Earlier quoted context omitted.
They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…
Nit (maybe moot): > 4) Apple incurred damages […] from expenses related to mitigating the hacking of their users. This sounds like no one should be a security researcher for they risk paying companies to implement the security the company should have implemented anyway. Put another way, that also sounds like the corporate open source push, "We love open source because we don't have to support it, the community will!"…
"60. Defendants force Apple to engage in a continual arms race: Even as Apple develops solutions and enhances the security of its devices, Defendants are constantly updating their malware and exploits to overcome Apple’s own security upgrades.
61. These constant recovery and prevention efforts require significant resources and impose huge costs on Apple. Defendants’ unlawful malware activities have caused and continue to cause Apple significant damages in excess of $75,000 and in an amount to be proven at trial."
Hopefully the judgement is able to split the hairs between reputational and development harm to a company for security vulnerabilities, and harm to users for organized exploitation of those vulnerabilities.
The former feels like it should be free speech -- statement of facts related to the company's product(s). The latter is an obvious wrong.