IT Jobs
Vendor rages after iPhone hacker given job
The code was rubbish too, says Sophos.
By John Dunn | Techworld
Published: 14:36 GMT, 26 November 09
A security firm has expressed incredulity at the news that the Australian prank hacker who wrote a program targeting Apple iPhone users has been given a job by an application developer.
The writer of the Ikee worm, Ashley Towns, sprang to prominence only two weeks ago after his creation was found to be changing the desktop wallpaper on some ‘jailbroken' or unlocked iPhones to display a picture of 1980's British pop-star Rick Astley. Now, fellow-Australian software company mogeneration is reported to have offered Towns a paid job after hearing of his efforts.
"Yey, I got the job. I'm now an iPhone application developer," says the 21-year old's Twitter feed, adopting a nonchalant attitude that has seriously annoyed more than one security company. Currently, only one is willing to go on the record.
World Tech Update: iPhone's carbon footprint app | iPhone security is flawed, says developer | Hack In The Box security show heads to Europe | Why hackers must not be rewarded
"What disheartens me is that Towns has shown no regret for what he did. He admitted specifically infecting 100 iPhones himself, letting his worm loose in the process. Now his utterly irresponsible behaviour appears to have been rewarded," said Graham Cluley of software outfit Sophos, in an emailed press statement.
"There are plenty of young coders out there who would not have acted so stupidly, and are just as worthy of an opportunity inside a software development company, and are actually quite likely to be better coders than Towns who made a series of blunders with his code," huffed Cluley, who has a long public record for taking issue with anything that even vaguely appears to reward malware writers.
The fuss is unexpected given that the Ikee program was only capable of infecting a tiny number of users, specifically those who not only had unlocked their phone's application restrictions, but were using an secure shell (SSH) utility set to the default password. The program is only confirmed to have infected 100 users in Australia.
More contentiously, however, only days after Ikee came a second piece of more serious malware targeting the same SSH vulnerability, this time in an attempt to enrol the infected handset in a spam botnet.
The theme of malware writers using their creations to tout for work, however unintentionally, has a long history. An odd example was the CV that the writer of the notorious MyDoom is said to have embedded in its code for research companies to find. More blatantly, a storm erupted when the German author of the equally destructive Netsky/sasser malware was hired by a security firm in the country.







Add your commentComments
Glen Trickson | Published: 21:18 GMT, 01 January 2010
I don't see anything wrong here. Nowadays it is easy to find app developers but it is hard to find really good ones. I am an iPhone application developer by myself so I can speak about it. If this guy had made this worm - he has a talent for sure, because it is not easy to break the iPhone's security system. Thanks for the interesting article by the way. Sincerely, Glen Tickson from iphone application development
Daniel | Published: 11:39 GMT, 02 December 2009
One bad quote spreads like wild fire! On an interview shortly after the event, on Hack (an Australian ABC radio program) he both expressed regret and apologised for the stunt.
Penguin | Published: 12:34 GMT, 01 December 2009
Personally, I can't see the problem. The guy is obviously a fairly talented coder, so why shouldn't he get a job? At least that way, he'll be too busy to mess with more iPhones...
gnumar | Published: 05:23 GMT, 01 December 2009
A worm that only attacks "hacked" iPhones run by stupid lazy people who can't change the default password os an ssh server? It's similar to what RIAA do with infected torrent files or Microsoft did with chipped XBoxes, except instead of bricking the illegal users equipment, it was simply a Rick roll. As for "getting it" and respecting the community as per below comment, I think if that community is old men on porches, yeh, I hope they don't buy any software anymore.
Negrito | Published: 20:43 GMT, 30 November 2009
I could see if they were upset that the malicious iPhone hacker was hired, but it was the one that just changed your bg... When he could have been the malcious attacke and not said a thing, and quietly stolen everyone's data. Perhaps this Sohpos guy is upset because he was about to release an attack on said iPhone users, then come in on a white horse with the fix.... hmmm...
TravisX | Published: 05:24 GMT, 28 November 2009
Isnt hiring ppl who do stuff like that the same thing microsoft and other companies do regularly to fix their poorly secured software? Idk...
sf | Published: 06:05 GMT, 27 November 2009
simple, refuse to buy software from this vendor who clearly does not "get it" or respect the community