Live data from Hacker News

Open Source Implementation of Apple's Private Compute Cloud

github.com

101–110 of 111 posts

Re: Open Source Implementation of Apple's Private Compute Cloud

#101

Earlier quoted context omitted.

> no one, not even people operating the inference hardware You need to be careful with these claims IMO. I am not involved directly in CoCo so my understanding lacks nuance but after https://tee.fail I came to understand that basically there's no HW that actually considers physical attacks in scope for their threat model? The Ars Technica coverage of that publication has some pretty yikes contrasts between quotes fro…

> I came to understand that basically there's no HW that actually considers physical attacks in scope for their threat model? xbox, playstation, and some smartphone activation locks. Of course, you may note those products have certain things in common...

Yeah that's a good point, I don't call that confidential compute though it's a different use case.

CoCo = protecting consumer data from the industry. DRM = protecting industry bullshit from the consumer.

TBF my understanding is that in the DRM usecases they achieve actual security by squeezing the TCB into a single die. And I think if anyone tries, they generally still always get pwned by physical attackers even though it's supposedly in scope for the threat model.

Re: Open Source Implementation of Apple's Private Compute Cloud

#102
post #72

Earlier quoted context omitted.

> no one, not even people operating the inference hardware You need to be careful with these claims IMO. I am not involved directly in CoCo so my understanding lacks nuance but after https://tee.fail I came to understand that basically there's no HW that actually considers physical attacks in scope for their threat model? The Ars Technica coverage of that publication has some pretty yikes contrasts between quotes fro…

Nvidia has been investing in confidential compute for inference workloads in cloud - that covers physical ownership/attacks in their thread model. https://www.nvidia.com/en-us/data-center/solutions/confident... https://developer.nvidia.com/blog/protecting-sensitive-data-...

It's likely I'm mistaken about details here but I _think_ tee.fail bypassed this technology and the AT article covers exactly that.

Re: Open Source Implementation of Apple's Private Compute Cloud

#103
post #88

Earlier quoted context omitted.

All things that were compromised with physical attacks? What are mod chips if not physical attack as a service?

I'm not aware of working jailbreaks for either Xbox Series or PS5. Its possible that's just a matter of time, but they've both been out for quite a while now it seems like the console manufacturers have finally worked out how to secure them.

Older firmware versions of PS5 are in fact jailbroken (google ps5 jailbreak and you’ll find a bunch of info). I’m not aware of any for Xbox Series but I think that’s more due to lack of interest and the fact that you can run homebrew in development mode already.

Re: Open Source Implementation of Apple's Private Compute Cloud

#104
post #94

Earlier quoted context omitted.

> would I actually run on it if I'm not a spammer? > Gimme an actual example instead of downvoting, help me learn. Basically you asked a bunch of people on a privacy minded forum, why should they be allowed to encrypt their data? What are you (they) hiding!? Are you a spammer??? Apple is beloved for their stance on privacy, and you basically called everyone who thinks that's more than marketing, a spammer. And before…

Seems I formulated my question in a way that wasn't clear. I specifically like the privacy aspect (even though honestly I think most people in this forum claim they do and yet they rely on BigTech with which they their data, so IMHO most people on HN are not as demanding as you describe) the question is precisely about what to run. FWIW I specifically keep a page on self hosting AI (you can check if you want to see i…

Okay, so you had a whole agenda. Could have just been more transparent if you came out and said that directly.

It's an LLM. The user can ask it anything they can think of! But then to to "only spammers could eke out anything from them".

What do users ask OpenAI about? My boyfriend/girlfriend/wife/mistress cheated on me, what should I do? My mom is... My dad is... My friends are.. I have this problem with this company and I want to sue them... I have this weird lump on my foot... More nefariously, I'm sure someone out there asking "how do I make cocaine" is seriously considering it, and not just testing the machine. I want to talk to somebody about 1994, the TV series from 2019. I want to write a fiction book about the near future but one where I won the lottery or I grew up rich or I was Harry Potter or a murder mystery or utopian sci-fi or dystopian sci-fi or an alt-history where there are still dinousaurs or or or.

I don't know if it's a failure of your imagination, or if mine is overactive, but making a venn diagram of all the world's humans broken down into spammers and not spammers, and then placing the circle users of local LLMs inside of spammers, and there's no one else, just seems a bit reductive.

Re: Open Source Implementation of Apple's Private Compute Cloud

#105
post #21
post #9

Earlier quoted context omitted.

I read this and your reply to the sibling, you seem to have reputation to be sensible - what are you trying to say? If someone re-implements or reverses a service then it doesn't need to be in the same language.

Pedantic yes, sensible not really, sensible folks don't survive the level of BBS and USENET discussion forums. To make a full implementation of a Apple product, the specification for that Apple product must exist in some form.

Right, but whatever the languages used by Apple to implement their cloud is not really related to the Swift language. I guess you should have said what you said just now first.

Re: Open Source Implementation of Apple's Private Compute Cloud

#106

Earlier quoted context omitted.

> I.e.: If the security/privacy guarantees really are as advertised, then ipso facto someone could store child porn in the system and the provider couldn't detect this. But what they would be storing in this case is not illegal content. Straight up. Encrypted bits without a key are meaningless. There is nothing stopping a criminal from uploading illegal content to Google drive as an encrypted blob. There's nothing Go…

You're simply wrong about this. "I don't know the key" is not legal defense even against hosting an encrypted blob of copyright infringing contemt, much less an encrypted blob of illegal pornography.

If this were the case nobody would ever offer file hosting services (eg. Google Drive). Do you have any case history to show any company getting prosecuted for unknowingly hosting encrypted blobs of illegal material?

Obviously if they have to ability to know material is illegal, that's a problem.

And exactly what algorithm can you provide to me that takes an encrypted blob as an input and returns whether it is not illegal material. Clearly that doesn't exist, so your point makes zero sense.

You may be conflating "I forgot the key" vs "I've never been provided the key"

Re: Open Source Implementation of Apple's Private Compute Cloud

#107
post #92

Earlier quoted context omitted.

A company of what country would you prefer? Everyone likes to dunk on the US, but I doubt you could provide a single example of a country that is certainly a better alternative (to be clear I believe many of the west up in the same boat).

A European one. Pulling the kind of tricks the NSA does is considerably harder if you don’t have a secret court with secret orders.

You might want to look into what GCHQ, DGSE, and BND (as examples) actually do. Europe is not some surveillance-free zone.

Re: Open Source Implementation of Apple's Private Compute Cloud

#108

Earlier quoted context omitted.

You're simply wrong about this. "I don't know the key" is not legal defense even against hosting an encrypted blob of copyright infringing contemt, much less an encrypted blob of illegal pornography.

If this were the case nobody would ever offer file hosting services (eg. Google Drive). Do you have any case history to show any company getting prosecuted for unknowingly hosting encrypted blobs of illegal material? Obviously if they have to ability to know material is illegal, that's a problem. And exactly what algorithm can you provide to me that takes an encrypted blob as an input and returns whether it is not il…

I think you misunderstand jiggawatt, who wasn't talking about unknowingly hosting illegal material.

We're talking about knowingly hosting encrypted illegal material without knowing the key. This is unambiguously illegal whether or not you ever knew the key.

If the police show up and tell you that your site has an encrypted zip file containing illegal porn, of course they can instruct you to stop hosting it, and hold you liable if you refuse to follow those instructions.

They're not going to give you the decryption key to check for yourself, and it'd not even be legal for them to do so.

Jiggawatt is saying that if you have a truly uncensorable system, it's impossible to comply with the police instructions to selectively remove the illegal material, and so the whole thing becomes illegal.

> And exactly what algorithm can you provide to me that takes an encrypted blob as an input and returns whether it is not illegal material. Clearly that doesn't exist, so your point makes zero sense.

This on the other hand, tells me you don't know much about how legal systems work. I recommend you start with the essay "What color are your bits?" [1]

[1] https://ansuz.sooke.bc.ca/entry/23

Re: Open Source Implementation of Apple's Private Compute Cloud

#109

Earlier quoted context omitted.

If this were the case nobody would ever offer file hosting services (eg. Google Drive). Do you have any case history to show any company getting prosecuted for unknowingly hosting encrypted blobs of illegal material? Obviously if they have to ability to know material is illegal, that's a problem. And exactly what algorithm can you provide to me that takes an encrypted blob as an input and returns whether it is not il…

I think you misunderstand jiggawatt, who wasn't talking about unknowingly hosting illegal material. We're talking about knowingly hosting encrypted illegal material without knowing the key. This is unambiguously illegal whether or not you ever knew the key. If the police show up and tell you that your site has an encrypted zip file containing illegal porn, of course they can instruct you to stop hosting it, and hold…

I'm not sure I agree that OCs argument was focused on knowing that you were hosting illegal material that is encrypted. I'd argue that no-where in jiggawatt's comment is that argued. I think that's your argument, which is fine, and I agree with that. I also agree that you can be compelled to remove data, encrypted or not from your servers through lawful orders and if your system is designed in a blockchain like manner where it is not possible to remove illegal content, that's an even bigger issue.

My point all along, is that Google is not liable for someone uploading previously encrypted blobs of illegal content to Google Drive. And even more so, Google isn't liable if someone uploads illegal content to Google Drive that isn't encrypted. Google simply needs to remove it and follow the correct processes if reported / detected.

Could you make an argument for either that theoretically they could be? Sure. But in reality, no, they are not liable.

This is law due to Section 230:

> Section 230 of the Communications Act of 1934, enacted as part of the Communications Decency Act of 1996, provides limited federal immunity to providers and users of interactive computer services. The statute generally precludes providers and users from being held liable—that is, legally responsible—for information provided by another person, but does not prevent them from being held legally responsible for information that they have developed or for activities unrelated to third-party content. Courts have interpreted Section 230 to foreclose a wide variety of lawsuits and to preempt laws that would make providers and users liable for third-party content. For example, the law has been applied to protect online service providers like social media companies from lawsuits based on their decisions to transmit or take down user-generated content.

https://www.congress.gov/crs-product/R46751 https://www.eff.org/issues/cda230

Also, the blockchain problem already exists. I've linked some commentary about it.

https://ethereum.stackexchange.com/questions/94558/what-prev...

Re: Open Source Implementation of Apple's Private Compute Cloud

#110

Earlier quoted context omitted.

> the inference provider still has the ability to access the prompt and response plaintext Folks may underestimate the difficulty of providing compute that the provider “cannot”* access to reveal even at gunpoint. BYOK does cover most of it, but oh look, you brought me and my code your key, thanks… Apple's approach, and certain other systems such as AWS's Nitro Enclaves, aim at this last step of the problem: - https:…

> 3. There is no mechanism for a cloud service provider employee to access customer content stored on instance storage and encrypted EBS volumes. Are you telling me customer services can't reset a customer's forgotten console login password?

In these systems secured to this degree, yes.
Post reply on HN