Adam Gowdiak released information to Nokia and Sun Microsystems with respect to a potentially devastation security leak in the S40 series phones. According to articles on the net (here in dutch and here in english) it would be enough to know the target’s phonenumber to gain access to their virtually any data on the phone (e.g. contact lists).
Most consternation seems to be about the fact that Mr. Adam Gowdiak only gave a summary of his findings to Nokia and is asking about 13000 euros (20.000 dollars) for disclosing the full report.
What’s more worrying to me is that about 100 million devices in the world are now potentially easily hackable. And the question is: how will Nokia make sure (if the vulnerability claims turn out to be real) that every phone gets updated?
This is maybe again a case for having more internet connectivity on mobile phones, because then updates can be more easily distributed on a timely basis. This in the old PC world already proved to be very effective against security vulnerabilities.