Has anyone yet tried to sniff the traffic when the iLiad connects to iDS? I know it's SSL-protected, but with a MitM attack using tools like
Ettercap or
dsniff you should be able to deal with it.
Sniffing the traffic, we could then find out - for instance - how the iRex does remote flash upgrades.