All the latest UK technology news, reviews and analysis

Researcher wants cash for flaws

by Iain Thomson

More from this author

13 Aug 2008

Comment: 1

  • Tweet this
briefcase of cash

A security researcher is trying to garner funds to set up his own company by charging for details of software flaws.

Adam Gowdiak says he has identified flaws in Java technology used on Nokia's Series 40 phone operating system and has built two exploits that could be used to subvert systems running the code. He is asking Nokia and Sun for €20,000 to see his proof and amend the flaws but has not ruled out selling it to third parties.

"We plan to deal with professional and serious companies from the security, telecommunication, anti-virus and government industries. Thus, we will not fulfil every single party's request for early access to our research material," he says on his site. "We can't do anything about the leak occurring at one of these companies. In case of a leak, we will immediately inform the public about its occurrence."

In the forward to his paper Gowdiak claims that the flaws would allow a hacker to control certain functions of a mobile phone running Nokia’s Series 40 operating system just by knowing the phone number of the phone.

Once into the phone it could be programmed to call high cost phone services or send duplicate copies of SMS messages or even turn the phone into a sound recorder.

The move is a break from standard security research, where vendors are informed of any flaws and researchers make their money from consultancy. Gowdiak says this would not give him the freedom to do the research he wants but that he had given the companies a brief update on the flaws.

“If one takes into account that experienced and skilled third parties charge between $200 to $250 per hour for security evaluation services, €20,000 is equal to three to four weeks of work. So, you get the six months of work for the price of one month,” he said.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Infrastructure Technical Lead

Position: Infrastructure Technical Lead Experience...

Channel Manager / Sales Manager / Software - 40k to 45k ote 20k

Channel Manager / Sales Manager /Software solutions...

BUSINESS SALES / SOFTWARE SALES / BUSINESS CONSULTANT 60K + BONUS

BUSINESS SALES / IT SALES / BUSINESS CONSULTANT / LONDON...

Technical Sales / Direct Sales / Software / London 45K OTE 90K

TECHNICAL SALES / ACCOUNT EXECUTIVE / SOFTWARE SALES...

To send to more than one email address, simply separate each address with a comma.