Live data from Hacker News

Private Cloud Compute: A new frontier for AI privacy in the cloud

security.apple.com

271–280 of 393 posts

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#271
post #145

Earlier quoted context omitted.

That's true, but also it should be possible to make an OS that people can trust without trusting you, and as users we should encourage movement in that direction.

> should be possible What makes you think this?

It’s especially funny because I believe it is provably impossible. You’ll have to trust me that I’ve done the proof.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#272

Earlier quoted context omitted.

It's completely fair, because regardless of third party audits, chips, etc, there are backdoors right along the line, that are going to provide Apple and the government with secret legal access to your data. They can simply go to a secret court, receive a secret judgment, and be authorised to secretly view your data. Does anyone really think this is not already the case? There is no transparency. A licensed third par…

If you’re presenting a conspiracy theory, you have to at least poke holes in the claims you consider false. Under the system described in the linked paper, your scenario is not possible. In fact, the whole thing looks to be designed to prevent exactly that scenario. Where do you see the weakness? How could a secret order result in undetectable data capture?

No. The information is all out there - secret courts, secret judgements, its all been put out there. I don't need to dissect any technical information, to recognise that I cannot know what I do not know.

In case anyone was uncertain about whether to trust what we are told - we heard that the US government was taping millions of phone records from the Snowden revelations.

So, we are told there are secrets, and we are told that there are mechanisms in place to prevent this information from being made public.

You are also free to believe that the revelations are no longer relevant... I'd like to hear the reason.

IMO - the reverse is the case - in that you need to show why Apple have now become trustworthy. Why would Apple not be subject to secret judgements?

I know there is a lot of marketing spin about Apple's privacy - but do you really think that they would actually confront the government system, in a way that isn't some further publicity stunt? Can one confront the government and retain a license to operate, do you think? Is it not probable that the reality is that Apple have huge support from the government?

Perhaps this kind of idea is hard to understand - that one can make a big noise about privacy, and how one is doing this or that to prevent access, and all the while ensuring that access is provided to authorised parties. Corporations can say this sort of thing with a straight face - its not a privacy issue to private information - its a (secret) legal issue!

Sorry, but secret courts and secret judgements, along with existing disclosure that millions were being spied upon, means one needs to expect the worst.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#273

Earlier quoted context omitted.

Usually this is done the other way around - servers verifying client devices using a chip the manufacturer put in them and fully trusts. They can trust it, because it's virtually impossible for you (the user) to modify the behavior of this chip. However, you can't put something in Apple's server. So if you don't trust Apple, this improves the trust by... 0%. Their device says it's been attested. Has it? Who knows? Th…

If it is all a lie, Apple will lose so much money from class action lawsuits and regulatory penalties. > It’d be trivial to just use a fake hash You have to go deeper to support this. Apple is publishing source code to firmware and bootloader, and the software above that is available to researchers. The volume hash is computed way up in the stack, subject to the chain of trust from these components. Are you suggestin…

I don't know if they will. It is highly unlikely. But theoretically, it is possible, and very well within their technical capabilities to do so.

It's also not as complicated as you make it sound here. Because Apple controls the hardware, and thus also the data passing into attestation, they can freely attest whatever they want - no need to truly run the whole stack.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#274
post #116

Earlier quoted context omitted.

Well, a 89-day "update-and-revert" schedule will take care of those pesky auditors asking too many questions about NSA's backdoor or CCP's backdoor and all that.

No, because the log of what source was used will still show the backdoored version, and you can't unpublish the information that it was used. Reverting doesn't solve the problem that people will be able to say "this software was attested 90 days ago and it hasn't been released". If you're trying to do a quiet backdoor and you have the power to compel Apple to assist, the route to take is to simply misuse the keys tha…

> simply use them to forge messages attesting to be running software on hardware that you aren't

Well, your messages have to be congruent with the expected messages from the real hardware, and your fake hardware has to register with the real load balancers to receive user requests.

> RCE

That’s probably the best attack vector, and presumably why Apple is only making binary executables available. Not that that stops RCE.

But even then you can’t pick and choose the users whose data you compromise. It’s still a sev0 problem, but less exploitable for the goals of nation states so less likely to be heavily invested in for exploiting.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#275

I have a big question here. Who is this for? Dont get me wrong I think it's a great effort. This is some A+ nerd stuff right here. It's speaking my languge. But Im just going to figure out how to turn off "calls home". Cause I dont want it doing this at all. Is this speaking to me so I tell others "apple is the most secure option"? I don't want to tell others "linux" because I don't want to do tech support for that.…

NSA already has all our data and if they don't, they have direct contacts at Meta and Alphabet to get it same-day delivery. I'm trusting Apple more in this case, they have an incentive to keep things private and according to experts they're doing everything they can to do so. "Indeed, if you gave an excellent team a huge pile of money and told them to build the best “private” cloud in the world, it would probably loo…

The NSA partners directly with telecoms companies, especially AT&T. Its easier when companies like Meta and Facebook will play along, but that's not the only way they get access to a bunch of our data.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#276
post #136

Earlier quoted context omitted.

They already have root. Their software is closed source. There is absolutely nothing stopping them from uploading all of your data right now. If you don't trust the people making your OS, your problems are much deeper than fretting about off-device AI processing.

That's true, but also it should be possible to make an OS that people can trust without trusting you, and as users we should encourage movement in that direction.

Any kind of practical OS would contain code of unpractical amounts to manually review and audit.

That's not to mention the argument that any software of a LOC count of higher than some number is impossible to audit because of complex state handling. Rice's Theorem applies to your brain too, probably, to some extent. Idk about purely functional Haskell though.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#277
post #125

Earlier quoted context omitted.

Apple needs to differentiate itself, and they have chosen privacy as a way to do that, which I'm all for. The headlines around Microsoft's AI efforts have largely been a nightmare, with a ton of bad press. If the press around Apple's AI is all about how over the top they went with security and privacy, that will likely make people feel a little better about using it. I'm not a big user of OpenAI's stuff, but if I was…

I actually thought one notable thing in the presentation was that they spent all this time talking about their new private cloud compute architecture. And then showed that they have a prompt asking if you're ok sending the data to OpenAI. Presumably because despite OpenAI promising not to use your data (a promise apple relayed) OpenAI didn't buy into this new architecture.

Different features.

OpenAI provides the chatbot interface we all know.

The PCC cloud serves all of the other integrated AI features like notification prioritization, summarization, semantic search, etc. At least when those can’t be run on device.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#278
post #189

Earlier quoted context omitted.

What makes you think that internal access control at Apple is any better than Google's, Microsoft's or OpenAI's? Google employees have long reported that you can't access user data with standard credentials, for example. Also, what makes you think that Apple's investments on chip design and OS is superior to Google's? Google is known for OpenTitan and other in-house silicon projects. It's also been working in secure…

> What makes you think that internal access control at Apple is any better There are multiple verified stories on the lengths Apple goes internally to keep things secret. I saw a talk years ago about (I think) booting up some bits of the iCloud infrastructure, which needed two different USB keys with different keys to boot up. Then both keys were destroyed so that nobody knows the encryption keys and can't decrypt th…

Destroyed? Where? In all places where they were stored? Or just in some of them? How can you tell? You still need to trust them they didn't copy them somewhere.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#279
I would love to be able to run a PCC node locally on my M2 MacBook or similar for my iPhone to offload to, even if it’s only for doing what 15 Pro iPhones can do on-device.

There’s precedent for this sort of thing as well, like Apple TVs or iPads acting as HomeKit hubs and processing security can footage on-device.

Maybe they’ll open that up in the future.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#280
post #145

Earlier quoted context omitted.

That's true, but also it should be possible to make an OS that people can trust without trusting you, and as users we should encourage movement in that direction.

> should be possible What makes you think this?

Because there are so freaking many of us, and some of us trust each other. If we were better at coordinating about which parts of the code we trust and to what degree, we could determine which parts of it are untrustworthy and patch the problem out of it.

The GrapheneOS people are doing this, for example. It's not crazy to consider your device vendor as part of your threat model, because like it or not, they are a threat.

Post reply on HN