Private Cloud Compute: A new frontier for AI privacy in the cloud
21–30 of 393 posts
Re: Private Cloud Compute: A new frontier for AI privacy in the cloud
#22This entire platform is the first time I've strategically considered realigning the majority of my use to Apple. Airtag anonymity was pretty cool, technically speaking, but a peripheral use case for me. To me, PCC is a well-reasoned, surprisingly customer-centric response to the fact that due to (processing, storage, battery) limitations not all useful models can be run on-device. And they tried to build a privacy ar…
How so ? There are any number of state and state sponsored attackers who it should apply it including china, North Korea , Russia , Israel as nation states and their various affiliates like NSO group .
Even if NSA its related entities are going to be notably absent. If your threat model includes unfriendly nation state actors then the security depends on security at NSA and less on Apple, they have all your data anyway.
If nation state actors are interested in you, no smartphone that is not fully open source on both hardware and OS side that has been independently verified by multiple reviewers is worth it, i.e. no phone in the market today, everything else is tradeoff for convenience for risk, the degree of each is quite subjective to each individual.
For the rest of us, the threat model is advertisers, identity thieves, scammers and spammers and now AI companies using it for training.
Apple will protect against other advertisers insofar to grow their own ad platform , they already sell searches to Google for $20B/year and there is no knowing the details of the OpenAI deal on what kind of data will be shared.
Re: Private Cloud Compute: A new frontier for AI privacy in the cloud
#23(I wonder if Matt realizes nobody can read his tweets without a X account? Use BlueSky or Masto man)
Edit: here's his thread combined https://threadreaderapp.com/thread/1800291897245835616.html?...
Re: Private Cloud Compute: A new frontier for AI privacy in the cloud
#24I really want to see this OS, and have cautious optimism that this could be the first time we'll see a big tech company actually provide an auditable security guarantee! I think depending on how this plays out, Apple might manage to earn some of the trust its users have in it, which would be pretty cool! But even cooler will be if we get full chain-of-custody audits, which I think will have to entail opening up some…
> even if we can't verify that their sanctioned use case is secure, the cloud OS could be a great step forward in secure inference and secure clouds, which people could independently host or build an independent derivative of Yes, the tech industry loves to copy Apple :) Asahi Linux has a good overview of on-device boot chain security, https://github.com/AsahiLinux/docs/wiki/Apple-Platform-Secur... > My main concern…
Yes, most technology is built on other technology ;)
> This seems to imply that normal PCC nodes are bare-metal.
I realize that, but there's plausible deniability in it, especially since the modification could also hide the mechanism I've described in some other virtualization context that uses the unmodified image, without the statement being untrue
Re: Private Cloud Compute: A new frontier for AI privacy in the cloud
#25Re: Private Cloud Compute: A new frontier for AI privacy in the cloud
#26Can some ELI5 how remote attestation is supposed to work? It feels like asking a remote endpoint “are you who you say you are”. What’s stopping remote endpoint always responding “yes”
Re: Private Cloud Compute: A new frontier for AI privacy in the cloud
#27Some good comments on this from cryptographer Matt Green here: https://x.com/matthew_d_green/status/1800291897245835616?t=C... (I wonder if Matt realizes nobody can read his tweets without a X account? Use BlueSky or Masto man) Edit: here's his thread combined https://threadreaderapp.com/thread/1800291897245835616.html?...
> As best I can tell, Apple does not have explicit plans to announce when your data is going off-device for to Private Compute. You won't opt into this, you won't necessarily even be told it's happening. It will just happen. Magically.
Presumably it will be possible to opt out of AI features entirely, i.e. both on-device and off-device?
Why would a device vendor not have an option for on-device AI only? iOS 17 AI features can be used today without iCloud.
Hopefully Apple uses a unique domain (e.g. *.pcc.apple.com) that can be filtered at the network level.
Re: Private Cloud Compute: A new frontier for AI privacy in the cloud
#28I really want to see this OS, and have cautious optimism that this could be the first time we'll see a big tech company actually provide an auditable security guarantee! I think depending on how this plays out, Apple might manage to earn some of the trust its users have in it, which would be pretty cool! But even cooler will be if we get full chain-of-custody audits, which I think will have to entail opening up some…
> could be the first time we'll see a big tech company actually provide an auditable security guarantee AWS Nitro Enclaves [0] come close but of course what Apple has done is productize private compute for its 1b+ macOS & iOS customers! [0] https://docs.aws.amazon.com/enclaves/latest/user/nitro-encla...
Re: Private Cloud Compute: A new frontier for AI privacy in the cloud
#29A lot of this sounds like Apple has been 10-20 years behind the state of the art and now wants to tell you that they partially caught up. Verifiable hardware roots of trust and end-to-end software supply chain integrity are things that have existed for a while. The interesting part doesn't come until the end where they promise to publish system images for inspection.
Do you have analogous search terms for Microsoft, Alphabet, Google, and Amazon's approaches? Your comment makes me curious on how guarantee-to-guarantee looks (and associated architectures).
Re: Private Cloud Compute: A new frontier for AI privacy in the cloud
#30The absolute worst acronym for anything even remotely related to personal privacy.