6 ms·
Some useful context: this is almost certainly being driven by Apple’s Private Cloud Compute architecture and not tariffs, as an investment of this magnitude is
by abalone 2y ago
Some useful context: this is almost certainly being driven by Apple’s Private Cloud Compute architecture and not tariffs, as an investment of this magnitude is not planned overnight.
Why is PCC driving Apple to spend billions to build servers in the states? Because it is insane from a security standpoint (insanely awesome).
PCC is an order of magnitude more secure server platform than has ever been deployed for consumer use at planet scale. Secure and private enough to literally send your data and have it processed server side instead of on device without having to trust the host (Apple).[1] Until now the only way to do that was on device. If you sent your data for cloud processing, outside of something exotic like homomorphic encryption[2], you’d still have to trust that the host did a good job protecting your data, using it responsibly, and wasn’t compromised. Not the case with PCC.
To accomplish this Apple uses its own custom chips with Secure Enclaves that provide a trust foundation for the whole system, ultimately cryptographically guaranteeing that the binaries processing your data have been publicly audited by independent security auditors. This is the so called hardware root of trust.
It is essential then that the hardware deployed in data centers has not been physically tampered with. Without that the whole thing falls apart. So Apple has a whole section in their security white paper detailing an audited process for deploying data center hardware and ensuring supply chain integrity.[3]
You can imagine how that is the weak point in the system made more robust by managing it in the US. Tighter supply chain control.
[1] https://security.apple.com/blog/private-cloud-compute/ https://security.apple.com/blog/private-cloud-compute/
[2] Fun fact, Apple also just deployed a homomorphic encryption powered search engine! It’s also insane!
[3] https://security.apple.com/documentation/private-cloud-compute/hardwareintegrity https://security.apple.com/documentation/private-cloud-compu...
- ipaddr 2y agoTrusting Secure Enclaves custom chips over processing locally is going to be a hard to impossible sell for those who truly care about privacy. Thankfully for Apple that's a very low number in a world where people demand tiktok remain legal when shown how their data is being used by foreign actors. People only care about privacy when it's local (don't want mother to find out, neighbours to talk, friend to think a certain way about you or classmate stalking) and that's why ai fakes are much more concern then a company knowing everything you do. But this product is great for fortune 500 businesses.
- addicted 2y agoI think this is a level of security Apple is providing at additional cost to themselves that only a tiny fraction of consumers would even pay an extra cent for. From that perspective I really appreciate this effort by Apple.
- deleted 2y ago[deleted]
- darth_avocado 2y ago> at additional cost to themselves For now.
- deleted 2y ago[deleted]
- nobankai 2y agoYup. Apple knows that they don't have to ship anything more than a whitepaper to justify their stance to current customers. They could announce an internet-connected bidet with a webcam and there would still be people arguing that it's safe until someone exploits it. The fact that Apple is comfortable shipping a whitelabel ChatGPT is proof that the whole Private Cloud Compute thing is just for show. They're perfectly happy partnering with the Worldcoin guy to sell you something popular if there's money in it for them. Apple knows people expect them to release some haughty whitepaper, so they cook up PCC and claim you can audit it if they think you're worthy of seeing the insides. Now all the privacy nuts can pipe down while Apple plans a longer-term strategy to make their hardware compete in the datacenter. There is a world where Apple takes their own privacy commitment to the next level through radical transparency. But that's not what PCC is, it's another puppet for the Punch-and-Judy security theater that sells their iCloud subscriptions.
- abalone 2y agoPCC is completely different from the ChatGPT integration. ChatGPT is indeed not a privacy-hardened system, but Apple devices only use it for so called “world knowledge” queries and make you confirm when calling out to it, typically involving limited personal data. PCC is designed to handle extensive personal data, and the auditing is attested by cryptographic proofs provided to software clients, not just white papers read by humans. It is significantly different from what we’ve seen before in the industry, and highly worth the effort to understand it if you are at all involved in server engineering.
- pl4nty 2y ago> Until now the only way to do that was on device as usual, Apple's implementation is exceptional, but far from the first. see https://confidentialcomputing.io/ https://confidentialcomputing.io/ and its long history
- deleted 2y ago[deleted]
- transpute 2y ago2019 Linux Foundation Confidential Computing 2015 Intel SGX (Skylake) 2014 Apple Secure Enclave (A8, iPhone 6)
- mappu 2y agoARM TrustZone launched with the Arm1176JZ-S in 2004.
- duskwuff 2y ago> 2015 Intel SGX (Skylake) Might be worth pointing out that SGX was compromised repeatedly and comprehensively by speculative execution attacks, e.g. https://www.usenix.org/conference/usenixsecurity18/presentation/bulck https://www.usenix.org/conference/usenixsecurity18/presentat...
- bigfatkitten 2y agoSignal famously bet the (contact discovery) farm on SGX. A controversial design decision at the time, for good reason. https://news.ycombinator.com/item?id=15340729 https://news.ycombinator.com/item?id=15340729
- abalone 2y agoAbsolutely right. My comment was strictly about “for consumer use at planet scale.” It’s the aggressive adoption and rollout of confidential computing architecture in an easy to use consumer platform that I’m celebrating here. (Including a 12 figure financial commitment!) Prior to PCC, smartphones generally had to process data on device to ensure privacy.
- gigel82 2y agoPCC is an awesome solution for Apple to ensure that no one other than Apple can execute code in that environment. That is however not most users' concern (in fact, I'd guess less than 0.001% of Apple users are concerned with supply chain attacks on Apple's servers); what we're concerned with is Apple itself misusing our data in some way (for example, to feed into their growing advertising business, or to redirect to authorities). PCC does NOT solve any of this and it's in fact an unsolvable solution as long as their server side code is closed source (or otherwise unavailable for self-hosting as binaries). For me, Apple Intelligence stays off on my devices (and when that is no longer an option, I'm jumping ship - I just wish there was something at least passable to jump to).
- nroach 2y agoAre these the droids you’re looking for? https://github.com/apple/security-pcc https://github.com/apple/security-pcc
- gigel82 2y agoNo, that is not the PCC, just some research artifacts.
- abalone 2y ago> what we're concerned with is Apple itself misusing our data in some way… and it’s in fact an unsolvable solution as long as their server side code is closed source (or otherwise unavailable for self-hosting as binaries) It is in fact a solvable problem. The binaries are indeed available for self hosting in a virtualized PCC node for research purposes.[1] Auditors can confirm that the binaries do not transmit data outside of the environment. There are several other aspects of the architecture that are designed to prevent use data from leaking outside of the node’s trust boundary, for example TLS terminates at the node level and nodes use encrypted local storage so user data is unreadable to any other node / part of the organization. [1] https://security.apple.com/documentation/private-cloud-compute/inspectingreleases https://security.apple.com/documentation/private-cloud-compu...
- 2y ago
- szvsw 2y ago<<<security is not my domain, asking genuine questions!!>>> At the end of the day, it ultimately still boils down to trust though, yes? Trust that they are running the data centers the way they say they are, trust that their supply chain is what they say it is, and so on? At the same time, using some open source piece of software also entails a great amount of trust: I’m not going through the source code of Signal myself, and I’m also not checking that an open source locally served model isn’t sending traffic/telemetry etc back to some remote server via whatever software is running the model… rather, I’m placing my trust in the open source community that others have inspected and tested these things. I’m sure all sorts of shady PRs into important open source code bases are made on the reg after all. So that’s not to say that trusting Apple is necessarily more or less wise than trusting open source software from a security standpoint… my point is just that it seems like they are aspiring to a zero trust architecture, but at the end of the day, it does still require trust that they are operating in good faith vis-a-vis what they are representing in the white papers right? To me, it seems like a relatively safe assumption that they are for a variety of reasons, but nonetheless, it is an assumption right?
- abalone 2y ago> I’m placing my trust in the open source community You’re right, security is a matter of degrees not absolutes, but open source software requires considerably less trust than closed source. Right? PCC applies this principle by making the binaries it runs public and auditable by you or anyone in the security community. (In some cases the source code as well.) The craziness is in the architecture that provides cryptographic proof to clients that the server they’re connecting to is running an audited binary and running on secure hardware. It even does TLS termination at the shard level so you can have high confidence that if the binary isn’t connecting to anything your data will be unreadable by any other server in the org. So it goes way beyond trusting what the whitepaper says. Data center hardware deployments are audited by a third party that signs the servers in a key ceremony. That ultimately undergirds the cryptographic attestation that servers provide to clients that everything has been audited. And it’s also the element that tighter supply chain control helps shore up. If you’re new to security the architecture documentation I linked to is a very friendly read and a good intro to some of these threats, countermeasures and rationales.
- conradev 2y agoIt's worth noting that AWS has had this sort of infrastructure with Nitro for quite some time now: https://aws.amazon.com/ec2/nitro/nitro-enclaves/ https://aws.amazon.com/ec2/nitro/nitro-enclaves/ At some point it was novel to put a separate hardware root of trust on a PCI-e card but I think that was a while ago, even for Apple!
- abalone 2y agoNitro is good! And showcases a great many of the foundational architectural concepts in PCC. But there is a major difference that is germane to the topic of Apple’s investment in US server manufacturing: The hardware root of trust. Hardware tampering is the weak point and afaik AWS doesn’t describe any process to certify their supply chain integrity. I think the most they’ve done is commission a review of their architecture document.[1] PCC actually has an auditor sign each server node in the datacenter. Thank you for mentioning them though. It’s an important advancement in generally available confidential computing infrastructure. [1] https://aws.amazon.com/blogs/compute/aws-nitro-system-gets-independent-affirmation-of-its-confidential-compute-capabilities/ https://aws.amazon.com/blogs/compute/aws-nitro-system-gets-i...
- timewizard 2y ago> this is almost certainly being driven by Apple’s Private Cloud Compute architecture and not tariffs, as an investment of this magnitude is not planned overnight. The tarriffs haven't happened overnight. They've been discussed for going on 2 full years now. Anyone who wasn't blinded by their own political preferences saw this coming.
- flashman 2y ago> It is essential then that the hardware deployed in data centers has not been physically tampered with. Without that the whole thing falls apart. am i wrong or does this just change the threat from Chinese to US government tampering and if third-party auditing can detect hardware tampering then why does it matter where the hardware is manufactured
- yalogin 2y agoI think this is conjecture, there is no indication anywhere that it’s driven by the PCC data centers. If anything I would guess they are trying to build hardware in the US. That has to be the only reason to invest that much.
- vaxman 2y agoPCC is a kludge for mitigating battery life on smartphones doing Personal Assistant work, for knowing what their chances of getting nVidia chip allocations are, for knowing how unreliable nVidia hardware is --basically for having been caught with their pants down when genAI took off. That said, it's a good kludge. The easy fix is to add more vector cores and RAM to the chips and shrink them to use less power, but it takes time and initially these go to power cord systems (first in the kludge, then maybe MacPro and some kind of AI-hub that sits in your living room and vehicle), then..well you wonder why the small form factor iPhone just was dc'ed?