{"id":27724,"date":"2019-12-30T15:24:20","date_gmt":"2019-12-30T20:24:20","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=27724"},"modified":"2020-02-24T16:14:35","modified_gmt":"2020-02-24T21:14:35","slug":"apples-filing-against-corellium-and-jailbreaking","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2019\/12\/30\/apples-filing-against-corellium-and-jailbreaking\/","title":{"rendered":"Apple&rsquo;s Filing Against Corellium and Jailbreaking"},"content":{"rendered":"<p><a href=\"https:\/\/corellium.com\/statement-dmca\/\">Amanda Gorton<\/a> (<a href=\"https:\/\/www.macrumors.com\/2019\/12\/30\/corellium-apple-jailbreaking-crack-down\/\">MacRumors<\/a>):<\/p>\n<blockquote cite=\"https:\/\/corellium.com\/statement-dmca\/\"><p>Apple&rsquo;s latest filing against Corellium should give all security researchers, app developers, and jailbreakers reason to be concerned. The filing asserts that because Corellium &ldquo;allows users to jailbreak&rdquo; and &ldquo;gave one or more Persons access&#8230; to develop software that can be used to jailbreak,&rdquo; Corellium is &ldquo;engaging in trafficking&rdquo; in violation of the DMCA. In other words, Apple is asserting that anyone who provides a tool that allows other people to jailbreak, and anyone who assists in creating such a tool, is violating the DMCA.<\/p>\n<p>[&#8230;]<\/p>\n<p>Across the industry, developers and researchers rely on jailbreaks to test the security of both their own apps and third-party apps &#x2013; testing which cannot be done<em> <\/em>without a jailbroken device. For example, a recent analysis of the ToTok app revealed that an Apple-approved chat app was being used as a spying tool by the government of the United Arab Emirates, and <a href=\"https:\/\/twitter.com\/patrickwardle\/status\/1210742545451323392\">according to the researchers<\/a> behind this analysis, this work would not have been possible without a jailbreak.<\/p><\/blockquote>\n\n<p>The filing is available <a href=\"https:\/\/gofile.io\/?c=bJs6NY\">here<\/a> (<a href=\"https:\/\/twitter.com\/axi0mX\/status\/1210718075680518144\">tweet<\/a>).<\/p>\n\n<p><a href=\"https:\/\/twitter.com\/chronic\/status\/1210727284648267777\">Will Strafach<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/chronic\/status\/1210727284648267777\">\n<p>in their most recent court filing, Apple has declared an all out war on jailbreaking.<\/p>\n<p>they&rsquo;ve actively decided that they will destroy the livelihoods of those who dare to help folks escape the walled garden.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/jamiebishop123\/status\/1210722988376522754\">Jamie Bishop<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/jamiebishop123\/status\/1210722988376522754\">\n<p>Apple&rsquo;s latest filing in the Corellium case is HORRIFYING.<\/p>\n<p>It effectively will set a precedent which makes unsanctioned research of Apple products <em>ILLEGAL<\/em>.<\/p>\n<p>[&#8230;]<\/p>\n<p>I am SO unbelievably disappointed that Apple has declared war on the security scene.<\/p>\n<p>They lost all those years ago with the DMCA exemption, but now they&rsquo;ve decided to go after the researchers, the people keeping US safe.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/pwnallthethings\/status\/1211725164469276672\">Pwn All The Things<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/pwnallthethings\/status\/1211725164469276672\">\n<p>If Apple won this case, not just Apple, but <em>any<\/em> platform company could sue any security researcher for publishing a tool to help with security research on their platform. The DMCA claim is a really extreme claim.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/migueldeicaza\/status\/1210742038032834563\">Miguel de Icaza<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/migueldeicaza\/status\/1210742038032834563\">\n<p>&ldquo;We are profiting from Apple&rsquo;s IP for security&rdquo; is not any different than &ldquo;we are selling bootlegged DVDs of Star Wars for the sake of the children&rdquo;<\/p>\n<p>Of course, under capitalism rules, the next step is to offer more scenarios beyond security for the product - assorted virtualization workloads are the obvious next step.   Then followed by tools to install iOS on non-Apple hardware.  This is why Apple will fight this.<\/p>\n<\/blockquote>\n\n<p>It seems like Corellium is probably legally in the wrong, at least with respect to the virtualization product. Apple also acted dishonorably towards them and is now trying to use the case to overreach and assert even more control.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2019\/12\/23\/totok-and-tiktok\/\">ToTok and TikTok<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2019\/10\/29\/apple-v-corellium\/\">Apple v. Corellium<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2019\/08\/16\/apple-files-lawsuit-against-corellium-for-ios-virtualization\/\">Apple Files Lawsuit Against Corellium for iOS Virtualization<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2019\/08\/06\/hacker-friendly-iphones-and-mac-bug-bounty-program\/\">Hacker-Friendly iPhones and Mac Bug Bounty Program<\/a><\/li>\n<\/ul>\n\n<p id=\"apples-filing-against-corellium-and-jailbreaking-update-2020-01-03\">Update (2020-01-03): <a href=\"https:\/\/www.ifixit.com\/News\/apple-is-bullying-a-security-company-with-a-dangerous-dmca-lawsuit\">Kyle Wiens<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=21940846\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.ifixit.com\/News\/apple-is-bullying-a-security-company-with-a-dangerous-dmca-lawsuit\"><p>Despite a lack of apparent interest in enforcing their copyright to iOS software, in this specific case Apple has decided to exert control over iOS. And they&rsquo;ve crossed a red line by invoking the most notorious statute in the US copyright act, <a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/17\/1201\">section 1201<\/a>. This is the very law that made it illegal for farmers to <a href=\"https:\/\/www.wired.com\/2015\/02\/new-high-tech-farm-equipment-nightmare-farmers\/\">work on their tractors<\/a> and for you to <a href=\"https:\/\/www.ifixit.com\/News\/copyright-and-the-end-of-ownership\">fix your refrigerator<\/a>. It&rsquo;s the same law that we&rsquo;ve been whacking away at for years, getting <a href=\"https:\/\/www.eff.org\/deeplinks\/2018\/10\/new-exemptions-dmca-section-1201-are-welcome-dont-go-far-enough\">exemptions<\/a> from the US Copyright Office for fixing, jailbreaking, and performing security research on everything from smartwatches to automobiles.<\/p>\n<p>[&#8230;]<\/p>\n<p>In other words: Corellium sells a way to use iOS that works around the way Apple intended it to work. Apple knows that you can&rsquo;t use Corellium&rsquo;s software to create your own knock-off iPhone. But they can claim that Corellium&rsquo;s software is illegal, and they might technically be right.<\/p><\/blockquote>\n\n<p id=\"apples-filing-against-corellium-and-jailbreaking-update-2020-02-14\">Update (2020-02-14): <a href=\"https:\/\/twitter.com\/pwnallthethings\/status\/1213195171787096064\">Pwn All The Things<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/pwnallthethings\/status\/1213195171787096064\"><p>Notice how Apple defines &ldquo;good-faith&rdquo; research here. That for Corellium to be a &ldquo;good-faith&rdquo; org, it would have to <em>require<\/em> its users to turn over any security research directly to Apple. Otherwise it&rsquo;s not &ldquo;good faith&rdquo;.<\/p><p>But, wait, it gets worse. Apple defines &ldquo;good faith&rdquo; as not only turning over all <em>your<\/em> research on their platform and also requiring that <em>your customers<\/em> turn over <em>theirs<\/em>, but they also reserve the right to just not ever pay for it if you do.<\/p><p>That&rsquo;s the point. The lawsuit is about strategic control of the security market on iOS.<\/p><p>&ldquo;Good faith&rdquo; researchers are the ones who go cap in hand and beg Apple for permission to test and give Apple all their research at prices Apple decides (which might be $0, yolo)<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/juanandres_gs\/status\/1211864210755469312\">J. A. Guerrero-Saade<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/juanandres_gs\/status\/1211864210755469312\">\n<p>For iOS, Apple is betting the house on the walled garden \/ code signing \/ dev verification approach. Meaning exploits are that much more important in the attack chain. Once past initial checks, Apple&rsquo;s unwillingness to actively check device integrity means attackers are king.<\/p>\n<p>[&#8230;]<\/p>\n<p>Claiming Corellium enables attackers undermines the fact that most defenders are being barred from researching this space while attackers have been doing just fine. Need is huge. Research enablers must be embraced and emboldened precisely to entice defenders to look.<\/p>\n<\/blockquote>\n\n<p id=\"apples-filing-against-corellium-and-jailbreaking-update-2020-02-24\">Update (2020-02-24): <a href=\"https:\/\/twitter.com\/pwnallthethings\/status\/1231382219916292102\">Pwn All The Things<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/pwnallthethings\/status\/1231382219916292102\">\n<p>Me: oh looks like this lawsuit is about Apple cornering the infosec research community on their platform<\/p>\n<p>Lots of people: wow sounds like you&rsquo;re overreacting<\/p>\n<p>Apple: <em>uses lawsuit as vehicle to subpoena random other security researchers<\/em><\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Amanda Gorton (MacRumors): Apple&rsquo;s latest filing against Corellium should give all security researchers, app developers, and jailbreakers reason to be concerned. The filing asserts that because Corellium &ldquo;allows users to jailbreak&rdquo; and &ldquo;gave one or more Persons access&#8230; to develop software that can be used to jailbreak,&rdquo; Corellium is &ldquo;engaging in trafficking&rdquo; in violation of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2019-12-30T20:24:23Z","apple_news_api_id":"72342e1d-b417-445a-8c30-2628fff9a857","apple_news_api_modified_at":"2020-02-24T21:14:38Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAg==","apple_news_api_share_url":"https:\/\/apple.news\/AcjQuHbQXRFqMMCYo__moVw","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[38,167,1909,844,31,1610,688,41,209],"class_list":["post-27724","post","type-post","status-publish","format-standard","hentry","category-technology","tag-apple","tag-copyright","tag-corellium","tag-digital-millennium-copyright-act-dmca","tag-ios","tag-ios-12","tag-jailbreak","tag-lawsuit","tag-legal"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/27724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=27724"}],"version-history":[{"count":4,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/27724\/revisions"}],"predecessor-version":[{"id":28221,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/27724\/revisions\/28221"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=27724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=27724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=27724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}