4 ms·
Trusting Secure Enclaves custom chips over processing locally is going to be a hard to impossible sell for those who truly care about privacy. Thankfully for A
by ipaddr 2y ago
Trusting Secure Enclaves custom chips over processing locally is going to be a hard to impossible sell for those who truly care about privacy.
Thankfully for Apple that's a very low number in a world where people demand tiktok remain legal when shown how their data is being used by foreign actors. People only care about privacy when it's local (don't want mother to find out, neighbours to talk, friend to think a certain way about you or classmate stalking) and that's why ai fakes are much more concern then a company knowing everything you do.
But this product is great for fortune 500 businesses.
- addicted 2y agoI think this is a level of security Apple is providing at additional cost to themselves that only a tiny fraction of consumers would even pay an extra cent for. From that perspective I really appreciate this effort by Apple.
- deleted 2y ago[deleted]
- darth_avocado 2y ago> at additional cost to themselves For now.
- deleted 2y ago[deleted]
- nobankai 2y agoYup. Apple knows that they don't have to ship anything more than a whitepaper to justify their stance to current customers. They could announce an internet-connected bidet with a webcam and there would still be people arguing that it's safe until someone exploits it. The fact that Apple is comfortable shipping a whitelabel ChatGPT is proof that the whole Private Cloud Compute thing is just for show. They're perfectly happy partnering with the Worldcoin guy to sell you something popular if there's money in it for them. Apple knows people expect them to release some haughty whitepaper, so they cook up PCC and claim you can audit it if they think you're worthy of seeing the insides. Now all the privacy nuts can pipe down while Apple plans a longer-term strategy to make their hardware compete in the datacenter. There is a world where Apple takes their own privacy commitment to the next level through radical transparency. But that's not what PCC is, it's another puppet for the Punch-and-Judy security theater that sells their iCloud subscriptions.
- abalone 2y agoPCC is completely different from the ChatGPT integration. ChatGPT is indeed not a privacy-hardened system, but Apple devices only use it for so called “world knowledge” queries and make you confirm when calling out to it, typically involving limited personal data. PCC is designed to handle extensive personal data, and the auditing is attested by cryptographic proofs provided to software clients, not just white papers read by humans. It is significantly different from what we’ve seen before in the industry, and highly worth the effort to understand it if you are at all involved in server engineering.
- transpute 2y ago> Trusting Secure Enclaves custom chips over processing locally is going to be a hard to impossible sell for those who truly care about privacy. Isn't local processing on Apple devices rooted in the same secure enclave hardware/firmware, attacked and hardened for 10+ years?
- int_19h 2y agoThe problem with any remote arrangement is that you have to trust Apple that the server side is running all that stuff. Their answer to that is "you can audit us", but I don't see how that would prevent them from switching things in between audits. As far as local processing goes, though, you're also still fundamentally trusting Apple that the OS binaries you get from them do what they say they do. Since they have all the signing keys, they could easily push an iOS update that extracts all the local data and pushes it to some server somewhere. Now, I don't think that either of these scenarios is likely to happen if it's down to Apple by itself - they don't really gain anything from doing so. But they could be compelled by a government large and important enough that they can't just pull out. For example, if US demanded such a thing (like it already did in the past), and the executive made a concerted push to force it.
- transpute 2y agoyou have to trust Apple that the server side is running all that stuff Remote attestation should be proving to the client that the server is running the expected firmware and PCC software hashes, https://security.apple.com/documentation/private-cloud-compute/hardwarerootoftrust https://security.apple.com/documentation/private-cloud-compu.... Apple has released (some? all?) source for PCC software on the server, https://github.com/apple/security-pcc https://github.com/apple/security-pcc > When a user’s device sends an inference request to Private Cloud Compute, the request is sent end-to-end encrypted to the specific PCC nodes needed for the request. The PCC nodes share a public key and an attestation — cryptographic proof of key ownership and measurements of the software running on the PCC node — with the user’s device, and the user’s device compares these measurements against a public, append-only ledger of PCC software releases. > compelled by a government Sadly, the bar is much lower than "compel". Devices are routinely compromised by zero-day vulnerabilities sold by exploit brokers to multiple parties on the open market, including governments. Especially any device with cellular, wifi or bluetooth radios. Hopefully the Apple C1 modem starts a new trend in radio baseband hardening, including PAC, ASLR and iBoot, https://www.reuters.com/technology/apple-reveals-first-custom-modem-chip-shifting-away-qualcomm-2025-02-19/ https://www.reuters.com/technology/apple-reveals-first-custo...
- xpe 2y agoEverything about democracy is great except its people. You know, the big brained carbon lifeforms that refer to themselves as “citizens”.
- tstrimple 2y agoAt some point having trained and certified Apple engineers overseeing this sort of thing gives far more confidence than random startup #1345134 who promises they hired the best college drop outs that they could find.
- throwaway2037 2y ago> for those who truly care about privacy Is this the new "No true Scotsman" test on HN?
- r00fus 2y ago> Trusting Secure Enclaves custom chips over processing locally If you're using Apple hardware, it's the same technology in your local device anyway, right?