4 ms·
PCC is an awesome solution for Apple to ensure that no one other than Apple can execute code in that environment. That is however not most users' concern (in f
by gigel82 2y ago
PCC is an awesome solution for Apple to ensure that no one other than Apple can execute code in that environment.
That is however not most users' concern (in fact, I'd guess less than 0.001% of Apple users are concerned with supply chain attacks on Apple's servers); what we're concerned with is Apple itself misusing our data in some way (for example, to feed into their growing advertising business, or to redirect to authorities). PCC does NOT solve any of this and it's in fact an unsolvable solution as long as their server side code is closed source (or otherwise unavailable for self-hosting as binaries). For me, Apple Intelligence stays off on my devices (and when that is no longer an option, I'm jumping ship - I just wish there was something at least passable to jump to).
- nroach 2y agoAre these the droids you’re looking for? https://github.com/apple/security-pcc https://github.com/apple/security-pcc
- gigel82 2y agoNo, that is not the PCC, just some research artifacts.
- abalone 2y ago> what we're concerned with is Apple itself misusing our data in some way… and it’s in fact an unsolvable solution as long as their server side code is closed source (or otherwise unavailable for self-hosting as binaries) It is in fact a solvable problem. The binaries are indeed available for self hosting in a virtualized PCC node for research purposes.[1] Auditors can confirm that the binaries do not transmit data outside of the environment. There are several other aspects of the architecture that are designed to prevent use data from leaking outside of the node’s trust boundary, for example TLS terminates at the node level and nodes use encrypted local storage so user data is unreadable to any other node / part of the organization. [1] https://security.apple.com/documentation/private-cloud-compute/inspectingreleases https://security.apple.com/documentation/private-cloud-compu...
- gigel82 2y agoThat is a lot of mumbo-jumbo but what it boils down to is that you cannot run the PCC on your own hardware; you can download some "components" whose hash matches the supposed "transparency log" they publish (and some demo models) but since I can't go into my iPhone to say "set PCC server ip: 192.168.1.42" and see it work, I don't trust it (and it cannot be trusted).
- r00fus 2y ago> PCC is an awesome solution for Apple to ensure that no one other than Apple can execute code in that environment. Doesn't PCC guarantee even more than that? From my reading, Apple can't exfiltrate any data to other servers (even ones that Apple owns) nor can they inject any processing other than what is outlined into that server. Otherwise, what's the point of such a stringent hardware integrity requirement?
- gigel82 2y agoThere is no way to verify that. It's just something they "pinky swear they won't do". The stringent hardware integrity is to protect against supply chain attacks (Apple making sure they fully control the stack down to the hardware and can run any software they want that connects to any external service they desire - such as the CCP, NSA, 3rdPartyAds, etc.)