3 ms·
Your concern is the hardware auditors are not trustworthy because Apple hired them? I mean that’s fair but I don’t think the goal here is to offer that level o
by abalone 2y ago
Your concern is the hardware auditors are not trustworthy because Apple hired them?
I mean that’s fair but I don’t think the goal here is to offer that level of guarantee. For example their ceremony involves people from 3 other Apple organizational units, plus the auditor. It’s mostly Apple doing the certification. They’re not trying to guard too heavily against the “I don’t trust Apple is trying to fool me” concern.
What this does protect you from is stuff like a rogue internal actor, software vulnerability, or government subpoena. The PCC nodes are “airtight” and provably do not retain or share data. This is auditable by the whole security community and clients can verify they are communicating with an auditable binary. It’s not just a white paper.
That’s an enormous step up from the status quo.