For example, as a security researcher, I could order a copy of iOS 11.1 running on an iPhone 6 32GB. It would be spun up and accessible in about 3 or 4 minutes, and I could run direct commands on the Darwin kernel underneath.
Why is this illegal? Correlium DOES NOT have a physical iPhone 6 that it is screen recording. They actually have made copies of various iOS releases, and are running them on virtualization software, while making big bucks from the researchers for this technology.
Will Apple win? Well, if you look at the Apple vs Psystar case of 2007 (in which Apple won pretty much every case and appeal and every injunction they filed for), the odds of victory from Correlium is about as likely as Bill DeBlasio winning the 2020 Election.
It most definitely is not unethical. Illegal perhaps, but unethical? Please.
If they are trying to make money off selling to people doing something other than security research (say, playing games and using apps), than yeah, that'd be unethical.
Like, I could see fair use for an individual security researcher, but a business making profit circumventing Apple's ToS and security in multiple ways, and encouraging others to do the same? I find it unlikely to pass.
I would argue it IS unethical. When speaking of ethics, the intention matters.
If they were just offering these tools to security researchers at cost or for free, then I could agree, but they aren't. They're intentionally doing something that wasn't allowed to make money.
This is _quite_ unethical.
But I grew up during the FOSS craze.
No. Nothing in copyright law allows this. However, everything in contract law allows this.
Copyright law forms the underlying background situation only. Under 17 U.S.C. § 106, the default is that only the copyright owner may make copies (including, e.g., the copy made when installing the software or the copy made into memory when running it).
However, those exclusive rights may be licensed to others. (Under 17 U.S.C. § 117, a software licensee, or the lawful owner of a copy of the software, may always copy the software to install/run or to make an archival copy.)
Licenses are governed by contract law. Contract law typically consists of an offer, acceptance, and some thing of value traded by each side. Restatement (Second) of Contracts, § 17(1).
The thing exchanged can be a promise, a forbearance (i.e., a license), a conditional promise, or any number of things. Restatement (Second) of Contracts, §§ 71-81.
In this case, the license to copy the software to your internal storage and from there into RAM is offered conditionally. In return, you promise not to run it on non-Apple systems. If you break your promise, the conditions of Apple's license to you are triggered and your license terminates. All of that is governed by contract law.
The backstop to that, though - the legal stick - is that now you're using an unlicensed copy and continuously copying it into RAM to use it. That is what opens you up to copyright violation liability.
We were quite tight with Apple. We had meetings on campus with senior executives that led to a pilot program with iAd where people could actually play games as an interstitial ad unit. We had employees at Apple who were dedicated to working with us to run this pilot program. Apple ultimately decided to shut down iAd which doomed our collaboration and possible acquisition opportunities.
So this move is really fascinating to me personally. Apple knew how we were doing it and embraced it, probably because we weren't competing against them or undermining the security of their OS.
Out of the big tech companies, Apple seems to be the most likely to ruin my business model by cutting me off.
Edit, is there something incorrect here? It's historically true and relevant to op.
Apple is depending on privacy and security to be a key differentiator with other phones, tablets and computers. Especially as the markets for all three are slowing as new features are harder to invent.
This company undermines this by allowing anyone to find bugs whilst encouraging them to profit off it instead of working with Apple.
Why doesn't Apple simply outbid whomever is outbidding them? Why is Apple entitled to security research at anything less than the current market rate?
It’s quite hard to outbid the black market.
Selling vulnerabilities on an open market should be outlawed. Either disclose them publicly for free, or participate in a bounty program by the software owner. People selling undisclosed vulnerabilities should be considered accomplice of people who then use it to break into systems.
This is not only about Apple. This is also about their customers. You are essentially advocating that people should sell exploits in the black market, legal disclosure be damned.
Some documents here.
It's the same idea as a 'Hackintosh' but with iOS/ARM instead of macOS/Intel.
That said, who gets to be a bonafide sec researcher? Love to see how apple can define that.
The fact that they encourage vulns to be sold to an open market is likely a problem. They might have to shut that down and move to a wink wink mode.
Very interesting case indeed.
https://www.bloomberg.com/news/articles/2019-08-08/apple-to-...
This is different. In the US, bugs are actually "legal" to buy and sell and protected by the 1st. However, how you USE those bugs is a different matter.
What is happening here? Corellium has copied iOS code, is running it on non-Apple hardware by virtualization, and justifies what would typically be a majorly illegal process (i.e. what if HTC made a phone running iOS?) by claiming "security researchers."
Are they able to fully emulate an iPhone?
It's hard to be sympathetic when Apple's business model is built around preventing users from using the software they pay for in ways Apple does not approve of—sometimes you can frame this around profit, but the problems hardly stop there (e.g. they exercise political control of their platform, too). If this isn't a legitimate market, I don't see any good that comes from making this market illegal.
That said Corellium doesn't seem to be aimed at anything good, either, so this should be fun to watch.
IMO, it should be illegal for companies to sell computer hardware and then block users from sideloading.