You made two classic mistakes...
1. It didn't take the researcher 20 years to do the analysis
2. This is white hat study. How d'ya know a black hat study hasn't discovered this on release of the first handset, following the same standard procedure as the white hat study?
Note for those trying to leglislate that investigating encryption systems is unlawful: if the white hats aren't allowed to show that an encryption scheme is flawed (or publish the shortcomings), then the black hats can take advantage with no-one the wiser. Also, the institutions using the flawed systems lose a major incentive to get it right and can chill anyone suggesting otherwise.