3 ms·
But that does have to do with privacy. Apple wants to implement features that access data locally. It doesn’t want to allow competition for offering those feat
by bnj 4mo ago
But that does have to do with privacy.
Apple wants to implement features that access data locally. It doesn’t want to allow competition for offering those features, but if it did, competitors may use that access to local data to exfiltrate.
So it is about both competition and, as a result of creating competition, privacy.
- FinnKuhn 4mo agoApple is using Cloud compute as well to enable Siri AI. If you want to you could still use Apple or another provider you decide to trust - or even one that does everything locally. The competition would still have to follow GDPR after all.
- theshrike79 4mo agoApple PCC has been independently audited to be ultra secure. Will the EU enforce the same for 3rd party integrations?
- FinnKuhn 4mo agoIf Apple had e.g. required competitors to undergo similar independent audits that would probably be allowed as it is quite similar to how Apple solved the third party app store issue.
- MBCook 4mo agoAre we sure the EU would allow that? Or would it be seen as a way to stifle competition?
- bigyabai 4mo agoI mean, Apple's PCC audits require them to individually vet each auditor before they're allowed to see the PCC nodes. If Apple extended that philosophy to other vendors then yeah, it would be deliberately unfair and anticompetitive.
- MBCook 4mo agoIt sounds like they are whitelisting the hashes of all the Google software and OSes and stuff to ensure nothing is changed out from under them without them knowing. Even if you could make all the other possible vendors run private cloud compute style stuff that would be a lot to manage. And I can’t imagine the EU would like, and as a user I would certainly hate, the “OK you can use Grok but you lose all privacy too bad“ dialogue box they could make.
- bigyabai 4mo agoI don't even think it offers a meaningful degree of security. It's a form of theater, you have to be hand-selected to perform the audit that Apple promised. Most sysadmins know that hash matching only mitigates a small subset of rare upstream attacks. Apple could still be MITMing the whole thing (SSL added and removed here :)) and no auditor would get the chance to check. The offered audit is so weak that I would not trust any FAANG business to administrate it. Apple is once again demanding arbitrary centralization to give them an undeserved veto power. None of this is for security.
- theshrike79 4mo agoIf they're not "hand-selected", what would be the way to select the auditors? Just have an open house for anyone interested to come poke the hardware and software?
- bigyabai 4mo agoHave a set of clearly-defined requirements that doesn't randomly reject valid candidates? Nobody wants another opaque system like the App Store review process. By the sound of it, Apple's offered audit doesn't include insight into the most dangerous parts of a system like this. This could easily lead to a situation where real security experts are denied access to promote influencer-adjacent Yes Men who rubberstamp the hashes matching without any question. Hence my concern for "SSL added and removed here" - none of Google's famously backdoored infrastructure will be audited. For privacy purposes, Apple's promise is woefully incomplete.
- flopbob 4mo agoThis is mostly wrong. The DMA has a process to determine if a service provider acts a gatekeeper to the market, and let's be honest if Apple is not one, then I don't know who else besides Google.. So there is no privacy argument in there except Apple didn't want to design a interface that complies and is safe.
- alt227 4mo agoThats what Apple wants you to think. In reality it has nothing to do with privacy. Apple could let 3rd parties tap into these APIs but only after the user clicks away a big scary message telling the user they are leaving the comfort of the apple curated garden. This allows competition, but also allows privacy for those who want it. See? Simple really, but Apple being Apple dont want to let 3rd parties use its AI APIs and so we have this standoff.
- bnj 4mo agoBig scary warnings aren’t a solution either. I watch the way my son interacts with consent screens and warnings, and it’s barely believable- the average person is very well trained to click through the warnings. Someone might believe that people who ignore the warnings deserve everything they get, but I respectfully disagree. I remember helping my grandma uninstall and remove all the hostile browser extensions that had tricked her into installing them. If Apple is protecting vulnerable populations by taking the choice out of the users hands, even if it’s only profit motivated, I’m okay with that until someone presents an alternative that actually addresses those needs.
- hananova 4mo agoApple is very good at “big scary warnings” that are also quite difficult to click through without knowing the correct steps to take. See also the EU alternative app stores, or running an unsigned app on macOS, or installing a device profile…