News: 1629238210

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Apple says its CSAM scan code can be verified by researchers. Corellium starts throwing out dollar bills

(2021/08/18)


Updated Last week, Apple essentially invited security researchers to probe its forthcoming technology that's supposed to help thwart the spread of known child sexual abuse material (CSAM).

In an attempt to clear up what it characterized as misunderstandings about its [1]controversial plan to [2]analyze iCloud-bound photos for this awful material, the Cupertino giant described

[3]PDF

the systems, protections, and mechanisms involved.

Crucially, Apple repeatedly stated that its claims about its CSAM-scanning software are "subject to code inspection by security researchers like all other iOS device-side security claims." And its senior veep of software engineering Craig Federighi went on the record to say "security researchers are constantly able to introspect what's happening in Apple's [phone] software."

[4]

Now, Florida-based infosec outfit Corellium is taking Apple up on that assertion. And yes, that's the same Corellium Apple tried to drag through the courts, alleging “unlawful commercialization of Apple’s valuable copyrighted works,” until it gave up that fight last week.

[5]

[6]

With that victory, of sorts, under its belt, and Apple's invitation to bug hunters and cryptography experts, Corellium, which previously accused Apple of trying to hinder external security research, this week heralded the iPhone maker's “commitment to holding itself accountable" by researchers.

We feel there may be some sarcasm in that quote.

[7]

In any case, Corellium has launched a $15,000 initiative to encourage researchers to test Apple's commitment to accountability. Specifically, the initiative is open to proposals for "research projects designed to validate any security and privacy claims for any mobile software vendor, whether in the operating system or third-party applications," though it's clear it has Apple in mind.

That may be because, depending on [8]who you are , Apple in the past at least has either made it difficult or slightly less than difficult to pore over its low-level, proprietary code for exploitable faults.

"We applaud Apple’s commitment to holding itself accountable by third-party researchers," [9]said Corellium, which provides among other things virtualized iOS devices for infosec types to examine and probe for holes, adding: "We believe our platform is uniquely capable of supporting researchers in that effort."

[10]

Up to 1700 EST on October 15, Corellium says it will accept security research proposals and judge them based on technical merits, feasibility, and presumed likelihood of success. The biz said it will award a $5,000 grant and a year of free access to its mobile device virtualization platform for up to three submissions.

The program rules require any vulnerabilities found to be reported directly to the relevant vendor, so any bug bounty award from the vendor would depend on whether that company has a vulnerability reward program and what the program covers.

True to form, Apple did not respond to a request for comment. Neither did Corellium.

[11]Apple settles lawsuit against Corellium as iOS platform dictatorship looks more precarious

[12]Judge rules Corellium iOS research app 'fair use' in slap to Apple

[13]We turn away for a second and Corellium is already showing off Ubuntu on Apple Silicon

[14]Apple's iPhone computer vision has the potential to preserve privacy but also break it completely

In a phone interview, Katie Moussouris, founder of [15]Luta Security and a pioneer in designing bug bounties, told The Register she found it noteworthy that research grant programs, which have been around for years, are moving away from vendors.

It's interesting that they're offering research grants towards doing research for any mobile devices and not just iPhones

"What's interesting about the Corellium announcement is it's no longer the vendors themselves offering research grants, which obviously I think is a great idea, but it's a third-party that makes a virtualization platform that makes reverse engineering easier," she said. "I also think it's interesting that they're offering research grants towards doing research for any mobile devices and not just iPhones."

Moussouris said it's clear Corellium's grant program would have happened if Apple's litigation had not concluded.

Asked about Federighi's characterization of Apple's openness with regard to security research, Moussouris said Apple's perception of openness isn't necessarily the same as the rest of the security industry.

"Remember, for a long time, the Apple security team couldn't even have the word 'security' on their business cards," she said. 'They couldn't talk about security at all. So I think that for Apple, this seems very open. For the rest of the world, Apple's still on a much more secretive and closed side of things, including for security research."

Citing her role in the creation of the first Microsoft bug bounty program, Moussouris said, "I am a big fan of incentive programs, smart incentive programs that don't create perverse incentives [like] overly rewarding things that should have been found internally by the organization itself, by its own employees, and by testing and tools." ®

Updated to add

Apple on Tuesday filed an appeal

[16]PDF

in the lawsuit it brought against Corellium and then settled

[17]PDF

last week.

As we understand it, Apple is seeking to overturn US District Judge Rodney Smith's decision to throw out Apple's copyright claims against Corellium over the latter's virtualization technology.

Some parts of Apple's lawsuit were dismissed by the judge, some parts regarding the DMCA were settled by Apple, and now Apple would like to continue suing Corellium on the points of copyright that were dismissed.

Get our [18]Tech Resources



[1] https://www.theregister.com/2021/08/09/apple_csam_faq/

[2] https://www.apple.com/child-safety/

[3] https://www.apple.com/child-safety/pdf/Security_Threat_Model_Review_of_Apple_Child_Safety_Features.pdf

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YRyF@JCeJW0mXzoPBVFkMwAAAEg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRyF@JCeJW0mXzoPBVFkMwAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YRyF@JCeJW0mXzoPBVFkMwAAAEg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRyF@JCeJW0mXzoPBVFkMwAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2020/07/23/apple_iphone_security_research_device/

[9] https://www.corellium.com/blog/open-security-initiative

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YRyF@JCeJW0mXzoPBVFkMwAAAEg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2021/08/11/apple_corellium_lawsuit/

[12] https://www.theregister.com/2021/01/04/corellium_ios_ruling/

[13] https://www.theregister.com/2021/01/21/linux_apple_m1/

[14] https://www.theregister.com/2021/08/16/ai_vision_apple/

[15] https://www.lutasecurity.com/

[16] https://regmedia.co.uk/2021/08/18/corellium.pdf

[17] https://regmedia.co.uk/2021/08/18/pacer_apple_corellium_final_judgment.pdf

[18] https://whitepapers.theregister.com/



Pear

elsergiovolador

Wow the level of contempt from Apple is astounding.

"Look it was reviewed by researchers! They say it's safe! What else do you want you stupid customer?"

Look, Squirrel!

sqlrob

The client can be 100% secure and do everything it says on the box. Unless this also includes auditing how hashes get in the system AND keeping that audit 100% up to date, it's really kind of pointless and doesn't prove much.

Doctor Syntax

How do you audit a precedent?

cornetman

They don't really address how they are going to handle governments making them use the technology, once it is up and running, to bend it to their own ends.

Like scanning for distributed pictures of Winnie The Pooh or whatever is the demon de jour in the Western world.

Rug

elsergiovolador

This is an equivalent of a rug company sending a Roomba equipped with sensors to sweep your house looking for traces of drugs and then reporting you and we are at a point discussing what if Roomba will start collecting DNA samples from the rug instead of rejecting the whole idea altogether.

Re: Rug

cornetman

Don't get me wrong. This is an awful idea and Apple are going to regret going down this path.

I would be interested to know where this came from originally. I cannot believe that they are that stupid that they didn't realise how this tech would be bent to the ends of the likes of China at the very least. It will be a case of do it, or you don't sell in China.

Re: Rug

HildyJ

Drugs are passe.

The vector will be spousal and child abuse with the FBI requesting' that Roomba search for and report on any blood traces it finds.

who audits the hashes?

revilo

Do they really believe we have an IQ of 50? Of course, one can audit the software which produces the hashes or compares them. I trust that they can program this correctly. But nobody can audit the smut which actually feeds the hashes. Or does anybody believe that the database of smut pictures is passed around to security researchers? Craig Federighi is an intelligent person who knows that he is misleading the press. The system design by definition to be not auditable. The basic fact remains that every user is subjected to a police software, treated like a criminal, gets a hash of kiddy porn pictures loaded on their machines and will be completely depending on the goodwill of the folks feeding the offensive database (which is not apple). In the future and some countries this will certainly also include politically offensive documents. Apple is misleading us also because it would technically be no problem to compare even encrypted files on icloud with an offensive database. Nobody would object to such checks. That the police software has to run on every users machine is completely new and unacceptable.

When taxes are due, Americans tend to feel quite bled-white and blue.