Live data from Hacker News

Private Cloud Compute: A new frontier for AI privacy in the cloud

security.apple.com

191–200 of 393 posts

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#191
post #160

Earlier quoted context omitted.

Thanks for the link. > As best I can tell, Apple does not have explicit plans to announce when your data is going off-device for to Private Compute. You won't opt into this, you won't necessarily even be told it's happening. It will just happen. Magically. Presumably it will be possible to opt out of AI features entirely, i.e. both on-device and off-device? Why would a device vendor not have an option for on-device A…

Almost certainly you will be able to disable it entirely and hide the UI to re-enable it via provisioning profiles via Apple Configurator 2 or MDM. This is actually what you have to do now if you don’t want Siri and Mail to leak your address book to Apple.

> if you don’t want Siri and Mail to leak your address book to Apple.

By disabling Siri and iCloud, or other policies?

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#192
post #78

It is not possible for this to be fully private in the United States because the government not only can force Apple to open up the kimono, it can also forbid it to talk about it. There’s not really anything Apple can do to work around this “limitation”. Thank your “representative” for extending the PATRIOT Act when you get a chance.

Private Cloud Compute servers have no persistent storage so there would be nothing to see upon opening the kimono. You'd need some sort of government requested live wire tap thing to harvest the data out of the incoming requests, which might be a different situation. I'm, of course, just some dude on the internet, thinking up a counter-point to this concern, who knows if I am even remotely in the right ballpark.

> have no persistent storage

How often do PCC servers reboot and wipe the temporary encryption key?

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#193

The thing with cloud and with anything related to it, anything that connects to the internet somehow... is that, unless it's open source and the servers decentralized, you are always trusting SOMEONE. Sure, Apple might make their best to ensure nobody – but them – have access to your data... but Apple controls all the end points. It controls the updates your iPhone receives, it controls the servers where this happens…

> unless it's open source and the servers decentralized, you are always trusting SOMEONE Specifically, open-source and self-hostable . Open source doesn't save you if people can't run their own servers, because you never know whether what's in the public repo is the exact same thing that's running on the cloud servers.

This is what the “attestation” bit is supposed to take care of—if it works, which I’m assuming it will, because they’re open sourcing it for security auditing.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#194

The thing with cloud and with anything related to it, anything that connects to the internet somehow... is that, unless it's open source and the servers decentralized, you are always trusting SOMEONE. Sure, Apple might make their best to ensure nobody – but them – have access to your data... but Apple controls all the end points. It controls the updates your iPhone receives, it controls the servers where this happens…

> unless it's open source and the servers decentralized, you are always trusting SOMEONE Specifically, open-source and self-hostable . Open source doesn't save you if people can't run their own servers, because you never know whether what's in the public repo is the exact same thing that's running on the cloud servers.

> exact same thing that's running on the cloud servers

What runs on the servers isn't actually very important. Why? Becuase even if you could somehow know with 100% certainty that what a server runs is the same code you can see, any provider is still subject to all kinds of court orders.

What matters is the client code. If you can audit the client code (or better yet, build your own compatible client based on API specs) then you know for sure what the server side sees. If everything is encrypted locally with keys only you control, it doesn't matter what runs on the server.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#195
Many people in this thread are extremely cynical and also ignorant of the actual security guarantees. If you don’t think Apple is doing what they say they’re doing, you can go audit the code and prove it doesn’t work. Apple is open sourcing all of it to prove it’s secure and private. If you don’t believe them, the code is right there.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#197

Earlier quoted context omitted.

Is there more to that thread? I can't read it if it exists, not sure if that is what the parent is talking about? But i don't have a Twitter account anymore, so maybe it's locked?

Without being logged into X, you can only see the first post in a thread.

Not even that anymore, all links show is "Something went wrong, but don’t fret — let’s give it another shot."

Impossible to see any content.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#200

Earlier quoted context omitted.

I don't know what you're seeing. It's a very long thread. Exceptionally good take on the whole thing. Apple has gone way out of their way to try and sell this thing. Above and beyond compared to how I imagine Microsoft or Google would have tackled this.

If your AI model sucks, you have to use other gimmicks to lure customers. That's marketing 101. Create irrational fear about piracy, push privacy focused products and profits as the sheeple promptly fall for this

I've never seen someone use "sheeple" in an anti-privacy argument.
Post reply on HN