4 ms·
> Their answer to that is "you can audit us", but I don't see how that would prevent them from switching things in between audits. PCC does actually prevent Ap
by abalone 2y ago
> Their answer to that is "you can audit us", but I don't see how that would prevent them from switching things in between audits.
PCC does actually prevent Apple from switching things in between audits to a high degree. It’s not like a food safety inspection. The auditor signs the hardware in a multi party key ceremony and they employ other countermeasure like chassis tamper switches. PCC clients use a protocol that ensures whatever they are connecting to has a valid signature. This is detailed in Apple’s documentation.[1]
See, this is why I think privacy engineering is low key the most cutting edge aspect of server development. Previously held axioms are made obsolete by architectural advancements. I think we’re looking at a once in 15 year leap - the previous ones being microservices and web based architecture.
[1] https://security.apple.com/documentation/private-cloud-compute/hardwareintegrity https://security.apple.com/documentation/private-cloud-compu...