix bugs and security vulnerabilities. A patch may be created to improve functionality, usability, or performance. A pa ...
that would remove the
OtherOS OtherOS is a feature of early versions of Sony Computer Entertainment's PlayStation 3 video game console, allowing user installed software, such as Linux or FreeBSD. Software running in the OtherOS environment has access to 6 of the 7 Synergistic ...
feature from all models, a feature that was already absent on the newer Slim revisions of the machine. On July 13, 2010, Hotz posted a message on his Twitter account stating that he had abandoned his efforts.The PS3 just too difficult to crack – GamingBolt.com: Video Game News, Reviews, Previews and Blog
. GamingBolt.com. Retrieved February 16, 2011.


Sony lawsuit

On December 29, 2010, hacking group fail0verflow did a presentation at the 27th
Chaos Communications Congress The Chaos Communication Congress is an annual hacker conference organized by the Chaos Computer Club. The congress features a variety of lectures and workshops on technical and political issues related to security, cryptography, privacy and ...
where they exposed a mistake of Sony in their usage of
ECDSA In cryptography, the Elliptic Curve Digital Signature Algorithm (ECDSA) offers a variant of the Digital Signature Algorithm (DSA) which uses elliptic-curve cryptography. Key and signature sizes As with elliptic-curve cryptography in general, the ...
signatures without publishing the corresponding private key. This key was used by Sony to prevent piracy. On January 2, 2011, Hotz posted a copy of the private key of the PlayStation 3 on his website. These keys were later removed from his website as a result of legal action by Sony against fail0verflow and Hotz. In response to his continued publication of PS3 exploit information, Sony filed on January 11, 2011, for an application for a temporary restraining order ( TRO) against him in the US District Court of Northern California. Hotz published his commentary on the case, including a song about the "disaster" of Sony. Sony in turn has demanded that social media sites, including YouTube, hand over IP addresses of people who visited Geohot's social pages and videos, the latter being the case only for those who "watched the video and 'documents reproducing all records or usernames and IP addresses that have posted or published comments in response to the video".
PayPal PayPal Holdings, Inc. is an American multinational financial technology company operating an online payments system in the majority of countries that support E-commerce payment system, online money transfers; it serves as an electronic alter ...
granted Sony access to Geohot's PayPal account contribution transactions, and the judge of the case granted Sony permission to view the IP addresses of everyone who visited geohot.com. In April 2011, it was revealed that Sony and Hotz had settled the lawsuit out of court, on the condition that Hotz would never again resume any hacking work on Sony products.


Android

In June 2014, Hotz published a root exploit software hack for
Samsung Galaxy S5 The Samsung Galaxy S5 is an Android-based smartphone unveiled, produced, released and marketed by Samsung Electronics as part of the Samsung Galaxy S series. Unveiled on 24 February 2014 at Mobile World Congress in Barcelona, Spain, it was relea ...
devices used in the US market. The exploit is built around the CVE-2014-3153 vulnerability, which was discovered by hacker Pinkie Pie, and it involves an issue in the
futex In computing, a futex (short for "fast userspace mutex") is a kernel system call that programmers can use to implement basic locking, or as a building block for higher-level locking abstractions such as semaphores and POSIX mutexes or conditio ...
subsystem that in turn allows for
privilege escalation Privilege escalation is the act of exploiting a Software bug, bug, a Product defect, design flaw, or a configuration oversight in an operating system or software application to gain elevated access to resource (computer science), resources that ar ...
. The exploit, known as ''towelroot'', was designated as a "one-click Android rooting tool".Towelroot: One-Click Android Rooting Tool Released By Geohot
, The Hacker News, June 1, 2015.
Although originally released for the Verizon Galaxy S5, the root exploit was made compatible with most Android devices available at that time. For example, it was tested and found to work with the AT&T Galaxy S5, Nexus 5, and Galaxy S4 Active. Updates continued to be applied to the root exploit to increase its capabilities with other devices running Android. Updates to the Android operating system closed the source of the exploit. Samsung officially responded to the towelroot exploit by releasing updated software designed to be immune from the exploit.Samsung's official response to "Towelroot"
Announcements: July 7, 2014, Samsung KNOX News


Career

Hotz made a meaningful side income from public donations solicited for his security exploits. Hotz worked at
Facebook Facebook is a social media and social networking service owned by the American technology conglomerate Meta Platforms, Meta. Created in 2004 by Mark Zuckerberg with four other Harvard College students and roommates, Eduardo Saverin, Andre ...
between May 2011 and January 2012. On July 16, 2014,
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
hired Hotz to work with the
Project Zero Project Zero is a team of security analysts employed by Google tasked with finding Zero-day (computing), zero-day vulnerabilities. It was announced on 15 July 2014. History After finding a number of flaws in software used by many end-users whi ...
team where he developed Qira for dynamically analysing application binaries. Hotz was employed at the
startup A startup or start-up is a company or project undertaken by an entrepreneur to seek, develop, and validate a scalable business model. While entrepreneurship includes all new businesses including self-employment and businesses that do not intend to ...
Vicarious Vicarious may refer to: * Vicariousness, experiencing through another person * Vicarious learning, observational learning In law * Vicarious liability, a term in common law * Vicarious liability (criminal), a term in criminal law Religion * Subst ...
from January until July 2015. On November 18, 2022, Hotz announced that he had been hired by
Twitter Twitter, officially known as X since 2023, is an American microblogging and social networking service. It is one of the world's largest social media platforms and one of the most-visited websites. Users can share short text messages, image ...
for a 12-week internship, with the task of fixing Twitter search as well as removing the pop up log-in screen displayed to users scrolling without being logged in to an account. On December 20, after less than 5 weeks at the role, he resigned, stating “appreciate the opportunity, but didn’t think there was any real impact I could make there”.


comma.ai

Hotz founded his AI startup, comma.ai, in September 2015. In an interview with Bloomberg, Hotz revealed that the company was building vehicular automation technology based on machine learning algorithms. Hotz built a working self-driving 2016
Acura ILX The Acura ILX is a compact executive car manufactured and marketed by Honda under the Acura brand, based on the ninth-generation Civic sedan. The ILX replaced the Canadian market exclusive Acura CSX. The gasoline-electric hybrid version was ...
, which he demonstrated on California's Interstate 280 freeway in a video, resulting in a cease and desist letter from the
California Department of Motor Vehicles The California Department of Motor Vehicles (DMV) is the state agency that registers motor vehicles and boats and issues driver licenses in the U.S. state of California. It regulates new car dealers (through the New Motor Vehicle Board), c ...
. Hotz wanted to sell his technology to
Tesla Motors Tesla, Inc. ( or ) is an American multinational automotive and clean energy company. Headquartered in Austin, Texas, it designs, manufactures and sells battery electric vehicles (BEVs), stationary battery energy storage devices from hom ...
, meeting with CEO
Elon Musk Elon Reeve Musk ( ; born June 28, 1971) is a businessman. He is known for his leadership of Tesla, SpaceX, X (formerly Twitter), and the Department of Government Efficiency (DOGE). Musk has been considered the wealthiest person in th ...
. Hotz claims that Musk offered him $12 million (minus $1 million for every month it took Hotz to work on the task) to create a driving system that could replace the MobilEye solution that Tesla used at the time, which was disputed by Musk. Musk offered advice on Hotz's
self-driving car A self-driving car, also known as an autonomous car (AC), driverless car, robotic car or robo-car, is a car that is capable of operating with reduced or no human input. They are sometimes called robotaxis, though this term refers specifica ...
project in a December 2015 interview. On October 27, 2016, the
National Highway Traffic Safety Administration The National Highway Traffic Safety Administration (NHTSA ) is an agency of the U.S. federal government, part of the Department of Transportation, focused on automobile safety regulations. NHTSA is charged with writing and enforcing Feder ...
(NHTSA) informed Hotz that the product was legally required to comply with
Federal Motor Vehicle Safety Standards The Federal Motor Vehicle Safety Standards (FMVSS) are U.S. federal vehicle regulations specifying design, construction, performance, and durability requirements for motor vehicles and regulated automobile safety-related components, systems, and ...
, and requested information that would confirm such compliance. A day later, George Hotz tweeted from Shenzhen that the comma one was cancelled. Kristen Lee stated on Jalopnik that the NHTSA was simply trying to open a dialog, and commented: "Instead, they got the worst attitude possible from Silicon Valley: try and regulate us, thought leaders, and we’ll take our ball and go home." comma.ai open sourced their self driving car software (called openpilot) on November 30, 2016, emphasizing its intended use for research without a warranty. On September 14, 2018, comma.ai announced Hotz would become the Head of Research Team for the project, and appointed Riccardo Biasini as the new CEO of the company. He left in March 2019, but returned in May 2019 to become president once again. On January 7, 2020, comma.ai debuted its $999 comma two ADAS (driver-assist) device at the annual CES tech show in Las Vegas. On August 23, 2022, comma.ai was sued by
patent troll In international law and business, patent trolling or patent hoarding is a categorical or pejorative term applied to a person or company that attempts to enforce patent rights against accused infringers far beyond the patent's actual value or ...
Sucxess LLC. On October 31, 2022, Hotz said he is taking some time away from comma.ai.


tiny corp

Hotz founded tiny corp on November 5, 2022. tiny corp aims to port
machine learning Machine learning (ML) is a field of study in artificial intelligence concerned with the development and study of Computational statistics, statistical algorithms that can learn from data and generalise to unseen data, and thus perform Task ( ...
instruction sets to hardware accelerators. On May 24, 2023, tiny corp announced that they raised $5.1M to build computers for machine learning and develop neural network framework called tinygrad. Tinygrad, the neural network framework developed by Tiny Corp, aims to provide a balance between the simplicity of Andrej Karpathy's micrograd framework and the functionality of the
PyTorch PyTorch is a machine learning library based on the Torch library, used for applications such as computer vision and natural language processing, originally developed by Meta AI and now part of the Linux Foundation umbrella. It is one of the mo ...
framework. tinygrad aims to realize performance gains over PyTorch through a number of optimizations, including
dynamic compilation Dynamic compilation is a process used by some programming language implementations to gain performance during program execution. Although the technique originated in Smalltalk,Peter L. Deutsch and Alan Schiffman. "Efficient Implementation of the S ...
, fusing of operations, and a greatly simplified backend. tinygrad is currently used to enable comma.ai's openpilot framework to run on the company's dedicated hardware, which includes a
Snapdragon 845 The Qualcomm Snapdragon suite of systems on chips (SoCs) are designed for use in smartphones, tablets, laptops, 2-in-1 PCs, smartwatches, and smartbooks devices. Before Snapdragon SoC made by Qualcomm before it was renamed to Snapdrago ...
GPU. Additionally, tiny corp builds the TinyBox, a $15,000 AI computer aimed at local model training and inference, serving as a personal compute cluster.


Other activities and recognition

Hotz was a finalist at the 2004
Intel International Science and Engineering Fair The Regeneron International Science and Engineering Fair (ISEF) is an annual science fair in the United States. It is owned and administered by the Society for Science, a 501(c)(3) non-profit organization based in Washington, D.C. Each May, more ...
(ISEF), a science competition for high school students, in Portland, Oregon with his project "The Mapping Robot". Recognition included interviews on the ''
Today Show ''Today'' (also called ''The Today Show'') is an American morning television show that airs weekdays from 7:00 a.m. to 11:00 a.m. on NBC. The program debuted on January 14, 1952. It was the first of its genre on American television ...
'' and ''
Larry King Show ''The Larry King Show'' was an American overnight radio talk show hosted by Larry King. It was broadcast nationally over the Mutual Broadcasting System from January 1978 to May 1994. A typical program consisted of King interviewing a guest, the ...
''. Hotz was a finalist at the 2005 ISEF competition, with his project "The Googler". Hotz competed at the 2007 ISEF where his 3D imaging project, entitled "I want a
Holodeck The Holodeck is a fictional device from the television franchise ''Star Trek'' which uses "holograms" (projected light and electromagnetic energy which create the illusion of solid objects) to create a realistic 3D simulation of a real or imagi ...
", received awards and prizes in several categories including a $20,000 Intel scholarship. He travelled to Sweden to speak about the project at the
Stockholm International Youth Science Seminar Stockholm International Youth Science Seminar (SIYSS) is an annual weeklong event for young international scientists, arranged in connection with the Nobel festivities by the SIYSS Committee of the Swedish Federation of Young Scientists. The histor ...
. In March 2008, ''
PC World ''PC World'' (stylized as PCWorld) is a global computer magazine published monthly by IDG. Since 2013, it has been an online-only publication. It offers advice on various aspects of PCs and related items, the Internet, and other personal tec ...
'' listed Hotz as one of the top 10 Overachievers under 21. In August 2013, Hotz attended the
DEF CON DEF CON (also written as DEFCON, Defcon, or DC) is a Computer security conference, hacker convention held annually in Las Vegas Valley, Las Vegas, Nevada. The first DEF CON took place in June 1993 and today many attendees at DEF CON include comp ...
hacker convention with Carnegie Mellon's Plaid Parliament of Pwning (PPP). PPP placed first in the DEF CON Capture the Flag (CTF) tournament. Later in 2013, Hotz also competed in the 2013
New York University Tandon School of Engineering The New York University Tandon School of Engineering (commonly referred to as Tandon) is the engineering and applied sciences school of New York University. Tandon is the second oldest private engineering and technology school in the United St ...
Cyber Security Awareness Week (CSAW). Working alone, Hotz took first place under the pseudonym tomcr00se. In August 2014, Hotz once again competed as part of Carnegie Mellon's PPP to win the DEF CON CTF tournament for a second year in a row. The team also won the DEF CON "Crack Me If You Can" tournament. In 2013, Hotz began making
hip hop music Hip-hop or hip hop (originally disco rap) is a popular music Music genre, genre that emerged in the early 1970s from the African Americans, African-American community of New York City. The style is characterized by its synthesis of a wide r ...
on his
SoundCloud SoundCloud is a German audio streaming service owned and operated by SoundCloud Global Limited & Co. KG. The service enables its users to upload, promote, and share audio. Founded in 2007 by Alexander Ljung and Eric Wahlforss, SoundCloud is ...
, tomcr00se. he has made 28 original songs and covers. Hotz also has a Twitch channel, where he frequently does programming livestreams. his twitch channel has over 83k followers. In February 2020, Hotz founded the cheapETH crypto currency.


References


External links

* * {{DEFAULTSORT:Hotz, George 1989 births American bloggers Bergen County Academies alumni Living people People from Glen Rock, New Jersey Computer security specialists Facebook employees Google employees Hackers