Why doesn't Apple simply outbid whomever is outbidding them? Why is Apple entitled to security research at anything less than the current market rate?
Why doesn't Apple simply outbid whomever is outbidding them? Why is Apple entitled to security research at anything less than the current market rate?
Part of their legal argument is that the tool doesn't have valid uses.
Apple lawyers are expensive and know what they are doing. They think that bringing this up will increase their chances of winning the lawsuit.
Therefore it's perfectly valid to point out that their argument is BS.
The tool has many valid uses. You’re not going to hear about them from Apple, though.
It’s quite hard to outbid the black market.
Selling vulnerabilities on an open market should be outlawed. Either disclose them publicly for free, or participate in a bounty program by the software owner. People selling undisclosed vulnerabilities should be considered accomplice of people who then use it to break into systems.
As such it's unlikely that such restrictions would survive a constitutional challenge.
However, running a platform for the explicit goal of breaking security? Are you copying copyrighted code to achieve this goal? You're on shaky ground there.
Yes, it is. The restrictions to the first amendment are very tight and very narrow.
> You don't have freedom of speech for the purposes of harming others.
So, that's complicated. You can't incite violence, but you're more than allowed to disparage groups of people.
I doubt someone is going waste millions dollar vulns to get access to my lame personal life.
You realise that banning “vulnerabilities” being sold is functionally very similar if not identical to outlawing certain kinds of free speech, right?
Disclosing one, yes. Selling it secretly do that it can result in exploits, certainly not. Responsible disclosure is a thing. I doubt that people selling credit card numbers and fake identities are protected by free speech.
I’m British and I’m fairly sure disclosing a security bug is permitted in the UK.
Also, the court case in question was filed in the USA, so it’s reasonable to assume the law in question would be USA law, not, say, the law in Greece.
> it’s reasonable to assume the law in question would be USA law, not, say, the law in Greece.
Yep. And it is totally legitimate to have little sympathy for the case, or to criticize the law that allows this kind of things.
Journalists and newspaper editors also do not work for free. More importantly, speech in a newspaper is still protected, even if a copy of the newspaper costs money.
What is the functional difference between selling a copy of a newspaper costing a lot of money per issue detailing the exploit and selling the exploit some other way?
Moreso selling "information that you would rather not be public but is not considered a secret legally" is completely legal in the US. There are lots of books published and sold containing information that some company or person would rather keep secret.
>Responsible disclosure is a thing.
Not a legal requirement. More of a gentleman's agreement after companies sent the law after security researchers so researchers sold or released anonymous zero days.
I think there's this weird schism at times where people perform all sorts of convoluted hoop-jumping to decide whether hacking is bad or good depending on their perspective, the target, and a host of other variables that really do not much more than inject subjectivity into debates.
Witness the Apple fans who will have a certain glee at another vendors vulnerabilities and then bemoan attempts to find vulnerabilities in the Apple ecosystem. And, to be quite clear, "Apple" can be replaced with many major ecosystems.
Just the other week people were bemoaning Google's Project Zero for calling out vulnerabilities in iOS. "Not fair, I bet they don't do that for Android, Chrome, they're doing it for market advantage!" - except that Project Zero absolutely _does_ feature Android and Chrome vulnerabilities.
The convolution is in somehow shoehorning the notion of selling a secret into the notion of free speech.
> Google's Project Zero
Do you understand that the projects that aim at improving security are fundamentally different than the ones aiming at exploiting flaws?
Does it stand to reason that attempting with purpose to discover exploitable flaws in and of itself makes you a bad actor? ( we've sentenced minors, academics and "white hats" using this argument )
What if someone wrote software that had a legitimate use, but made use of an undisclosed flaw that is then sold to many consumers and reverse engineered, revealing the flaw to larger constituents? What if bad actors merely used a tool out of its original context to exploit a side effect? Does this constitute intent? ( this was tried and the individual in question was jailed )
If an open source project collects money from a bad actor unknowingly and then discloses through a PR or official release the existence of a flaw previously unknown, should they be culpable? ( waiting to see this one play out, hasn't yet, but I have no doubt it will. Was kind of expecting it as a result event-stream.js )
This all just speaks to the concept of subjectivity vs objectivity in the litigation of this concept. The point where it is subjective, rather than objective is the point where it becomes an ethical discussion, and is therefor subject to the principle of fallibility and the human uncertainty principle. tl;dr, if you can't strip motive, investment and bias from the argument, it can't be objective by definition.
"Does it stand to reason that attempting with purpose to discover exploitable flaws in and of itself makes you a bad actor?"
No. I think a lot of past litigation of such case were really misguided.
"What if someone wrote software that had a legitimate use, but made use of an undisclosed flaw that is then sold to many consumers and reverse engineered, revealing the flaw to larger constituents?"
Illegitimate unless the flaw was previously disclosed in a responsible way to the constructor (which basically means give them time to solve the issue).
"What if bad actors merely used a tool out of its original context to exploit a side effect?"
If the tool had an exploit built-in, the author's responsibility is engaged, not otherwise.
"If an open source project collects money from a bad actor unknowingly and then discloses through a PR or official release the existence of a flaw previously unknown, should they be culpable?"
Of course not, but we live in a stupid enough universe for such a thing to be liable.
This is not only about Apple. This is also about their customers. You are essentially advocating that people should sell exploits in the black market, legal disclosure be damned.
Obviously the DeCSS people lost that argument.
Banning someone from saying “by doing X you can bypass security feature Y” is going to be a difficult one to get past the Supreme Court, at least in the USA.