Apple is suing smartphone emulation software startup Corellium
technologyreview.com
technologyreview.com
"Researchers can audit our CSAM process...except for you, who we just handed a pile of money over to and are still on our shit list."
1) Sue the company out of existence 2) Buy the company 3) Settle
They chose option #3, which from what I've seen is solely related to DMCA claims. With this in mind, why should Corellium be allowed to continue this work having just gotten out of the proverbial "doghouse"?
Apple's already marked them as a bad actor in this regard and continuing to make noise seems ill-advised.
No matter how they handled it though, the fact remains that they are providing lip service to the public ("security researchers can easily vet our methods") while continuing to fight against the very same researchers who might want to investigate this new scanning technology.
Apple should realize that users just want the privacy they have heard so much about over the years.
https://storage.courtlistener.com/recap/gov.uscourts.flsd.55...
"Part of the two-year case was settled just last week—days after news of the company’s CSAM technology became public."
And
"On Monday, Corellium announced a $15,000 grant for a program it is specifically promoting as a way to look at iPhones under a microscope and hold Apple accountable. On Tuesday, Apple filed an appeal continuing the lawsuit."
https://news.ycombinator.com/newsguidelines.html
(Submitted title was "Apple says researchers can vet its CSAM tools. But sues a startup for it.")
> On Monday, Corellium announced a $15,000 grant for a program it is specifically promoting as a way to look at iPhones under a microscope and hold Apple accountable. On Tuesday, Apple filed an appeal continuing the lawsuit.
> ... “With their left hand, they make jail-breaking difficult and sue companies like Corellium to prevent them from existing. Now with their right hand, they say, ‘Oh, we built this really complicated system and it turns out that some people don’t trust that Apple has done it honestly—but it’s okay because any security researcher can go ahead and prove it to themselves.’”
> “Security researchers are constantly able to introspect what's happening in Apple’s [phone] software,” Apple vice president Craig Federighi said in an interview with the Wall Street Journal. “So if any changes were made that were to expand the scope of this in some way—in a way that we had committed to not doing—there’s verifiability, they can spot that that's happening.”
Apple uses complex cryptography to shield themselves and their list providers from accountability. You cannot determine if they've included non-child-abuse images in the database through inspection.
Why are we defending this move by Apple?
Richard Stallman was right about everything. In twenty years, people will be standing up for Apple as they upload your health data to your employer and insurance provider.
"It won't matter if you eat right and exercise," is a quote I expect to hear.
Apple uses the technical protections on the phone to make it very difficult to actually even be in a position to do security research without also being NDA'd. There is no owner override like there is on, say, M1 Macs. Apple's position is that nobody but them loads OS code onto your iPhone. Not even you - and you can't practically do any research or auditing on things like the CSAM scanner without having the ability to poke around in the OS.
If Apple had an owner override on iOS-fused devices, then we could load our own kernels, call into the neuralhash framework, and so on to actually validate that the system does what it says. But that would also mean that Epic could sell Fortnite skins outside of the App Store, and we can't have that. So instead we need to gag and muzzle security researchers... which also makes them no longer independent auditors of the iOS security model.
How droll.
Don't claim in one breath that an iPhone can't be looked at by security researches, and in the next say "well, not the ones I want"
I understand if their security research policy doesn't go far enough, but let's not pretend there is nothing.
When Apple will start analyzing pictures on iphones and not in the cloud, then your substitution will become correct.
And presumably the hash match database downloaded to the device is encrypted and unable to be examined.
Pedos are extremely tech-savvy, they need to be to survive. Starting now, none of them is gonna use Apple products and that's it.
My guess is they'll catch as many pedos as terrorists that were caught by the TSA.
https://www.nytimes.com/interactive/2019/09/28/us/child-sex-...
This is not at all borne out in reality. When the FBI rounded up a big ring of CSAM creators/consumers a few years back it came out that they (the people sharing) had rules for how to interact with the community that would have fully protected them, but many of them were sloppy. Same thing with the amount of CSAM that FB reports.
Only, simultaneously, Apple hates the idea that people ever should get access to the software that runs on their phones and reverse engineer it: they tend to downplay results that are found in a way that often involves going to war with the security research community, they sued Corellium--which provides tooling to security researchers--and insisted that their clients were doing things that were inherently illegal, and they are so stingy with giving general access to their devices that not only can you not opt out of their lockdown they won't sell you special bright yellow open devices either... after many years of pleading with them, they finally decided to allow some researchers access, but it requires not only being invited but then signing off on gag clauses that are generally considered to violate the ethical responsibility of practitioners.
It thereby feels like Apple is talking out of both sides of their mouth... though, of course, that's nothing new for them :/. On the one hand, they want to claim that security researchers are important to their overall security strategy; but, on the other, they simultaneously abuse and prosecute people who dare to either directly pull apart their systems or have the audacity to provide the tools required for others to do so.
And, for anyone who is stuck in the mental frame "BuT I tHoUgHt ApPlE lOvEs SeCuRiTy ReSeArChErS", barely over a year ago (wow time flies when you are living alone and physically falling apart during a pandemic, huh? ;P), I wrote a thread on Twitter that documented a ton of the issues that we run into with Apple, including using specific examples, and touched on this lawsuit against Corellium. FWIW, I don't personally know of anyone in the security industry that thinks Apple is doing well on this front, and I doubt many exist.
https://twitter.com/saurik/status/1295024384596312064?s=21
Also: here is a thread on Twitter from a few days ago (started by Runa Sandvik, the senior director of information security at the New York Times) about Apple's recent statements, as well as a direct link to a reply sub-thread from Kurt Opsahl--the Deputy Executive Director and General Counsel of the EFF--that quickly got updated re the Corellium appeal.
https://twitter.com/runasand/status/1426232172109869057?s=21
https://twitter.com/kurtopsahl/status/1426314930001567751?s=...
(edit) I am realizing it is probably also worth explaining another key detail here that is probably more than just a bit confusing: one reason this is particular news right now is because, in addition to the big CSAM background story, Apple just announced an appeal of the case they lost to Corellium.
I think it is important to triple underscore that: a lot of people know about how Corellium and Apple recently settled, but that was over other claims that Apple (seemingly) gave up on; Apple can't appeal that AFAIK. However, in December, Apple had most of its (extremely weak...) case dismissed by the judge.
https://www.reuters.com/article/us-apple-corellium-idUSKBN29...
> U.S. District Judge Rodney Smith ruled in favor of Corellium LLC, saying its software emulating the iOS operating system that runs on the iPhone and iPad amounted to “fair use” because it was “transformative” and helped developers find security flaws.
It almost certainly isn't the case that Apple decided to do this appeal because of Corellium's press release, as it almost certainly takes more than less-than-a-day to put that together and file it ;P. It will be interesting to see if Apple manages to put together a more coherent argument in their appeal.
From: https://www.macrumors.com/2021/08/17/apple-appeals-corellium...
> Back in December, Apple lost a copyright lawsuit against security research company Corellium, and today, Apple filed an appeal in that case, reports Reuters.
For fun corporate and university IT types can start adding iCloud-related domains to their internal blacklists.
This distinction is even codified in U.S. law. The government needs a warrant to search your phone, but only needs a subpoena to search a remote server that's storing your files[1].
But yes, I can see why that distinction might feel a little arbitrary at times, particularly in the modern age where cloud storage is so common. Perhaps the 4th amendment should cover third parties storing "papers, and effects" on a person's behalf.
[1]: https://grandjurytarget.com/2020/10/28/by-search-warrant-or-...
Speaking solely for myself, I don't see a meaningful difference between these cases. They're both "content you upload to a server is scanned", with the only difference being that the scan happens immediately before upload rather than sometime after upload.
My opinion would be notably changed if Apple was scanning content you're not uploading, but the current system doesn't seem to allow for that.
> iCloud secures your information by encrypting it when it's in transit, storing it in iCloud in an encrypted format, and using secure tokens for authentication. For certain sensitive information, Apple uses end-to-end encryption. This means that only you can access your information, and only on devices where you’re signed into iCloud. No one else, not even Apple, can access end-to-end encrypted information.
There's a section "End-to-end encrypted data" which explicitly lists the things which are actually e2e, and iCloud Photos isn't on that list.
I regret paying for it.
---
> Serious question: Why do you browse the web without an ad blocker? I can't imagine subjecting myself to that kind of torture.
As best as I know: doing this on mobile (assuming that's their platform) requires both:
* a non-iOS device (Android basically)
* a non-Chromium browser on said device (Firefox basically)
That pairing is the only reason I can adblock on mobile. Not sure if things changed on Chrome or related browsers on Android, but as best as I remember, iOS and Android+Chrome aren't adblock-friendly.
I think Opera might have one too.
[1] <https://davidgerard.co.uk/blockchain/2019/01/13/brave-web-br...>
Mmmm. I can use Adblock in Edge Beta on Android.
To reduce the risk of malware delivered via your browser?
It also blocks things that you don't see (tracking), improves performance and prevents malware infections.
It is pretty amazing to auto-bypass paywalls, and how much faster sites load, that you can see how many external JavaScript sources there are on every site by default.
It’s a little annoying when I realize that X or Y page doesn’t look or work right and need to adjust, then reload, maybe a couple times, but overall worth it! Magic is right.
Always use "legal@oracle.com"
edit: now I recommend privacy@chevron.com
Funnily enough the same NeuralHash has already been generated for completely different images, so good luck explaining why your 4th of July pics cost all of your safety vouchers to Apple/FBI
> In the lawsuit, Apple argued that Corellium violated its copyrights, enabled the sale of software exploits used for hacking, and shouldn’t exist. The startup countered by saying that its use of Apple’s code was a classic protected case of fair use. The judge has largely sided with Corellium so far. Part of the two-year case was settled just last week—days after news of the company’s CSAM technology became public.
> On Monday, Corellium announced a $15,000 grant for a program it is specifically promoting as a way to look at iPhones under a microscope and hold Apple accountable. On Tuesday, Apple filed an appeal continuing the lawsuit.
Apple is now appealing the claims they lost, not the ones they settled (they can't do that: that would undermine the premise of settling anything at all). Legal complaints are not atomic all-or-nothing affairs in this way.
https://www.reuters.com/legal/transactional/apple-files-appe...