Live data from Hacker News

Private Cloud Compute: A new frontier for AI privacy in the cloud

security.apple.com

141–150 of 393 posts

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#141
post #23

Some good comments on this from cryptographer Matt Green here: https://x.com/matthew_d_green/status/1800291897245835616?t=C... (I wonder if Matt realizes nobody can read his tweets without a X account? Use BlueSky or Masto man) Edit: here's his thread combined https://threadreaderapp.com/thread/1800291897245835616.html?...

"I wonder if Matt realises nobody can read his tweets without a X account?"

https://nitter.poast.org/matthew_d_green/status/180029189724...

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#142
post #78

It is not possible for this to be fully private in the United States because the government not only can force Apple to open up the kimono, it can also forbid it to talk about it. There’s not really anything Apple can do to work around this “limitation”. Thank your “representative” for extending the PATRIOT Act when you get a chance.

Slightly off-topic, "open up the kimono" sounds disturbing and creepy to me as an Asian. I suspect I'm not alone in this.

That’s even better. I do think it’s disturbing and creepy when someone goes through my private data without my knowledge.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#143
post #78

It is not possible for this to be fully private in the United States because the government not only can force Apple to open up the kimono, it can also forbid it to talk about it. There’s not really anything Apple can do to work around this “limitation”. Thank your “representative” for extending the PATRIOT Act when you get a chance.

Slightly off-topic, "open up the kimono" sounds disturbing and creepy to me as an Asian. I suspect I'm not alone in this.

Some share your sentiment. https://www.npr.org/sections/codeswitch/2014/11/02/360479744...

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#144
post #136
post #129

Read through it all, it still comes down to "trust us". Apple can sign and authorise an update at any time that will backdoor it, and the government is the stroke of a pen away from forcing them to, all completely silently. I get that there's benefit to what they are doing. But the problem of selling a message of trust is you absolutely have to be 100% truthful about it, and them failing to be transparent that people…

They already have root. Their software is closed source. There is absolutely nothing stopping them from uploading all of your data right now. If you don't trust the people making your OS, your problems are much deeper than fretting about off-device AI processing.

While true, the gap between "we send your data to our datacenters but we don't look at it" to "we look at it a little bit without telling you" is much smaller than "we leave your data on your device alone" to "we upload data from your device", both on a technical and policy level.

Even if the org has been trustworthy to this point, I think this step makes it more likely (maybe still unlikely, but more likely) that in the future they do look at your data, as less things have to change for that to happen.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#145
post #136

Earlier quoted context omitted.

They already have root. Their software is closed source. There is absolutely nothing stopping them from uploading all of your data right now. If you don't trust the people making your OS, your problems are much deeper than fretting about off-device AI processing.

That's true, but also it should be possible to make an OS that people can trust without trusting you, and as users we should encourage movement in that direction.

> should be possible

What makes you think this?

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#147
I'm interested in how this compares to AWS nitro enclaves, which they mention briefly.

The main difference seems to be verifiability down to the firmware level.

Nitro enclaves does not provide measurements of the firmware[0], or hypervisor, furthermore they state that the hypervisor code can be updated transparently at any time[1].

Apple is going to provide images of the secure enclave processor operating system(sepOS), as well as the bootloader.

It also sounds like they will provide the source code for these components too, although the blog post isn't clear on that.

[0]: https://docs.aws.amazon.com/enclaves/latest/user/set-up-atte....

[1]: https://docs.aws.amazon.com/pdfs/whitepapers/latest/security...

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#148
post #136

Earlier quoted context omitted.

They already have root. Their software is closed source. There is absolutely nothing stopping them from uploading all of your data right now. If you don't trust the people making your OS, your problems are much deeper than fretting about off-device AI processing.

That's true, but also it should be possible to make an OS that people can trust without trusting you, and as users we should encourage movement in that direction.

Good luck. It’s much easier to talk about it. The last open OS I have seen reach a semi-mainstream level of adoption was started in the early 90’s, more than 30 years ago, by some Linus guy.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#149
post #136

Earlier quoted context omitted.

They already have root. Their software is closed source. There is absolutely nothing stopping them from uploading all of your data right now. If you don't trust the people making your OS, your problems are much deeper than fretting about off-device AI processing.

That's true, but also it should be possible to make an OS that people can trust without trusting you, and as users we should encourage movement in that direction.

I understand the sentiment, but it's impractical to live in a trust-less society. If you've ever had dental work done, you've put an awful lot of faith in a stranger pushing a drill into your head. Ditto for riding buses and bus drivers, etc etc.

Trust can be abused, certainly, but it also allows collaboration and specialisation, and without those I doubt we'd have gotten very far.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#150
post #136
post #129

Read through it all, it still comes down to "trust us". Apple can sign and authorise an update at any time that will backdoor it, and the government is the stroke of a pen away from forcing them to, all completely silently. I get that there's benefit to what they are doing. But the problem of selling a message of trust is you absolutely have to be 100% truthful about it, and them failing to be transparent that people…

They already have root. Their software is closed source. There is absolutely nothing stopping them from uploading all of your data right now. If you don't trust the people making your OS, your problems are much deeper than fretting about off-device AI processing.

That's true, but if you don't update your local software and it isn't currently backdoored, then it won't magically become backdoored without some active involvement somewhere. The trouble with remotely pushing data somewhere is that you can't tell if anything has changed even if you wanted to. (Attestation only works if it's not compromised, and for obvious reasons, there's no way to know that an attestation mechanism is compromised.)

That said I really don't disagree with this point at all in terms of it being a valid problem. It's not a fixable problem either (it comes down to, again, building trustworthy computers) but it could be biased way towards being solved whereas today it is still "trust me bro". I don't think Apple will be the company to make progress towards this, though.

Post reply on HN