Steven Valdez is a research engineer with 14 years of experience specializing in security, cryptography, and privacy, holding a BS and MEng from MIT. He spent a decade at Google working on Chrome, Network Security, BoringSSL, and privacy-preserving APIs, and now applies that expertise at Aarno Labs. His open-source contributions to high-profile crypto projects like BoringSSL, Conscrypt, and ring show deep practical knowledge of TLS, certificate verification, and secure key handling. Steven combines low-level crypto engineering with internet standards work, focusing on rugged, production-ready fixes rather than academic prototypes. Based in Chicago, he blends research-grade rigor with production shipping experience and a knack for finding subtle protocol and implementation gaps. An understated strength is his track record of improving platform security across both Java and Rust crypto stacks, demonstrating cross-language fluency in hard security problems.
14 years of coding experience
10 years of employment as a software developer
Bachelor of Science - BS Computer Science, Bachelor of Science - BS Computer Science at Massachusetts Institute of Technology
Contributions summary:Steven's contributions primarily involve modifying and improving code within the BoringSSL library. Their work focused on enhancing the cryptographic core, specifically addressing security vulnerabilities and optimizing key handling. The user introduced checks for null values and corrected logic errors related to certificate verification, resulting in increased robustness. Furthermore, they have been adding support for upcoming features, notably TLS 1.3.
Conscrypt is a Java Security Provider that implements parts of the Java Cryptography Extension and Java Secure Socket Extension.
Role in this project:
Security Engineer
Contributions:5 commits, 6 comments in 2 months
Contributions summary:Steven's contributions primarily focus on security-related modifications within the Conscrypt Java Security Provider. They made changes to the `NativeCrypto.java`, and other Java files, to manage TLS cipher suites, specifically blacklisting TLS 1.3 ciphersuites from Android. These changes appear to be related to the security of TLS and fixing initialization of SSL context and parameters. The commits demonstrate an understanding of TLS protocols and Android security implementations.
securecryptographysocketprovidersecurity
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.