Apple files lawsuit against Corellium for iOS emulation
bloomberg.com
bloomberg.com
For example, as a security researcher, I could order a copy of iOS 11.1 running on an iPhone 6 32GB. It would be spun up and accessible in about 3 or 4 minutes, and I could run direct commands on the Darwin kernel underneath.
Why is this illegal? Correlium DOES NOT have a physical iPhone 6 that it is screen recording. They actually have made copies of various iOS releases, and are running them on virtualization software, while making big bucks from the researchers for this technology.
Will Apple win? Well, if you look at the Apple vs Psystar case of 2007 (in which Apple won pretty much every case and appeal and every injunction they filed for), the odds of victory from Correlium is about as likely as Bill DeBlasio winning the 2020 Election.
It most definitely is not unethical. Illegal perhaps, but unethical? Please.
If they are trying to make money off selling to people doing something other than security research (say, playing games and using apps), than yeah, that'd be unethical.
Edit: Oops. Meant to reply to blazespin.
Like, I could see fair use for an individual security researcher, but a business making profit circumventing Apple's ToS and security in multiple ways, and encouraging others to do the same? I find it unlikely to pass.
Let's say someone ran a service to help you hack AirBNB. Legal?
Let's say someone ran a service which spun up Windows Virtual Machines, of any model, which were not genuine licenses, for the sake of "security research." Legal?
Let's say someone ran a service which helped you find bugs in anti-cheat software and run those bugs on your PC. Legal?
Etc. It's tough.
Microsoft outright encourages this. From https://developer.microsoft.com/en-us/microsoft-edge/tools/v...:
Before installing, please note:
These virtual machines expire after 90 days. We recommend setting a snapshot when you first install the virtual machine which you can roll back to later.
Edit: Furthermore:
The Microsoft Software License Terms for the Microsoft Edge and IE VMs are included in the release notes[1] and supersede any conflicting Windows license terms included in the VMs. By downloading and using this software, you agree to these license terms.
[1]: https://az792536.vo.msecnd.net/vms/release_notes_license_ter...
From the license:
NO ACTIVATION. To prevent its unlicensed use, the software contains activation enforcement technology. Because the software is licensed for testing use only, you are not licensed to activate the software for any purpose even if it prompts you to do so.
Not only are you encouraged to use the software without paying for a license for testing purposes, you're outright forbidden from doing so.
Microsoft are definitely not 'someone' in the sense OP intended.
Let's say someone ran a service which spun up Windows Virtual Machines, of any model, which were not genuine licenses, for the sake of "security research." Legal?
Here, I see "someone" as a security researcher, not someone who is reselling the VMs. The OP may have meant someone spinning them up to resell them to security researchers, but, given the ambiguity, I do think it's important to point out that you can spin up free Windows VMs for research purposes--you are explicitly licensed to do so.
If the analogy is taken literally, then the answer is: yes, it's legal as long as you're not reselling them.
But MS does not encourage you to sell access to those unlicensed copies. Corellium's business model isn't security research, it's taking illegal copies and "renting" them out to people for money. And people go to them because it's convenient, not because there is no other legal way.
Let's say someone ran a service which spun up Windows Virtual Machines, of any model, which were not genuine licenses, for the sake of "security research." Legal?
You can, in fact, legally spin up arbitrary Windows VMs for security research without a paid license.
If any comparison is to be made here, it should be between Apple's licensing and Microsoft's licensing:
* Microsoft will allow you to use Windows without paying for research purposes; Apple will not.
* Microsoft will allow you to run Windows on hardware purchased from a third party, or even hardware you've made yourself; Apple will not.
* Microsoft goes out of their way to facilitate research with the help of virtualization technology; Apple goes out of their way to impede it.
As a customer of both companies, Apple's approach here really rubs me the wrong way and definitely contributes to my unwillingness to completely embrace the Apple ecosystem.
Edit: To be clear, this part:
These virtual machines expire after 90 days. We recommend setting a snapshot when you first install the virtual machine which you can roll back to later.
If you set a snapshot and roll back to it later, you get another 90 days. Rinse and repeat.
Just because someone gave you the right to use for free something that belongs to them doesn't mean you are allowed to sell that right or that "something", or even pass it on for free.
The analogy is harmful because it implies that it's unreasonable to expect that like Microsoft and Apple would allow their software to be used for free for research purposes; it doesn't mention resale of the software. I don't see that as an unreasonable expectation; Microsoft does it without issue.
Edit: Just to be clear, Microsoft is not offering these VMs as a service. You are required to download the image and run it yourself. It’s basically just a license to use Windows for free as long as it’s for a specific kind of research.
You can run z/OS just fine on Hercules (mainframe emulator) but IBM does not allow it, and for this reason no one does it.
Given the potential profit in providing emulated z/OS hardware, the fact that no one provides this is quite telling.
Hercules is an interesting case because it's widely rumored to be used inside IBM to run modern System Z releases.
In this case however the company in question isn't just making and selling an emulator you can run iOS on, its selling hosted iOS as a service, which is a clear license violation - just making the emulator and instructions for use available for sale would be quite legal.
This is _quite_ unethical.
I would argue it IS unethical. When speaking of ethics, the intention matters.
If they were just offering these tools to security researchers at cost or for free, then I could agree, but they aren't. They're intentionally doing something that wasn't allowed to make money.
This lawsuit (if it goes to court - many cases do not) would decide whether it is, or is not, "allowed". Still, contracts can contain all sorts of clauses, not all of them will be permitted/enforceable by law. Famously, non-compete agreements aren't enforceable in California but that doesn't stop them from appearing in California employment contracts.
The iOS copy isn't running on the actual iPhone, which is a massive violation of the iOS ToS which says that iOS can only run on an Apple-branded device.
There is also legal precedent upholding this in Apple vs Psystar (2007), in which a company claimed "fair use" when selling their own "hackintoshes" and a UEFI product which made building "hackintoshes" easier.
How did Psystar do? They lost. Terribly. And they had a surprisingly robust legal team, making it all the way to the point to appealing to the Supreme Court (the SCOTUS denied the request).
Or, well, enter a legal contract with Apple.
There's also a bunch of details to that case that may make that decision irrelevant here.
But I grew up during the FOSS craze.
No. Nothing in copyright law allows this. However, everything in contract law allows this.
Copyright law forms the underlying background situation only. Under 17 U.S.C. § 106, the default is that only the copyright owner may make copies (including, e.g., the copy made when installing the software or the copy made into memory when running it).
However, those exclusive rights may be licensed to others. (Under 17 U.S.C. § 117, a software licensee, or the lawful owner of a copy of the software, may always copy the software to install/run or to make an archival copy.)
Licenses are governed by contract law. Contract law typically consists of an offer, acceptance, and some thing of value traded by each side. Restatement (Second) of Contracts, § 17(1).
The thing exchanged can be a promise, a forbearance (i.e., a license), a conditional promise, or any number of things. Restatement (Second) of Contracts, §§ 71-81.
In this case, the license to copy the software to your internal storage and from there into RAM is offered conditionally. In return, you promise not to run it on non-Apple systems. If you break your promise, the conditions of Apple's license to you are triggered and your license terminates. All of that is governed by contract law.
The backstop to that, though - the legal stick - is that now you're using an unlicensed copy and continuously copying it into RAM to use it. That is what opens you up to copyright violation liability.
Perhaps the whole EULA thing is old news but I'm still not sure if I'm bound to every condition stated in a EULA when my cat clicks "Agree"... I thought at one point, the courts ruled that EULAs are pretty toothless. These are honest questions - I have no clue.
If I can get my hands on your car without specifically agreeing a contract to pay for it, ...
The core of the legal concept of property is the right to exclude others. This is an academic philosophical lens to view it through, but it's fundamental to understanding how the law treats these things. "Property" isn't a physical thing itself, it's your right to exclude others. (This, by the way, is also a useful lens through which to view Fourth Amendment jurisprudence).
The property you're "stealing" in a copyright infringement case isn't the bits themselves. The property is the right to exclude others from copying, publicly performing, etc. By doing so without a license, you're denying the software licensor the ability to exclude you.
IANAL but I would be really surprised if courts are as lenient with businesses as they are with consumers. I think it's unreasonable to expect a normal person to be able to go through the EULA of every product they use. I don't think it's unreasonable to expect a business to understand whether the way they are making money is legal.
They are freely available for download from Apple.
See here for handy index: https://ipsw.me/
"some thing of value" - usually termed "consideration".
What is the "consideration" that Apple receives?
If Apple grants no license, the other party cannot do anything with the software, including those uses that would remain forbidden under the license. In granting a license, Apple allows some uses, but retains some limitations. Thus, Apple has only granted rights to the other party, and has received nothing in return that Apple did not have before.
"But wait!" you say. "That seems circular!" Indeed. The issue comes from a slight ambiguity in the term "license." The word is used both to mean the contract between Apple and the licensee, and the permission granted in that license. Strictly speaking, the former is a "license agreement," but referring to the agreement just as the "license" is commonplace.
Indeed, the first line of the iOS Software License Agreement reads: "PLEASE READ THIS SOFTWARE LICENSE AGREEMENT (“LICENSE”) CAREFULLY BEFORE USING YOUR iOS DEVICE"
Apple gives you permission to use (and, to some extent, copy) iOS. In return, you give Apple a promise to use the software in accordance with the terms of the license. You also give Apple other consideration, such as a waiver of liability in the event that you view indecent or offensive material on your iOS device.
Your point is an astute one. Section 73 of the Restatement (Second) of Contracts reads: "Performance of a legal duty owed to a promisor which is neither doubtful nor the subject of honest dispute is not consideration; but a similar performance is consideration if it differs from what was required by the duty in a way which reflects more than a pretense of bargain."
However, there are other things you give up, as noted above. Additionally, in all practical reality, courts are generally loathe to invalidate a license agreement or any other contract for insufficient consideration.
We were quite tight with Apple. We had meetings on campus with senior executives that led to a pilot program with iAd where people could actually play games as an interstitial ad unit. We had employees at Apple who were dedicated to working with us to run this pilot program. Apple ultimately decided to shut down iAd which doomed our collaboration and possible acquisition opportunities.
So this move is really fascinating to me personally. Apple knew how we were doing it and embraced it, probably because we weren't competing against them or undermining the security of their OS.
Apple is depending on privacy and security to be a key differentiator with other phones, tablets and computers. Especially as the markets for all three are slowing as new features are harder to invent.
This company undermines this by allowing anyone to find bugs whilst encouraging them to profit off it instead of working with Apple.
Corellium is heavily used by security researchers, killing it will reduce the number of bugs that are found in iOS and make the platform less secure overall.
Apple wants to project the appearance they have minimal security flaws and they accomplish this largely by making security research more difficult to perform.
I'm also confused why you seem to think security researchers don't deserve to get paid for their work. Bug bounties have been around for a while now for a reason.
Which is why the $1m announcement was an odd move and done people on HN consider it just a PR thing.
This move by Apple seems to contradict the notion that Apple is serious about security - how are researchers supposed to find bugs without this?(a successful lawsuit would also set precedent that no US entity could run a very similar service)
Sure, there's workarounds (eg buy a pile of iPhones), but why is Apple making it harder to secure their product?
Out of the big tech companies, Apple seems to be the most likely to ruin my business model by cutting me off.
Edit, is there something incorrect here? It's historically true and relevant to op.
Why doesn't Apple simply outbid whomever is outbidding them? Why is Apple entitled to security research at anything less than the current market rate?
This is not only about Apple. This is also about their customers. You are essentially advocating that people should sell exploits in the black market, legal disclosure be damned.
Obviously the DeCSS people lost that argument.
Banning someone from saying “by doing X you can bypass security feature Y” is going to be a difficult one to get past the Supreme Court, at least in the USA.
Part of their legal argument is that the tool doesn't have valid uses.
Apple lawyers are expensive and know what they are doing. They think that bringing this up will increase their chances of winning the lawsuit.
Therefore it's perfectly valid to point out that their argument is BS.
The tool has many valid uses. You’re not going to hear about them from Apple, though.
Selling vulnerabilities on an open market should be outlawed. Either disclose them publicly for free, or participate in a bounty program by the software owner. People selling undisclosed vulnerabilities should be considered accomplice of people who then use it to break into systems.
As such it's unlikely that such restrictions would survive a constitutional challenge.
However, running a platform for the explicit goal of breaking security? Are you copying copyrighted code to achieve this goal? You're on shaky ground there.
Yes, it is. The restrictions to the first amendment are very tight and very narrow.
> You don't have freedom of speech for the purposes of harming others.
So, that's complicated. You can't incite violence, but you're more than allowed to disparage groups of people.
I doubt someone is going waste millions dollar vulns to get access to my lame personal life.
You realise that banning “vulnerabilities” being sold is functionally very similar if not identical to outlawing certain kinds of free speech, right?
Disclosing one, yes. Selling it secretly do that it can result in exploits, certainly not. Responsible disclosure is a thing. I doubt that people selling credit card numbers and fake identities are protected by free speech.
I’m British and I’m fairly sure disclosing a security bug is permitted in the UK.
Also, the court case in question was filed in the USA, so it’s reasonable to assume the law in question would be USA law, not, say, the law in Greece.
> it’s reasonable to assume the law in question would be USA law, not, say, the law in Greece.
Yep. And it is totally legitimate to have little sympathy for the case, or to criticize the law that allows this kind of things.
Journalists and newspaper editors also do not work for free. More importantly, speech in a newspaper is still protected, even if a copy of the newspaper costs money.
What is the functional difference between selling a copy of a newspaper costing a lot of money per issue detailing the exploit and selling the exploit some other way?
Moreso selling "information that you would rather not be public but is not considered a secret legally" is completely legal in the US. There are lots of books published and sold containing information that some company or person would rather keep secret.
>Responsible disclosure is a thing.
Not a legal requirement. More of a gentleman's agreement after companies sent the law after security researchers so researchers sold or released anonymous zero days.
I think there's this weird schism at times where people perform all sorts of convoluted hoop-jumping to decide whether hacking is bad or good depending on their perspective, the target, and a host of other variables that really do not much more than inject subjectivity into debates.
Witness the Apple fans who will have a certain glee at another vendors vulnerabilities and then bemoan attempts to find vulnerabilities in the Apple ecosystem. And, to be quite clear, "Apple" can be replaced with many major ecosystems.
Just the other week people were bemoaning Google's Project Zero for calling out vulnerabilities in iOS. "Not fair, I bet they don't do that for Android, Chrome, they're doing it for market advantage!" - except that Project Zero absolutely _does_ feature Android and Chrome vulnerabilities.
The convolution is in somehow shoehorning the notion of selling a secret into the notion of free speech.
> Google's Project Zero
Do you understand that the projects that aim at improving security are fundamentally different than the ones aiming at exploiting flaws?
Does it stand to reason that attempting with purpose to discover exploitable flaws in and of itself makes you a bad actor? ( we've sentenced minors, academics and "white hats" using this argument )
What if someone wrote software that had a legitimate use, but made use of an undisclosed flaw that is then sold to many consumers and reverse engineered, revealing the flaw to larger constituents? What if bad actors merely used a tool out of its original context to exploit a side effect? Does this constitute intent? ( this was tried and the individual in question was jailed )
If an open source project collects money from a bad actor unknowingly and then discloses through a PR or official release the existence of a flaw previously unknown, should they be culpable? ( waiting to see this one play out, hasn't yet, but I have no doubt it will. Was kind of expecting it as a result event-stream.js )
This all just speaks to the concept of subjectivity vs objectivity in the litigation of this concept. The point where it is subjective, rather than objective is the point where it becomes an ethical discussion, and is therefor subject to the principle of fallibility and the human uncertainty principle. tl;dr, if you can't strip motive, investment and bias from the argument, it can't be objective by definition.
"Does it stand to reason that attempting with purpose to discover exploitable flaws in and of itself makes you a bad actor?"
No. I think a lot of past litigation of such case were really misguided.
"What if someone wrote software that had a legitimate use, but made use of an undisclosed flaw that is then sold to many consumers and reverse engineered, revealing the flaw to larger constituents?"
Illegitimate unless the flaw was previously disclosed in a responsible way to the constructor (which basically means give them time to solve the issue).
"What if bad actors merely used a tool out of its original context to exploit a side effect?"
If the tool had an exploit built-in, the author's responsibility is engaged, not otherwise.
"If an open source project collects money from a bad actor unknowingly and then discloses through a PR or official release the existence of a flaw previously unknown, should they be culpable?"
Of course not, but we live in a stupid enough universe for such a thing to be liable.
It’s quite hard to outbid the black market.
Some documents here.
It's the same idea as a 'Hackintosh' but with iOS/ARM instead of macOS/Intel.
That said, who gets to be a bonafide sec researcher? Love to see how apple can define that.
The fact that they encourage vulns to be sold to an open market is likely a problem. They might have to shut that down and move to a wink wink mode.
Very interesting case indeed.
https://www.bloomberg.com/news/articles/2019-08-08/apple-to-...
This is different. In the US, bugs are actually "legal" to buy and sell and protected by the 1st. However, how you USE those bugs is a different matter.
What is happening here? Corellium has copied iOS code, is running it on non-Apple hardware by virtualization, and justifies what would typically be a majorly illegal process (i.e. what if HTC made a phone running iOS?) by claiming "security researchers."
Are they able to fully emulate an iPhone?
It's hard to be sympathetic when Apple's business model is built around preventing users from using the software they pay for in ways Apple does not approve of—sometimes you can frame this around profit, but the problems hardly stop there (e.g. they exercise political control of their platform, too). If this isn't a legitimate market, I don't see any good that comes from making this market illegal.
That said Corellium doesn't seem to be aimed at anything good, either, so this should be fun to watch.
IMO, it should be illegal for companies to sell computer hardware and then block users from sideloading.