4 ms·
It's closed source and paid for some very obvious reasons: - Corellium is the result of years of research, throwing it away for free would be stupid - If Corel
by jakeashacks 7y ago
It's closed source and paid for some very obvious reasons:
- Corellium is the result of years of research, throwing it away for free would be stupid
- If Corellium released their tools, Apple would so something to break it, starting a cat and mouse war like they already do with jailbreaking
- Not much people can use the thing anyways. It requires arm64 computers. Most of computers use x86(-64)
- Red_Leaves_Flyy 7y agoI don't have sympathy for a company experiencing hardship because their entire existence is predicated on doing things to the software of another company (Apple) that (Apple) does not like. They brought this upon themselves. I think it is a necessary service, however their for profit nature creates perverse incentives. Corelliums refusal to be bought by Apple likely shows their continued attempts to profit off of exploiting the work of another company. Corellium could take the mongodb approach, or I don't know, actually work with Apple on Apple's terms, since their financially dependent on their ability to provide re tools for Apple's proprietary software. Apple actually creates economic value. Corellium are greedy pirates leeching off of sketchy markets for exploits sometimes used by authoritarian regimes to abuse the human rights of minorities and citizens alike.
- jakeashacks 7y ago> Corelliums refusal to be bought by Apple likely shows their continued attempts to profit off of exploiting the work of another company. The only reason Apple wanted to buy Corellium was to shut them down. Apple doesn't need Corellium's technologies, they can do the same things and better. > actually work with Apple on Apple's terms Apple's terms are stupid. "Give us every vulnerability you and your clients find with the service", and it's not like Apple's paying them back anyway. Corellium already submitted many bugs to Apple and Apple didn't keep their promise of paying the bounty but instead decided to sue them.
- Red_Leaves_Flyy 7y agoWhat else you gonna do with those vulns if not report them to apple?
- jakeashacks 7y agoYou can keep them for yourself (can make further research easier), release them as 0days (not every vulnerability can be used by attackers so sometimes full disclosure isn't a bad idea. an example would be bootchain bugs, they can't be used remotely), release them as jailbreaks, sell them to someone (you can verify they won't be used for malicious purposes; you could sell them to another researcher for example which can use them to make their research easier)
- Wowfunhappy 7y ago> I don't have sympathy for a company experiencing hardship because their entire existence is predicated on doing things to the software of another company (Apple) that (Apple) does not like. Why does Apple have to like it? Corellium saw a critical need and did the work to fill it. Does security research not have economic value? Should no one do that research?
- Red_Leaves_Flyy 7y agoThat argument is disingenuous. Corellium is doing some security research. But what else are they doing? They're definitely profiting from the use of their software to find vulns that get used against vulnerable populations. There are a lot of rumors about less savory things they might be up to. So arguing that apple is just picking on security researchers is rubbish. Apple isn't innocent, but corellium seems to be worse at the moment.
- Wowfunhappy 7y agoDo we have evidence of those "less savory" things? All security research could be used for ill, but I firmly believe the ability to do such research makes us better off overall.