Live data from Hacker News

Apple reveals new AI architecture built around Google Gemini models

macrumors.com

511–520 of 609 posts

Re: Apple reveals new AI architecture built around Google Gemini models

#513

Earlier quoted context omitted.

I don't trust a single US tech company to keep my data private from the US government. Maybe I need a tinfoil hat, but I don't feel like I'm unjustified in this based on the history going back to echelon. Not that this is a particular jive at the USA, my own government (Danish) actively pushes for mass surveillance and non-functional e2e encryption. There is still a difference though. Google will sell my data and use…

This part of their requirements for how PCC is architected directly addresses your concern: “Verifiable transparency. Security researchers need to be able to verify, with a high degree of confidence, that our privacy and security guarantees for Private Cloud Compute match our public promises. We already have an earlier requirement for our guarantees to be enforceable. Hypothetically, then, if security researchers had…

They do this by allowing you to download all of the components (minus data cryptexes containing the model weights) and run it on your own Apple silicon chip (you can put your computer in recovery mode and use csrutil to enable research guest operating systems)

I think what is concerning is that they are expanding into Google Cloud and NVIDIA to run with it too with their versions of confidential compute, which if I remember correctly are not as well verified as Apple PCC and a little harder for researchers to get their hands on.

Apple uses a key ceremony process where no single party has access to all the keys required to sign hardware, meaning in theory they can’t just sign malicious hardware. However, I’m not sure how Google and NVIDIA play into this and I don’t think they’ve provided much detail on it. I think it seems a little rushed to get the features out since they fucked up with initial Apple Intelligence release.

Re: Apple reveals new AI architecture built around Google Gemini models

#514
post #334

Earlier quoted context omitted.

They are using Google Cloud. https://security.apple.com/blog/expanding-pcc/?linkId=100000... "Now, we are collaborating with Google and NVIDIA to run new Apple Intelligence workloads on Google Cloud, extending our industry-leading PCC privacy commitments to third-party data centers for the first time."

Per that link: I think there's an interesting question about whether a nefarious actor who's infiltrated a cloud provider with physical access to machines that are running signed operating systems, with signed binaries, with TDX remote attestation, and with hardware supply chain verification, has the ability to break the privacy guarantees of a tenant with Apple's sophistication. Certainly, one could tamper with the…

>nefarious actor who's infiltrated a cloud provider

Google is buying that compute from xAI aka Musk

Re: Apple reveals new AI architecture built around Google Gemini models

#515
Just an interesting thought on the very different philosophical approaches. Let's imagine that Android had a terrible assistant, so bad that even most Google Fanbois admitted it was pretty bad. Apple became a leader in AI. Google approaches them to license the Siri model for Android. Would Apple have ever done that?

Re: Apple reveals new AI architecture built around Google Gemini models

#517
post #334

Earlier quoted context omitted.

Per that link: I think there's an interesting question about whether a nefarious actor who's infiltrated a cloud provider with physical access to machines that are running signed operating systems, with signed binaries, with TDX remote attestation, and with hardware supply chain verification, has the ability to break the privacy guarantees of a tenant with Apple's sophistication. Certainly, one could tamper with the…

Those datacentres would be in the same position of trust as a VPN provider in that the data must be unencrypted at points in the process. They could be making it very safe, and the things apple says they are doing would make it as safe as possible, but as a user there is no way of verifying the claims.

> as a user there is no way of verifying the claims

I think this sums up what it's like to be an Apple user pretty well. With their heavy proprietary and closed approach, all users can do is "trust" them.

Re: Apple reveals new AI architecture built around Google Gemini models

#518

Earlier quoted context omitted.

What does verify mean? Can they verify the private cloud is completely immune to nationstate actors, has no zero-day vulnerabilities, is completely bulletproof in a court of law and can never be compelled to secretly share info with government(s), etc? I think the users fear here is real. "We did good due diligence at the consumer level" and "we're completely immune to nationstate hackers and clandestine legal cases"…

You should read the paper. Like any good security paper, it doesn’t assert immunity to particular parties. Instead, covers things like how PCC attests that the running software image is identical to the publicly-available, forensically-studied one. Fear is real for sure, but don’t let fear be an excuse to lose rigor in thinking.

This is a non-answer, and in fact, a statement like "don't let fear be an excuse to lose rigor in thinking" in response to my question "how verifiable are their claims" is insulting and sloppy. Rigor in thinking includes human discussion and humans asking questions, but yet you shot that down.

ChatGPT, do what this user wouldn't, and answer the dang question:

> No, Apple cannot verify that Private Cloud Compute is completely immune to nation-state actors, contains no zero-days, or could never be subjected to secret legal compulsion. Nobody can honestly establish those absolutes for a complicated, evolving computer system operating across multiple jurisdictions.

> What Apple has done is more meaningful than ordinary corporate “due diligence,” however. PCC is specifically engineered to make clandestine access—whether by hackers, insiders, or governments—technically difficult, difficult to target, and more likely to leave externally detectable evidence...

> Against ordinary attackers, rogue employees, conventional cloud administrators and routine government data requests, PCC appears exceptionally strong for a cloud AI service.

> Against a targeted nation-state willing to combine zero-days, supply-chain compromise, endpoint exploitation, legal pressure and secrecy, the right description is: Highly resistant, deliberately difficult to target, and unusually auditable—but not immune.

Thanks ChatGPT. Don't know why I bother to ask humans anymore, it's StackOverflow the whole way down.

Re: Apple reveals new AI architecture built around Google Gemini models

#519

Earlier quoted context omitted.

I agree that many AI businesses will go bust and they deserve it, but the tech is good. I can recommend my own layered approach, using the lowest capability models that get stuff done: 1. I maximally use local models like gemma4:26b-a4b-it-qat for everything that works with this free option. 2. I like paying for inexpensive APIs for mid-tier models like deepseek v4 flash, gcp-5-mini, gemini-2-flash for things that op…

I think you are conflating LLMs with AI. LLMs we all agreed were amazing back in 2023-2024. What's happening now with AI is more of a corporate phenomenon quite removed from the actual tech. Yes LLMs are useful, but replacing customer support with an LLM that gives user accounts away, or calling LLMs on a loop where the bottleneck is your checkbook and calling it AGI, those are phenomenons that are separate from LLMs…

We agree more than you may believe. I have worked in the field of AI since the early 80s, symbolic AI, simpler neural networks. I only believe in using any tech if it serves human needs, is privacy preserving, etc.

Re: Apple reveals new AI architecture built around Google Gemini models

#520
post #443

Earlier quoted context omitted.

The better use case would be to make AI cancel that damn subscription that lets you jump through 20 dark pattern questions and then tells you to call customer support.

And you end up with a new subscription the LLM was tricked into accepting

Great news: I was able to score you 10% off the next 12 months on your subscription!
Post reply on HN