4 ms·
> Wouldn't it be more accurate to call Apple's architecture data protection rather than privacy? As an European citizen in a post Snowden world I would be surpr
by JimDabell 4mo ago
> Wouldn't it be more accurate to call Apple's architecture data protection rather than privacy? As an European citizen in a post Snowden world I would be surprised if any of my data on Apple services was actually kept private from the US government, and Apple certainly wants to own a lot of data/metadata about you.
Your conception doesn’t seem to match PCC at all. The whole point of it is that nobody can access the data, not even the people running the servers.
https://security.apple.com/blog/private-cloud-compute/ https://security.apple.com/blog/private-cloud-compute/
- Geee 4mo agoThere's no guarantee against data exfiltration, because the data leaks happens through tool calls, which are not made from the PCC, but from your own device. E.g. "the user asks if their Bitcoin private key is unique, let's make a web search". Combined with prompt injection attacks, it's quite easy for an attacker to craft a prompt which sends your private data through any supported tool call (web search, database search, email, app APIs, etc.). Everything is wide open for the attacker / or yourself accidentally to exfiltrate your data.
- JimDabell 4mo agoThat doesn’t make sense in this context – the point of PCC is so you know somebody isn’t snooping on your information when you send it to the servers. The person I was responding to seemed to think that Apple would be looking at that information.
- Geee 4mo agoYou're right, but also "PCC is very secure" might give a false sense of security, considering that there might be other associated vulnerabilities in these kinds of systems.
- fragmede 4mo agoWhich is a good point. set a Bitcoin wallet private key in an obvious place on your system, and then setup a monitor (on another system) to notify you if its contents gets stolen. Doesn't prevent the exfiltration but at least you'll know when it does.
- shaky-carrousel 4mo agoAnd we have to believe that it's not backdoored because they say so? That's incredibly naïve.
- JimDabell 4mo agoNo. I provided the link so you could read more about it.
- 9dev 4mo agoI have read it. The entire trust hinges on several critical points, such as trusting secure boot. You remember when the NSA injected itself in TLS termination at all major cloud providers? You remember when several giant automotive corporations built elaborate detection of testing scenarios to fake emissions? You remember room 641A? I have no real way to tell if this is security Theater or meaningful protection. None of us has,
- shaky-carrousel 4mo agoThat's "because they said so" but with more words. Sorry, but a pretty blog post is not proof enough.
- Quothling 4mo agoI don't trust a single US tech company to keep my data private from the US government. Maybe I need a tinfoil hat, but I don't feel like I'm unjustified in this based on the history going back to echelon. Not that this is a particular jive at the USA, my own government (Danish) actively pushes for mass surveillance and non-functional e2e encryption. There is still a difference though. Google will sell my data and use it for all sorts of things. Though I've obviously accepted that since I have had a Samsung flip phone since Apple made their iPhones too big for my pockets.
- jesseendahl 4mo agoThis part of their requirements for how PCC is architected directly addresses your concern: “Verifiable transparency. Security researchers need to be able to verify, with a high degree of confidence, that our privacy and security guarantees for Private Cloud Compute match our public promises. We already have an earlier requirement for our guarantees to be enforceable. Hypothetically, then, if security researchers had sufficient access to the system, they would be able to verify the guarantees. But this last requirement, verifiable transparency, goes one step further and does away with the hypothetical: security researchers must be able to verify the security and privacy guarantees of Private Cloud Compute, and they must be able to verify that the software that’s running in the PCC production environment is the same as the software they inspected when verifying the guarantees.”
- criley2 4mo agoWhat does verify mean? Can they verify the private cloud is completely immune to nationstate actors, has no zero-day vulnerabilities, is completely bulletproof in a court of law and can never be compelled to secretly share info with government(s), etc? I think the users fear here is real. "We did good due diligence at the consumer level" and "we're completely immune to nationstate hackers and clandestine legal cases" are very different things.
- brookst 4mo agoYou should read the paper. Like any good security paper, it doesn’t assert immunity to particular parties. Instead, covers things like how PCC attests that the running software image is identical to the publicly-available, forensically-studied one. Fear is real for sure, but don’t let fear be an excuse to lose rigor in thinking.