11 ms·
Apple is suing smartphone emulation software startup Corellium
- villgax 5y agoThis is outdated reporting, Apple did drop the suit against Corellium a few days back. Funnily enough the same NeuralHash has already been generated for completely different images, so good luck explaining why your 4th of July pics cost all of your safety vouchers to Apple/FBI
- commoner 5y agoAlready covered in the article: > In the lawsuit, Apple argued that Corellium violated its copyrights, enabled the sale of software exploits used for hacking, and shouldn’t exist. The startup countered by saying that its use of Apple’s code was a classic protected case of fair use. The judge has largely sided with Corellium so far. Part of the two-year case was settled just last week—days after news of the company’s CSAM technology became public. > On Monday, Corellium announced a $15,000 grant for a program it is specifically promoting as a way to look at iPhones under a microscope and hold Apple accountable. On Tuesday, Apple filed an appeal continuing the lawsuit.
- shapefrog 5y agoHeadline is deliberatly implying that they are suing a startup for veting their CSAM tool. Fake news.
- commoner 5y agoThis doesn't look like "fake news" to me. Timeline: Monday, August 16: Corellium launches its "Open Security Initiative" to fund "research projects designed to validate any security and privacy claims for any mobile software vendor". The announcement prominently lists Apple's privacy and security claims about its CSAM scanning as one of the topics that would be eligible for funding under this initiative. (https://www.corellium.com/blog/open-security-initiative https://www.corellium.com/blog/open-security-initiative) Tuesday, August 17: Apple appeals the copyright case that it lost against Corellium. Reuters reports that the appeal was a "surprise" after the recent settlement. (https://www.reuters.com/legal/transactional/apple-files-appeal-notice-copyright-lawsuit-against-cybersecurity-firm-2021-08-17/ https://www.reuters.com/legal/transactional/apple-files-appe...)
- shapefrog 5y agoCorrect timeline: August 2019 - Apple sued iOS virtualization provider Corellium for copyright infringement and DMCA violations December 29, 2020 - Apple loses copyright claims in lawsuit against U.S. security bug startup August 5, 2021 - Apple announces new protections for child safety August 17, 2021 - Apple says researchers can vet its child safety features. But it’s suing a startup that does just that. Unless there is an iTimemachine I struggle to see how Apple sued a company in August 2019 for saying in August 2021 it will vet help vet its CSAM tools announced in August 2021.
- commoner 5y agoApple settled the lawsuit on August 10, 2021, just to file an appeal on August 17, 2021 (one day after Corellium's announcement). That is the focus of the article, not the original 2019 filing. From the Reuters link in the article: > The appeal came as a surprise because Apple had just settled other claims with Corellium relating to the Digitial Milennium Copyright Act, avoiding a trial. > Experts said they were also surprised that Apple revived a fight against a major research tool provider just after arguing that researchers would provide a check on its controversial plan to scan customer devices. https://www.reuters.com/legal/transactional/apple-files-appeal-notice-copyright-lawsuit-against-cybersecurity-firm-2021-08-17/ https://www.reuters.com/legal/transactional/apple-files-appe...
- zenexer 5y agoIt’s going to be practically impossible for most researchers to vet the CSAM detection tool without Corellium. It’s already very difficult with Corellium, but Apple is going out of their way to ensure such research is infeasible in most cases. That isn’t limited to their CSAM detection tool—hence the lawsuit that predates that tool. Apple is claiming that researchers can vet the CSAM detection feature while simultaneously attempting to take down organizations that make such research possible. It’s a stupid statement on their part.
- saurik 5y agoNeither the headline nor the HN title say that the lawsuit is "for saying" anything... they both merely--and very correctly--claim that Apple "is suing a startup that does just that". Are you claiming that Apple is not suing Corellium? Alternatively, are you claiming Corellium does not "do[] just that"?
- zenexer 5y agoNo they didn’t. They did settle, but they subsequently appealed a week later.
- tremon 5y agoNote to self: make sure every settlement agreement includes a clause like "the agreed-to settlement amount triples on every subsequent legal action by $other_party concerning this subject".
- saurik 5y agoSo, it is maybe worth explaining this a bit: Apple lost these claims in December... and like, really badly: the jugs outright dismissed them; but then the trial was going to continue with the rest of the claims, which were settled. Apple is now appealing the claims they lost, not the ones they settled (they can't do that: that would undermine the premise of settling anything at all). Legal complaints are not atomic all-or-nothing affairs in this way.
- zenexer 5y agoThanks for the added context. I assumed it was either something along those lines or the settlement was never actually finalized. It’ll be interesting to see what comes of all of this.
- croes 5y agoYou mean Apple lost, but they appealed already https://www.reuters.com/legal/transactional/apple-files-appeal-notice-copyright-lawsuit-against-cybersecurity-firm-2021-08-17/q https://www.reuters.com/legal/transactional/apple-files-appe...
- arkades 5y agoI got an ad overlay from the top of my screen, a growing banner from the bottom, and a fade-in pop-up over that. Within five seconds of loading the page, precisely 0% of it remained unobscured.
- shapefrog 5y agoYay. 2 free stories remaining.
- c7DJTLrn 5y agoFor me the whole page is just some kind of abstract image captioned "MS Tech" with a tiny shred of the actual article at the bottom of my screen.
- azalemeth 5y agoIndeed. Fortunately, umatrix exists and is very helpful – I turned off cookies and scripts for the page, and all was good.
- webmobdev 5y agoThat's the beauty of using Firefox + uBlock Origin on both your computer and non-ios mobile - you will completely avoid these kind of irritating annoyances, experience quicker loading and more responsive websites and save a lot of bandwidth. (On ios AdGuard does the same but is limited because of Safari. Google is also working to cripple ad-blocking on Chrome, so Firefox is currently the best browser to comprehensively avoid such ad-infestation and trackers online).
- heavymark 5y agoI’ve been using 1Blocker on Mac and iOS for years and every once in a great while I have it disabled temporarily and can’t believe people what people have to deal with where everything is covered in ads. Every once in a while some feature on a site doesn’t work so I click disable content blockers for that one page temporarily then all is good or can always just open up chrome for a particular site on those rare occasions.
- deleted 5y ago
- deleted 5y ago[deleted]
- flixic 5y agoHeadline implies that Apple sued Corellium because of their CSAM research, but that's not at all related. This is quite clickbaity.
- Crontab 5y agoCorrect. I am quite disappointed in the editors.
- zenexer 5y agoI didn’t get that impression from the title, but I also knew they were referring to Corellium before clicking the link. I interpreted it as, “Apple says researchers can vet its CSAM tools despite aggressively suing the one company that makes such research feasible.”
- mrunseen 5y agoYeah, I thought like that too. It could’ve been better though.
- ziml77 5y agoI heard nothing about Corellium before, so my reading of the headline was that Apple is retaliating against a company for trying to audit their CSAM tools despite saying that it's totally fine if people want to do those audits.
- chrisfinazzo 5y agoOn one level, I'm not surprised and can understand why Apple might be pissed off that Corellium is still making news. "Researchers can audit our CSAM process...except for you, who we just handed a pile of money over to and are still on our shit list."
- saurik 5y agoThe narrative here--which I feel like a lot of people aren't grokking somehow--is that to analyze Apple's CSAM tools you need to be able to extract them from a phone to debug and work with them, which involves reverse engineering the implementation; and Apple recently said quite strongly that a reason you can trust their client-side CSAM is because, by virtue of being on the client, security researchers can do this analysis. Only, simultaneously, Apple hates the idea that people ever should get access to the software that runs on their phones and reverse engineer it: they tend to downplay results that are found in a way that often involves going to war with the security research community, they sued Corellium--which provides tooling to security researchers--and insisted that their clients were doing things that were inherently illegal, and they are so stingy with giving general access to their devices that not only can you not opt out of their lockdown they won't sell you special bright yellow open devices either... after many years of pleading with them, they finally decided to allow some researchers access, but it requires not only being invited but then signing off on gag clauses that are generally considered to violate the ethical responsibility of practitioners. It thereby feels like Apple is talking out of both sides of their mouth... though, of course, that's nothing new for them :/. On the one hand, they want to claim that security researchers are important to their overall security strategy; but, on the other, they simultaneously abuse and prosecute people who dare to either directly pull apart their systems or have the audacity to provide the tools required for others to do so. And, for anyone who is stuck in the mental frame "BuT I tHoUgHt ApPlE lOvEs SeCuRiTy ReSeArChErS", barely over a year ago (wow time flies when you are living alone and physically falling apart during a pandemic, huh? ;P), I wrote a thread on Twitter that documented a ton of the issues that we run into with Apple, including using specific examples, and touched on this lawsuit against Corellium. FWIW, I don't personally know of anyone in the security industry that thinks Apple is doing well on this front, and I doubt many exist. https://twitter.com/saurik/status/1295024384596312064?s=21 https://twitter.com/saurik/status/1295024384596312064?s=21 Also: here is a thread on Twitter from a few days ago (started by Runa Sandvik, the senior director of information security at the New York Times) about Apple's recent statements, as well as a direct link to a reply sub-thread from Kurt Opsahl--the Deputy Executive Director and General Counsel of the EFF--that quickly got updated re the Corellium appeal. https://twitter.com/runasand/status/1426232172109869057?s=21 https://twitter.com/runasand/status/1426232172109869057?s=21 https://twitter.com/kurtopsahl/status/1426314930001567751?s=21 https://twitter.com/kurtopsahl/status/1426314930001567751?s=... (edit) I am realizing it is probably also worth explaining another key detail here that is probably more than just a bit confusing: one reason this is particular news right now is because, in addition to the big CSAM background story, Apple just announced an appeal of the case they lost to Corellium. I think it is important to triple underscore that: a lot of people know about how Corellium and Apple recently settled, but that was over other claims that Apple (seemingly) gave up on; Apple can't appeal that AFAIK. However, in December, Apple had most of its (extremely weak...) case dismissed by the judge. https://www.reuters.com/article/us-apple-corellium-idUSKBN29320J https://www.reuters.com/article/us-apple-corellium-idUSKBN29... > U.S. District Judge Rodney Smith ruled in favor of Corellium LLC, saying its software emulating the iOS operating system that runs on the iPhone and iPad amounted to “fair use” because it was “transformative” and helped developers find security flaws. It almost certainly isn't the case that Apple decided to do this appeal because of Corellium's press release, as it almost certainly takes more than less-than-a-day to put that together and file it ;P. It will be interesting to see if Apple manages to put together a more coherent argument in their appeal.
- test6554 5y agoHow long before people figure out the CSAM service endpoints and block them via a PI Hole device?
- kemayo 5y agoAs I understand what has been said, the CSAM detection is part of the iCloud Photos upload process, via attaching some metadata to the photos that're being uploaded. So you could block this service, but it'd be functionally equivalent to just disabling iCloud Photos entirely.
- zionic 5y agoThis makes sense, iCloud can just be blocked with the rest of the malware domains. For fun corporate and university IT types can start adding iCloud-related domains to their internal blacklists.
- kemayo 5y agoFor consistency, they'd need to block Google, Facebook, and everyone else who's scanning all your uploaded content. See: https://en.wikipedia.org/wiki/PhotoDNA https://en.wikipedia.org/wiki/PhotoDNA
- Ajedi32 5y agoThe distinction there is that it's the server doing the matching and reporting, not the client. People expect remote servers to be accessible to government searches, but not their own personal devices. This distinction is even codified in U.S. law. The government needs a warrant to search your phone, but only needs a subpoena to search a remote server that's storing your files[1]. But yes, I can see why that distinction might feel a little arbitrary at times, particularly in the modern age where cloud storage is so common. Perhaps the 4th amendment should cover third parties storing "papers, and effects" on a person's behalf. [1]: https://grandjurytarget.com/2020/10/28/by-search-warrant-or-subpoena-the-government-will-get-your-gmail-and-the-numbers-are-on-the-rise/ https://grandjurytarget.com/2020/10/28/by-search-warrant-or-...
- notquitehuman 5y agoEven if they weren’t lying through their teeth, this changes nothing. My objection is to Apple believing that they can use a device I own for proactive law enforcement and then acting on that belief. Nothing about how they do that is even worth considering. Apple is spying on you for the police.
- sharken 5y agoThe last sentence is the simple truth that no amount of Apple marketing dollars can hide.
- dudul 5y agoAnd the thing is they're spying on you for nothing - at least not to catch pedos. Pedos are extremely tech-savvy, they need to be to survive. Starting now, none of them is gonna use Apple products and that's it. My guess is they'll catch as many pedos as terrorists that were caught by the TSA.
- aunterste 5y agoThe TSA is the sole gateway to getting on a commercial flight, so while they not catch many/any, they are an effective deterrent, Apple has no such monopoly to leave any dent on the Pedo scene.
- rgovostes 5y ago> [In 2018, Facebook Messenger] was responsible for nearly 12 million of the 18.4 million worldwide reports of child sexual abuse material, according to people familiar with the reports. https://www.nytimes.com/interactive/2019/09/28/us/child-sex-abuse.html https://www.nytimes.com/interactive/2019/09/28/us/child-sex-...
- joshstrange 5y ago> Pedos are extremely tech-savvy, they need to be to survive. This is not at all borne out in reality. When the FBI rounded up a big ring of CSAM creators/consumers a few years back it came out that they (the people sharing) had rules for how to interact with the community that would have fully protected them, but many of them were sloppy. Same thing with the amount of CSAM that FB reports.
- nullc 5y agoThe quote from the Apple executive is misleading to outright dishonest. > “Security researchers are constantly able to introspect what's happening in Apple’s [phone] software,” Apple vice president Craig Federighi said in an interview with the Wall Street Journal. “So if any changes were made that were to expand the scope of this in some way—in a way that we had committed to not doing—there’s verifiability, they can spot that that's happening.” Apple uses complex cryptography to shield themselves and their list providers from accountability. You cannot determine if they've included non-child-abuse images in the database through inspection.
- djrogers 5y agoNo, but you can verify that only photos uploaded to iCloud are scanned, and can verify that photo metadata beyond the security voucher is not generated or sent to anyone but Apple.
- nullc 5y agoThe former, yes. The latter no: because Apple can send it on further beyond your ability to observe. :)
- troyvit 5y agoYeah but once you move something from your personal device to a cloud operated by a private entity why would you expect privacy anyway?
- blew_job 5y agoHorrible counter argument, what's the point of Apple advertising privacy ad nauseam if your shit isn't safe and secure for your eyes only.
- croes 5y agoHow can you verify what Apple does on its iPhones?
- 5y ago
- runjake 5y agoResearchers can vet the client-side part of the tools, but per the Security Device program agreement they can’t discuss anything publicly without Apple giving them the go ahead. And presumably the hash match database downloaded to the device is encrypted and unable to be examined.
- imwillofficial 5y agoMost misleading headline of the century.
- justinzollars 5y agoApple is now the bad guy.
- squarefoot 5y agoGroklaw PJ, where are you now that you are needed the most?
- downandout 5y agoI realize that “child safety features” is the absurd euphemism in the title of the article itself, but the title really should be changed here on HN. Allowing a title like “child safety features” to describe this technology within a community that both knows better and is prominently featured in Google gives that description credence. It should be changed to something like “…invasive screening technology” or “…government backdoor into your iPhone”.
- mcdevilkiller 5y agoDid the font break on my device, or is everything just in bold? I cannot read it like that.
- neycoda 5y agoThe notification has one title, the title here has another, the article title has another, and I'm immediately assaulted with pop-ups and page scroll shifts... it can be REALLY annoying checking HN sometimes, you know?!