Does anyone know more about exactly how Corellium works in this regard? To me, it makes all the difference.
Where does the IPSW come from? Do they pull a new copy off of Apple's servers each time a customer spins up an instance? Does the customer download the IPSW and upload it to their account?
Speaking more broadly, I feel Corellium would have a much stronger case if their product was running on end-user machines. As long as it's running on Corellium's servers, they're "retransmitting" Apple's software, for lack of a better word.
According to their docs, they do provide the IPSW.
Didn’t work for Psystar and it won’t work for them.
Especially if Apple doesn’t provide any way to do it legally, then they can have a chance at trying to convince a jury. I agree hosting and reselling the service is pushing the question a bit far, but it may be deemed legit depending on the jury. IANAL, obviously, just asking the question.
Psystar sold computers with macOS installed, that's redistribution and a copyright violation. Corellium isn't selling devices with iOS.
What about the screenshots linked in the article?
You can't find the IPSW download links on Apples websites, they're all sourced by reverse engineering.
My point is that Apple doesn't redirect you to an EULA page when using those links. Apple can block all direct links and force you to go through an EULA, but they don't. And how you get the links is irrelevant. So is the fact that a user isn't supposed to have them.
>You can use ipsw.me, which does not pirate anything since it only gives you official links, it doesn't rehost anything on their own servers
I'm not saying that ipsw.me pirates anything, but that you may be pirating by using ipsw.me
> Apple can block all direct links and force you to go through an EULA, but they don't
But they do require you to go through an EULA. You're using a weird technological argument that firmly places you into weev-CFAA-violation territory.
I'm not saying this is how things should be, but this is how things almost certainly are in the eyes of the law.
> So is the fact that a user isn't supposed to have them
Yeah, so how is this not unauthorized access to a protected computer? A crime under the CFAA, as previously demonstrated in United States v. Auernheimer
Well, each EULA only applies to the tool you click accept on right? If you click accept inside iTunes, it only applies to iTunes on that computer. If you click accept on your device, it only applies to that specific device.
> but that you may be pirating by using ipsw.me
Same thing. You're not pirating if you're downloading something from the official sources.
> But they do require you to go through an EULA
Apple can't just force one to accept the EULA. If downloading an ipsw requires an EULA and I don't agree with it, it's not my fault if Apple still allows me to get the ipsw.
If I'm not supposed to download AT&T customer information, it's not my fault if AT&T still allows me to get the information? There have already been criminal convictions over this exact issue in the past.
> If a server is publicly accessible, you don't need authorization to access it.
This theory did not hold up in the Auernheimer case.
E: Sorry HN won't let me answer below, "posting too fast"
>It's not your fault if you get access to the information, but it is your fault if you intentionally use that information for malicious purposes. Consider an analogy: you find someone's wallet in the streets. That doesn't make you a criminal. However if you decide to use that money and not turn it in, then you have broken a law. The same thing here. Accessing content that was made accessible by mistake doesn't make you a criminal, using that information further on does.
This is not the theory Auernheimer was convicted under, you should read up on that case. He was separately convicted of both accessing and using that information, had he not used the information he'd still have been convicted for the access if caught.
It's not your fault if you get access to the information, but it is your fault if you intentionally use that information for malicious purposes. Consider an analogy: you find someone's wallet in the streets. That doesn't make you a criminal. However if you decide to use that money and not turn it in, then you have broken a law. The same thing here. Accessing content that was made accessible by mistake doesn't make you a criminal, using that information further on does.
Unauthorized access to a computer implies bypassing authorization mechanisms to get content that you couldn't get otherwise. If a server is publicly accessible, you don't need authorization to access it. The law doesn't account for how someone can access something (i.e. using iTunes or by reverse engineering and finding the links), it only accounts for who is authorized to access, and a server by being public is automatically authorizing everyone to access its contents. Note however that an EULA can account for how you access content (i.e. "you must use iTunes"), but that is the matter we're discussing right now: whether an EULA is enforceable and whether you can get around it.