Live data from Hacker News

Private Cloud Compute: A new frontier for AI privacy in the cloud

security.apple.com

241–250 of 393 posts

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#241
post #238

Earlier quoted context omitted.

Usually this is done the other way around - servers verifying client devices using a chip the manufacturer put in them and fully trusts. They can trust it, because it's virtually impossible for you (the user) to modify the behavior of this chip. However, you can't put something in Apple's server. So if you don't trust Apple, this improves the trust by... 0%. Their device says it's been attested. Has it? Who knows? Th…

Usually the attestation systems operate on neither side having everything to compute a result that will match attestation requirements, and thus require that both server-side and client-side secret are involved in attestation process. The big issue with Apple is that their attestation infrastructure is wholly private to them, you can't self-host (Android is a bit similar in that application using Google's attestation…

Attestation requires a root of trust, i.e. if data hashes are involved in the computation, you have to be able to trust that the hardware is actually using the real data here. Apple has this for your device, because they built it. You don't have it for their server, making the whole thing meaningless. The maximum information you can get out of this is "Apple trusts Apple".

Under the assumption that Apple is telling the truth about what the server hardware is doing, this could protect against unauthorized modifications to the server software by third parties.

If however, we assume Apple itself is untrustworthy (such as, because the US government secretly ordered them to run a different system image with their spyware installed) then this will not help you at all to detect that.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#242
post #171

Who pays for the costs of private cloud compute, is it free of charge for the iPhone owner (at least until they turn it into a subscription)? What about second hand iPhone users?

Exactly - nothing is for free. They explicitly state that PCC data gets destroyed after a response is returned.

Are the anonymized queries (minus user data context) worth anything?

It’s gotta be some kind of subscription/per query charge model to pay for the servers, electricity, and bandwidth.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#243

Earlier quoted context omitted.

The best protection against "secret orders" is to use mathematics. Build your system so that it can't be decrypted, don't log anything etc. Mullvad has been doing this with VPNs and law enforcement has tested it - there's nothing for them to get. Same has been proven with Apple not allowing FBI to open an iPhone, because it'd set a precedent. Future iPhone versions were made so that it's literally impossible for even…

> Same has been proven with Apple not allowing FBI to open an iPhone, because it'd set a precedent. Future iPhone versions were made so that it's literally impossible for even Apple to open a locked iPhone. Right, but I have no reason to think that this isn't a marketing ploy either, just another story. There is simply no way that Apple is as big as it is, without providing whatever data the government requires. Corp…

Apple will obey government orders to give data they have and can access.

No government order short of targeting a specific backdoored update to a specific person will allow them to give data they can't access.

And if you're doing something that can make a TLA force Apple to create a targeted iOS update just for you, it's not something regular people can or should worry about.

Apple keeps normal people safe from mass surveillance, being protected from CIA/NSA required going Full Snowden and it's not a technological problem, you need to change the way you live.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#244
post #77

I was sceptical of the announcement, but this actually sounds really well thought out. One key part though will be the remote attestation that the servers are actually running what they say they're running. Without any access to the servers, how do we do that? Am I correctly expecting that that part remains a "trust me bro" situation?

Attestation will run on the RoT. >While we’re publishing the binary images of every production PCC build, to further aid research we will periodically also publish a subset of the security-critical PCC source code. I expect that they'll publish the attestation source code. But, basically what will happen is the Verifier will request a certain memory region to be attested, then that region will be hashed and the diges…

[deleted]

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#245
This is Confidential Computing https://en.m.wikipedia.org/wiki/Confidential_computing

with another name. Intel, AMD and Nvidia have been working for years on this. OpenAI released a blog some time ago where they mentioned this as the "next step". Exciting that Apple went ahead and deployed first, it will motivate the rest as well.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#247
post #221

Wow! This is incredibly exciting. Apple's Private Cloud Compute seems to be conceptually equivalent with System Transparency - an open-source software project my colleagues and I started six years ago. I'm very much looking forward to more technical details. Should anyone at Apple see this, please feel free to reach out to me at stromberg@mullvad.net. I'd be more than happy to discuss our design, your design, and/or…

https://en.m.wikipedia.org/wiki/Confidential_computing

This is what they are doing. Search implementations of this to understand more technical details.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#248
post #235

Earlier quoted context omitted.

The stories about Apple keeping things secret usually go about protecting their business secrets from normal people, up to doing probably illegal actions. Using deniable, one-time keys etc. are... not that unusual. In fact I'd say I'm more worried about the use of random USB keys there instead of proper KMS system. (There are similar stories with how doing a cold start can be difficult when you end up with a loop in…

they used smartcards, not usb keys

Which probably were just key transport devices from offline secured KMSes

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#249
post #221

Wow! This is incredibly exciting. Apple's Private Cloud Compute seems to be conceptually equivalent with System Transparency - an open-source software project my colleagues and I started six years ago. I'm very much looking forward to more technical details. Should anyone at Apple see this, please feel free to reach out to me at stromberg@mullvad.net. I'd be more than happy to discuss our design, your design, and/or…

Yeah it seems so, though most of these systems (e.g. Intel SGX, AMD SEV, NVIDIAs new tech) use the same basic building blocks (Apple itself isn't member of the confidential computing consortium but ARM is), for me it's the quality of the overall implementation and system that sets this apart. I'm also quite bullish about trusted computing, seems it gains significant momentum. I would like some technologies to be more open and e.g. allow you to control the whole stack and install your own root certificates / keys on a hardware platform, but even so I think it can provide many benefits. With Apple pushing this further into the mainstream I expect to see more adoption.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#250

Earlier quoted context omitted.

> Same has been proven with Apple not allowing FBI to open an iPhone, because it'd set a precedent. Future iPhone versions were made so that it's literally impossible for even Apple to open a locked iPhone. Right, but I have no reason to think that this isn't a marketing ploy either, just another story. There is simply no way that Apple is as big as it is, without providing whatever data the government requires. Corp…

Apple will obey government orders to give data they have and can access. No government order short of targeting a specific backdoored update to a specific person will allow them to give data they can't access. And if you're doing something that can make a TLA force Apple to create a targeted iOS update just for you, it's not something regular people can or should worry about. Apple keeps normal people safe from mass…

Do you not remember Edward Snowden? Eg this sort of info:

> The scandal broke in early June 2013, external when the Guardian newspaper reported that the US National Security Agency (NSA) was collecting the telephone records of tens of millions of Americans.

> The paper published the secret court order directing telecommunications company Verizon to hand over all its telephone data to the NSA on an "ongoing daily basis".

https://www.bbc.com/news/world-us-canada-23123964

You seem to think that 10 years, under cover of secret orders, that this is NOT going on now. Not Apple!

People's lovely trusting natures in corporations and government never ceases to amaze me.

Post reply on HN