back
126 comments
To confused HN commenters: Correlium works by offering VMs of iOS and all models of Apple device, and allowing Terminal access (i.e. pre-jailbroken) access the operating system underneath.

For example, as a security researcher, I could order a copy of iOS 11.1 running on an iPhone 6 32GB. It would be spun up and accessible in about 3 or 4 minutes, and I could run direct commands on the Darwin kernel underneath.

Why is this illegal? Correlium DOES NOT have a physical iPhone 6 that it is screen recording. They actually have made copies of various iOS releases, and are running them on virtualization software, while making big bucks from the researchers for this technology.

Will Apple win? Well, if you look at the Apple vs Psystar case of 2007 (in which Apple won pretty much every case and appeal and every injunction they filed for), the odds of victory from Correlium is about as likely as Bill DeBlasio winning the 2020 Election.

There is a fair use case here. My understanding is that you're allowed to do this sort of thing for purpose of security research.

It most definitely is not unethical. Illegal perhaps, but unethical? Please.

If they are trying to make money off selling to people doing something other than security research (say, playing games and using apps), than yeah, that'd be unethical.

To make copies of iOS (against ToS), run it on non-Apple-branded devices (against ToS), and make profit off it?

Like, I could see fair use for an individual security researcher, but a business making profit circumventing Apple's ToS and security in multiple ways, and encouraging others to do the same? I find it unlikely to pass.

Fair use is relevant here but one of the main tests used by the courts is whether or not the use is commercial - this kind of for-profit redistribution is unlikely to pass muster.
> It most definitely is not unethical. Illegal perhaps, but unethical? Please.

I would argue it IS unethical. When speaking of ethics, the intention matters.

If they were just offering these tools to security researchers at cost or for free, then I could agree, but they aren't. They're intentionally doing something that wasn't allowed to make money.

Fair use doesn't apply when you're acting for profit and making complete copies. That's like arguing that setting up a book production shop and selling fraudulent copies of the book (for borrowing only) is "fair use".

This is _quite_ unethical.

Sorry, meant to write illegal, not unethical.
Under what doctrine / case law?
Corellium isn’t making copies of iOS; it uses restore images from Apple’s servers.
If Correlium just provides the VM and the researchers download iOS releases directly from apple servers, is it still illegal?
What if they bought a phone for every VM they offer? So let's say they offer 5000 VMs, they buy 5000 equivalent phones. Do you think they will still have a chance?
Doing God's work. Every Apple purchase makes me feel like I'm creating a computer vilian.

But I grew up during the FOSS craze.

Does anything in copyright law entitle Apple to impose conditions on the use of software it gives away for free online (e.g., that it may be run only on Apple hardware)? It would seem analogous to me writing a book and offering it free online but licensed only to be read in a comfy chair with a nice cup of tea. Maybe I'm in the furniture business and my livelihood depends on everyone's compliance. I bring this up because I wonder if fanboyism is clouding our collective judgment where we might otherwise greet these so called terms of service with the contempt they so richly deserve.
> Does anything in copyright law entitle Apple to impose conditions on the use of software it gives away for free online (e.g., that it may be run only on Apple hardware)?

No. Nothing in copyright law allows this. However, everything in contract law allows this.

Copyright law forms the underlying background situation only. Under 17 U.S.C. § 106, the default is that only the copyright owner may make copies (including, e.g., the copy made when installing the software or the copy made into memory when running it).

However, those exclusive rights may be licensed to others. (Under 17 U.S.C. § 117, a software licensee, or the lawful owner of a copy of the software, may always copy the software to install/run or to make an archival copy.)

Licenses are governed by contract law. Contract law typically consists of an offer, acceptance, and some thing of value traded by each side. Restatement (Second) of Contracts, § 17(1).

The thing exchanged can be a promise, a forbearance (i.e., a license), a conditional promise, or any number of things. Restatement (Second) of Contracts, §§ 71-81.

In this case, the license to copy the software to your internal storage and from there into RAM is offered conditionally. In return, you promise not to run it on non-Apple systems. If you break your promise, the conditions of Apple's license to you are triggered and your license terminates. All of that is governed by contract law.

The backstop to that, though - the legal stick - is that now you're using an unlicensed copy and continuously copying it into RAM to use it. That is what opens you up to copyright violation liability.

I co-founded a company called App.io which ran from 2012 to 2015. We let people run iOS apps in the browser and we did it by streaming the simulator from virtualised macOS instances. We were running EXSi on Mac Minis colocated in data centres around the world and the system ultimately worked really well (we definitely had scalability issues with such an unconventional setup).

We were quite tight with Apple. We had meetings on campus with senior executives that led to a pilot program with iAd where people could actually play games as an interstitial ad unit. We had employees at Apple who were dedicated to working with us to run this pilot program. Apple ultimately decided to shut down iAd which doomed our collaboration and possible acquisition opportunities.

So this move is really fascinating to me personally. Apple knew how we were doing it and embraced it, probably because we weren't competing against them or undermining the security of their OS.

You were at least using actual Apple Hardware.
Apple model of use makes you something like renter of their hardware/software.
This is why Apple is the last platform I develop for, and I use JavaScript.

Out of the big tech companies, Apple seems to be the most likely to ruin my business model by cutting me off.

Edit, is there something incorrect here? It's historically true and relevant to op.

It's all about the security of the OS.

Apple is depending on privacy and security to be a key differentiator with other phones, tablets and computers. Especially as the markets for all three are slowing as new features are harder to invent.

This company undermines this by allowing anyone to find bugs whilst encouraging them to profit off it instead of working with Apple.

>“Although Corellium paints itself as providing a research tool for those trying to discover security vulnerabilities and other flaws in Apple’s software, Corellium’s true goal is profiting off its blatant infringement,” Apple said in the complaint. “Far from assisting in fixing vulnerabilities, Corellium encourages its users to sell any discovered information on the open market to the highest bidder.”

Why doesn't Apple simply outbid whomever is outbidding them? Why is Apple entitled to security research at anything less than the current market rate?

Security research doesn't really have anything to do with Apple's complaint of copyright infringement.
I highly doubt that is there concern, I think it's to paint them as evil. If the case was on should Corellium emulate Apple's hardware that will be simple, but to tack on that Corellium also indirectly enables the bad guys in this age of constant hacks and privacy invasion is an additional burden that Corellium has to bear.
> Why doesn't Apple simply outbid whomever is outbidding them?

It’s quite hard to outbid the black market.

For the same reason a host is entitled to prior disclosure of its unfixed vulnerabilities.

Selling vulnerabilities on an open market should be outlawed. Either disclose them publicly for free, or participate in a bounty program by the software owner. People selling undisclosed vulnerabilities should be considered accomplice of people who then use it to break into systems.

> Why is Apple entitled to security research at anything less than the current market rate?

This is not only about Apple. This is also about their customers. You are essentially advocating that people should sell exploits in the black market, legal disclosure be damned.

Corellium is an amazing product and I wish they win. They fill a massive gap that Apple is not addressing. Apple is not very good at doing good dev tools (cough xcode monolith cough), so when somebody enters the game and gets dev excited again about their platform, I think they should embrace it and buy them.
Just to clarify, it's not 'emulation' -- they have patched a copy of iOS itself to run on stock ARM devices, virtualizing hardware as needed.

It's the same idea as a 'Hackintosh' but with iOS/ARM instead of macOS/Intel.

Can anyone explain the exact nature of the infringement here? Presumably illegally copying the software from a device to a vm? Is there a logical strategy to counter this claim by Corellium?
It's an LLC so chances are they don't have a plan and were just waiting to get the C&D/Lawsuit.
If that's the case I would have much more sympathy for Apple if there were a legal way of doing this.
Not from a device. The iOS system software can be downloaded from Apple’s update servers.
Interesting case. Corellium should be allowed to sell to bonafide security researchers, Apple even admits it themselves - "“Corellium is not selectively limiting its customers to only those with some socially beneficial purpose.”".

That said, who gets to be a bonafide sec researcher? Love to see how apple can define that.

The fact that they encourage vulns to be sold to an open market is likely a problem. They might have to shut that down and move to a wink wink mode.

Very interesting case indeed.

It may, however, be that Apple thinks that pointing out they aren't selling to only security researchers or other "socially beneficial" people is easier than getting into a fight about fair use, which would also bring bad PR.
Corellium looks amazing. It or something like it may be our best chance for preserving what iOS/app history is still available.
This comes hot on the heels of an announcement from Apple that they are starting up a new program to allow select security researchers access to iPhones with a majority of security features disabled. I wonder if it is somehow related.

https://www.bloomberg.com/news/articles/2019-08-08/apple-to-...

Does anyone know how Corellium works?
It’s a custom bootloader and hardware that loads iOS images that Apple distributes.
How does this compare to Sony vs Bleem? Bleem was a commercial Playstation 1 emulator that Sony sued. Bleem won, but the company shut down due to the cost of the legal fees.
Bleem didn't violate any of Sony's patents or rules. It allowed unauthorized code to run through the use of a bug, but it didn't, you know, come with illegal copies of the games, or copy the PlayStation ROMs. It didn't copy any Sony code. It let users use the console in a way Sony didn't like, but didn't ACTUALLY "harm" Sony in any way.

This is different. In the US, bugs are actually "legal" to buy and sell and protected by the 1st. However, how you USE those bugs is a different matter.

What is happening here? Corellium has copied iOS code, is running it on non-Apple hardware by virtualization, and justifies what would typically be a majorly illegal process (i.e. what if HTC made a phone running iOS?) by claiming "security researchers."

How does this work then?

Are they able to fully emulate an iPhone?

> There is no basis for Corellium to be selling a product that allows the creation of avowedly perfect replicas of Apple’s devices to anyone willing to pay.

It's hard to be sympathetic when Apple's business model is built around preventing users from using the software they pay for in ways Apple does not approve of—sometimes you can frame this around profit, but the problems hardly stop there (e.g. they exercise political control of their platform, too). If this isn't a legitimate market, I don't see any good that comes from making this market illegal.

That said Corellium doesn't seem to be aimed at anything good, either, so this should be fun to watch.

Absolutely. I have zero sympathy for Apple and I hope they lose this and their anti-trust case. At the very least, I hope it costs them billions.

IMO, it should be illegal for companies to sell computer hardware and then block users from sideloading.

Expect a new startup in Russia or similar if Apple crushes them.
I think this is reasonable. Corellium is committing blatant copyright violation for profit. I think this is a pretty open and shut case win for Apple.
How could they change their service to circumvent apple here? E.g. what if they provided the VMs but the user had to manually upload the OS image?
Corellium actually does mobile hackintosh, very cool. I suppose they collected money for lawyers before started the big business.