3 ms·
PCC is fundamentally more secure than merely encrypting at rest and auditing access. That still has a variety of attack vectors such as a software bug that leak
by abalone 2y ago
PCC is fundamentally more secure than merely encrypting at rest and auditing access. That still has a variety of attack vectors such as a software bug that leaks data.
Apple is unable to access the data even if subpoenaed, for example, and this is provable via binary audits and client verification that they are communicating with an auditable node.
- mattlondon 2y agoHow is that any different in either direction? Bugs exist in any and all code. Encrypted data is unencryptable if you don't have the keys. I don't see that apple software is any different in that regard (just try using Mac OS for any length of time even on apple silicon and you run out of fingers to count obvious UI bugs pretty quickly just in day to day usage). And obviously AWS won't be able to decrypt your data without your keys either. The people running these huge multi-multi-billion clouds are not idiots making fundamental errors in security. This is why they all pay mega salaries for highly skilled people and offer five-figure bug bounties etc - they take this seriously. Would some random VPS or whatever be more likely to make errors like this, sure - but they are not in (and not expected to be) in the same league.
- mattlondon 2y agoAnd just to confirm, less than 24 hours a post on HN here about a whole new batch of critical security bugs in Mac OS: https://jhftss.github.io/A-New-Era-of-macOS-Sandbox-Escapes/ https://jhftss.github.io/A-New-Era-of-macOS-Sandbox-Escapes/ I would not trust Apple any more or less than other other big-time cloud provider.