Apple is suing iOS virtualization vendor Corellium for violating DMCA
ifixit.com
ifixit.com
As much as I believe in the open and free exchange of ideas I can’t actually agree with iFixit here.
The excuse of it being sold as a ‘security product’ contradicts the only statement on their website - that its a tool for development.
John Deere locking farmers out of repairing their own hardware? Awful, shitty behaviour.
But this is literally stealing Apple’s OS, shoving it in an emulator and charging people for it.
This article also makes the fallacious argument that Apple ‘gives away’ iOS with the purchase of an iPhone or iPad. That’s silly - the cost of the OS is built into the purchase price.
The R&D and development time and money that goes into iOS or MacOS is part of what we are paying for when we purchase a device from Apple.
When we purchase a computer from Dell with Windows 10, the cost of the OS is bundled with the purchase - but Microsoft still gets paid from that - unless, of course we might order the specific subset of Dell computers with Linux on them.
I expect better from iFixit. This article reads like a sob story from the CEO of the company. You stole their software. What did you expect?
How is this any different from a company that would sell you a preconfigured hackintosh? Or selling a DVD player with an unlicensed movie on it? :/
We can bitch about iOS and MacOS being closed platforms all we want - but for myself and many others the hardware/software package-as-a-unit is actually a huge part of the point.
If Corellium is distributing the IPSWs that can run on their emulator, then sure, that would be out of bounds (presumably Apple has not licensed other entities to distribute iOS)[0]. But if the user provides the IPSW to run, this is analogous to a version of VirtualBox that can boot iOS. It's absurd to think that should be illegal.
If this suit doesn't go well for Corellium, I really hope they open-source their tech. Good luck to Apple trying to ban that from existence.
[0] Regardless, this is not what Apple appears to be suing them about.
This is a downright lie.
>The Corellium Apple Product makes modifications to iOS that allows it to be installed on, and run from, Corellium-developed or Corellium-operated hardware. Such modifications include disabling loadable firmware validation, disabling self-verification of the FIPS module, adding Corellium software to the “trust cache,” and instructing the restore tool not to contact Apple servers for kernel / device tree / firmware signing.
-
> But if the user provides the IPSW to run
Ok, but that's not how Corellium works as is evident from the links in TFA https://i.imgur.com/RXe2aE2.png
And Corellium might not ask the user for the software but they still are downloading it from Apple servers, so I don't see how that makes a difference (but if it does, Corellium can very well apply the upload-your-own-ipsw idea)
As your subsequent comment points out, jailbreaks are specifically exempt.
Corellium performs modifications to crack iOS's licensing, which is clearly distinct from jailbreaking. It's the nature of the modifications they're distributing that's the problem.
> which is clearly distinct from jailbreaking
It really isn't. The modifications Corellium does are the same modifications a jailbreak would do and done for the exact same purposes. A jailbroken device can be used for security research purposes and so can Corellium, unsigned apps or tweaks can be installed on a jailbroken device and so they can on Corellium.
Important to note however, that is a DMCA exemption, not an "EULA exemption" (used quotes because that term probably doesn't exist), the exemption ignores the DMCA law, not the EULA, which proves that the EULA isn't really legally enforceable, it's more of a threat from Apple "if you do that we won't give you support/service".
https://superuser.com/questions/30940/is-an-eula-enforceable
The enforceability of an EULA depends on several factors, one of them being the court in which the case is heard. Some courts that have addressed the validity of the shrinkwrap license agreements have found some EULAs to be invalid, characterizing them as contracts of adhesion, unconscionable, and/or unacceptable pursuant to the U.C.C.—see, for instance, Step-Saver Data Systems, Inc. v. Wyse Technology,[6] Vault Corp. v. Quaid Software Ltd..[7] Other courts have determined that the shrinkwrap license agreement is valid and enforceable: see ProCD, Inc. v. Zeidenberg,[8] Microsoft v. Harmony Computers,[9] Novell v. Network Trade Center,[10] and Ariz. Cartridge Remanufacturers Ass'n v. Lexmark Int'l, Inc.[11] may have some bearing as well. No court has ruled on the validity of EULAs generally; decisions are limited to particular provisions and terms. (Wikipedia)
This is clearly a sorely needed product, Apple even agrees because they tried to BUY the company and when they said no they want to take their ball and go home.
If one could either choose between supporting all laws or opposing all laws with nothing in between, the history of civil disobedience would be different indeed!
I don't see that as apple agreeing the product is needed necessarily. Mostly based on their tendency to keep an iron grip on the ecosystem.
Apple's behavior would suggest more that they tried to buy the company first because it would hopefully be both safer from a PR standpoint and also cheaper/safer from an outcome standpoint than a protracted legal battle (depending on the specifics, it's possible EFF will have a horse in this game).
I think you're being assuming here.
Or email hn@ycombinator.com like the guidelines tell you to.
#!/usr/bin/env python3
import nltk
import nltk.sentiment.vader
import json
import urllib.request
companies = [
"apple",
"google",
"microsoft",
"amazon",
"facebook",
]
sample_size = 10
def get_json(url):
request = urllib.request.Request(url)
request.add_header("User-Agent", "Python")
return json.load(urllib.request.urlopen(request))
def allcomments(json):
comment = json["text"]
comments = comment if comment else ""
for child in json["children"]:
comments += allcomments(child)
return comments
if __name__ == "__main__":
for company in companies:
sentiments = []
print(company)
for item in get_json("https://hn.algolia.com/api/v1/search?query=" + company + "&tags=story")["hits"][:sample_size]:
tokens = nltk.tokenize.sent_tokenize(allcomments(get_json("https://hn.algolia.com/api/v1/items/" + item["objectID"])))
sia = nltk.sentiment.vader.SentimentIntensityAnalyzer()
scores = sum([sia.polarity_scores(token)["compound"] for token in tokens])
sentiment = scores / len(tokens)
print("\t" + item["title"] + ": " + str(sentiment))
sentiments.append(sentiment)
print("Average: " + str(sum(sentiments) / len(sentiments)))
Apple gets low scores because of China, mainly. Plus they lack the many open source projects that buoy up companies like Microsoft.I think this was gonna be a case of buy and shut down. there's nothing stopping Apple from releasing something like this themselves and undercutting Corellium. instead they're doing the opposite and have removed emulation from XCode.
Clearly someone at Apple has decided an emulated iOS is too much of a threat.
what?
I can understand advocacy, but as lostgame says, Corellium is basically riding Apple's coattails.
If they were helping Apple, then I doubt Apple would be suing them.
I understand the way that Apple thinks on this. It isn't "bullying." It's brand protection. I worked for years for a corporation with a legendary brand, and they went to great lengths to protect the integrity of that brand.
Part of protecting the integrity is to prevent others from diluting it; even if what they do is net positive, monetarily, it may damage the brand. A company that values its brand can't let that happen.
Branding is a very different world from what most tecchies do. The priorities are drastically different, and a lot harder to "pin down."
A well-curated brand can be unbelievably valuable, though. Apple's brand is one of the top five brands in the world.
I think it's pretty telling that Apple tried to acquire them, but only decided to sue them after their offer was rejected. Seems like Apple really does like their product, and thinks people would find it useful, and is just sore they can't have full control over it.
There are a number of security researchers who use Corellium to find bugs in iOS. Corellium themselves have submitted vulnerabilities using Apple’s bug bounty program.
Same reason I don’t fault Apple for suing companies who make products to run iOS / MacOS on non-Apple hardware.
I'll bet this isn't just about IP. I strongly suspect that it's about the brand.
It's up to Apple to decide if they want to make a virtualized iOS available for security researchers on the web.
Edit people in the rest of the thread are saying that a modified iOS is provided by them
So whether or not they're unlawfully redistributing iOS is irrelevant to the case. The DMCA crap is the interesting bit. And if Apple decides to sue for simple copyright infringement, Corellium could turn their product into bring-your-own-IPSW, with instructions/patches/whatever to modify the image so it'll run on their emulator.
As for the copyright thing, yes, they could ask the user to upload the ipsw (but still i don't see the difference between user doing it and them doing it, it'll end up in the same place), but there would be no need for modification instructions. Modifications are done dynamically, they're not pre-applied into a custom ipsw.
That’s pretty hairy stuff. Technically cool, but definitely sketchy.
Not quite. The optional "modifications" are pretty much the small byte patches in the kernel and bootloader which are normally done in a jailbreak. It is similar to how "Parallels Tools" is automatically loaded; Not entirely required, but makes the experience better.
Perhaps they’re wrong, but I doubt that they’d lie.
A company or person doesn't have to be helping some other corporation increase profits to be morally or legally in the clear. iFixit also isn't helping Apple, that doesn't mean 3rd party repairs should be illegal. In fact, whether they're hurting or helping Apple should be entirely immaterial.
They're helping their security but damaging their reputation. (Corellium makes finding bugs and developing jailbreaks easier. People exposing bugs will make other clueless people think iOS's security is bad, therefore damaging Apple's reputation). Apple chose to keep their reputation because who cares about security when everyone thinks security is good?
The difference is that Corellium is very explicitly doing this to promote interoperability. Adversarial interoperability is a good thing for the market, and copyright laws generally recognize this. If DMCA 1201 does not, that's a problem with the law - not with what this firm did.
If it was an FOSS project, instead of being sold to intelligence agencies, I would call them gods instead of thieves and agree with what you’re saying.
Additionally, possibly counterfeiting if they are sold as the real thing.
If you'd have stolen the copies, it would be theft and copyright infringement.
I don't understand why we still have this discussion...
Corellium likely adds value to Apple because they help to harden the ecosystem, something Apple clearly can't do 100%. Rather than open sourcing their OS, this really is a next best option security-wise. Therefore, Corellium's niche expands the Apple brand.
Really just sounds like they're getting knocked for dealing with intelligence agencies.
See the image in this tweet (can’t direct link from mobile) https://twitter.com/josephfcox/status/1189218066028216324
I don’t think you can reasonably make this argument.
Does anyone know more about exactly how Corellium works in this regard? To me, it makes all the difference.
Where does the IPSW come from? Do they pull a new copy off of Apple's servers each time a customer spins up an instance? Does the customer download the IPSW and upload it to their account?
Speaking more broadly, I feel Corellium would have a much stronger case if their product was running on end-user machines. As long as it's running on Corellium's servers, they're "retransmitting" Apple's software, for lack of a better word.
According to their docs, they do provide the IPSW.
Didn’t work for Psystar and it won’t work for them.
Especially if Apple doesn’t provide any way to do it legally, then they can have a chance at trying to convince a jury. I agree hosting and reselling the service is pushing the question a bit far, but it may be deemed legit depending on the jury. IANAL, obviously, just asking the question.
Psystar sold computers with macOS installed, that's redistribution and a copyright violation. Corellium isn't selling devices with iOS.
What about the screenshots linked in the article?
You can't find the IPSW download links on Apples websites, they're all sourced by reverse engineering.
My point is that Apple doesn't redirect you to an EULA page when using those links. Apple can block all direct links and force you to go through an EULA, but they don't. And how you get the links is irrelevant. So is the fact that a user isn't supposed to have them.
>You can use ipsw.me, which does not pirate anything since it only gives you official links, it doesn't rehost anything on their own servers
I'm not saying that ipsw.me pirates anything, but that you may be pirating by using ipsw.me
> Apple can block all direct links and force you to go through an EULA, but they don't
But they do require you to go through an EULA. You're using a weird technological argument that firmly places you into weev-CFAA-violation territory.
I'm not saying this is how things should be, but this is how things almost certainly are in the eyes of the law.
> So is the fact that a user isn't supposed to have them
Yeah, so how is this not unauthorized access to a protected computer? A crime under the CFAA, as previously demonstrated in United States v. Auernheimer
Unauthorized access to a computer implies bypassing authorization mechanisms to get content that you couldn't get otherwise. If a server is publicly accessible, you don't need authorization to access it. The law doesn't account for how someone can access something (i.e. using iTunes or by reverse engineering and finding the links), it only accounts for who is authorized to access, and a server by being public is automatically authorizing everyone to access its contents. Note however that an EULA can account for how you access content (i.e. "you must use iTunes"), but that is the matter we're discussing right now: whether an EULA is enforceable and whether you can get around it.
Well, each EULA only applies to the tool you click accept on right? If you click accept inside iTunes, it only applies to iTunes on that computer. If you click accept on your device, it only applies to that specific device.
> but that you may be pirating by using ipsw.me
Same thing. You're not pirating if you're downloading something from the official sources.
> But they do require you to go through an EULA
Apple can't just force one to accept the EULA. If downloading an ipsw requires an EULA and I don't agree with it, it's not my fault if Apple still allows me to get the ipsw.
If I'm not supposed to download AT&T customer information, it's not my fault if AT&T still allows me to get the information? There have already been criminal convictions over this exact issue in the past.
> If a server is publicly accessible, you don't need authorization to access it.
This theory did not hold up in the Auernheimer case.
E: Sorry HN won't let me answer below, "posting too fast"
>It's not your fault if you get access to the information, but it is your fault if you intentionally use that information for malicious purposes. Consider an analogy: you find someone's wallet in the streets. That doesn't make you a criminal. However if you decide to use that money and not turn it in, then you have broken a law. The same thing here. Accessing content that was made accessible by mistake doesn't make you a criminal, using that information further on does.
This is not the theory Auernheimer was convicted under, you should read up on that case. He was separately convicted of both accessing and using that information, had he not used the information he'd still have been convicted for the access if caught.
It's not your fault if you get access to the information, but it is your fault if you intentionally use that information for malicious purposes. Consider an analogy: you find someone's wallet in the streets. That doesn't make you a criminal. However if you decide to use that money and not turn it in, then you have broken a law. The same thing here. Accessing content that was made accessible by mistake doesn't make you a criminal, using that information further on does.
> Corellium submitted 8 vulnerabilities under Apple’s bug bounty program, many of them were fixed in iOS releases. But Apple never paid out.
It’s hard to see how Apple can spin:
Apple: “we will pay you bug bounty money to fund your company.”
Corellium: loadsa bugs
Apple: Thanks for the bugs, about that bounty? lol j/k
p.s. now we’re suing you, and we want all your bugs.If the user provides the IPSW files, I don't see what's the problem.
If I were Corellium I would open-source the product and see about licensing to corporate customers. What will Apple do then? Send a DMCA to GitHub?
I think GP is referring to the fact that Apple's EULA forbids running macOS on non-Apple hardware. But whether that's legally enforceable (if you're doing it on a personal machine rather than selling it) is not at all clear to me.
That's a long shot. When I buy an iphone, I get a license to use the OS the iphone comes with. If the license is for one device, I can't use it on many devices simultaneously, that much is clear.
However, for what Corellium is doing to be debatable, the license must say that one can only use the OS copy bundled with the device on the device itself, which sounds against "fair-use", and maybe even "anti-trust" worthy.
> How is this any different from a company that would sell you a preconfigured hackintosh?
Selling a pre-configured hackintosh isn't illegal on any jurisdiction as long as you have a valid license for the OS that you ship, in the same way that selling any laptop on ebay isn't illegal either, as long as the copy of the OS is legal.
If Corellium has one iPhone with iOS for every VM that's running at all times in a warehouse somewhere, then what they are doing is against Apple's EULA, which at most means that Apple doesn't need to give them support, but definitely not illegal.
Also, the real sad thing is that Apple is not providing this service themselves, and instead have killed emulation on XCode.
This theory was tested a decade ago by a company named Psystar and didn’t work.
Is this new? I swear I was emulating and iPhone SE a couple of months ago for a react-native project. Or are you referring to something else? Something i’m missing here?
https://updates.cdn-apple.com/2019FallFCS/fullrestores/061-0...
Microsoft does the same with Windows. Can I rent out VMs running cracked copies of Windows now?
I am pretty sure Microsoft doesn't do the same thing with Windows; they allow you to download, for example, an ISO file for Windows 10, but only if you go through their website portal that explains you must accept their "Microsoft Terms of Use" which then generates a personalized URL for your specific usage that expires in 24 hours, etc. Apple just lets anyone download the IPSW file for their firmware, no questions asked.
> Can I rent out VMs running cracked copies of Windows now?
You absolutely can provide a VM service that emulates an Intel computer, and if a user downloads Windows for free and is allowed to run it on that computer and they decide to violate the EULA, I'm pretty sure that's on them? If I provide software that helps you download and install iOS on any ARM device, and also happen to rent access to ARM devices, is that somehow more illegal than doing either of those two things separately?
> It only works on iOS compatible hardware
Put another way, Apple does not have a monopoly on creating iOS-compatible hardware. A third party would have a decent amount of trouble reverse-engineering their hardware to build a workalike, but, absent a license agreement or some sort of access control, they cannot legally prevent me from running an unmodified iOS image on a piece of hardware or software of my choosing.
(Corellium appears to be using modified iOS images, so they're almost certainly in the wrong here with regard to this point, of course.)
- Corellium is the result of years of research, throwing it away for free would be stupid - If Corellium released their tools, Apple would so something to break it, starting a cat and mouse war like they already do with jailbreaking - Not much people can use the thing anyways. It requires arm64 computers. Most of computers use x86(-64)
Corellium could take the mongodb approach, or I don't know, actually work with Apple on Apple's terms, since their financially dependent on their ability to provide re tools for Apple's proprietary software.
Apple actually creates economic value. Corellium are greedy pirates leeching off of sketchy markets for exploits sometimes used by authoritarian regimes to abuse the human rights of minorities and citizens alike.
The only reason Apple wanted to buy Corellium was to shut them down. Apple doesn't need Corellium's technologies, they can do the same things and better.
> actually work with Apple on Apple's terms
Apple's terms are stupid. "Give us every vulnerability you and your clients find with the service", and it's not like Apple's paying them back anyway. Corellium already submitted many bugs to Apple and Apple didn't keep their promise of paying the bounty but instead decided to sue them.
Why does Apple have to like it? Corellium saw a critical need and did the work to fill it.
Does security research not have economic value? Should no one do that research?
Actually they go a bit beyond that. From the apple filing:
>The Corellium Apple Product makes modifications to iOS that allows it to be installed on, and run from, Corellium-developed or Corellium-operated hardware. Such modifications include disabling loadable firmware validation, disabling self-verification of the FIPS module, adding Corellium software to the “trust cache,” and instructing the restore tool not to contact Apple servers for kernel / device tree / firmware signing.
This doesn't seem too different from a cloud hosting provider selling VMs running cracked copies of Windows.
They'd still be running afoul of the licensing terms and DMCA, but it would feel less egregiously like "stealing".
Alright, so I’m not going crazy, then. I added an edit to my first post making the comparison to a company selling preconfigured hackintoshes. It’s literal theft and resale in a different package.
That they had the balls to even do this, especially to the extent you are talking about, is shocking.
No, it's copyright infringement.
Apple has not "lost" a copy of iOS every time someone spins up a Corellium VM.
Hence why Corellium often provides members of the security and jailbreak community with access to their services.
Corellium doesn’t charge a few “nice” researchers, but builds their business around the evil researchers willing to pay $1M/yr for a license. Clearly they’re exactly like McDonalds!
People keep making very confident but incorrect statements regarding prices offered by Corellium because they assume everyone gets quoted the same, see this twitter thread for another example https://twitter.com/therealdaneel/status/1193122030687797248
It's not like Apple can't virtualize iOS.
Beyond that, I feel like this article could've done a much better job representing Apples claims. The author attempts to paint Corellium as the good guys while completely ignoring that they primarily sell to the likes of Azimuth.
Maybe DMCA is bad and Apple is evil, but that doesn't make Corellium the good guys.
Not only is this my favourite point in all the comments I’ve read - but I feel like this one sentence says, in one sentence - what it took me like a page and a half to convey. :P
That said, I don't have a huge problem with Apple's 'they copied our bits' complaint. That's true.
The problem is that Apple is weaponizing 1201 in a way that would be very damaging if applied in other contexts.
Proving actual damages is a part of any copyright infringement case.