Live data from Hacker News

Private Cloud Compute: A new frontier for AI privacy in the cloud

security.apple.com

291–300 of 393 posts

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#291
post #260

Earlier quoted context omitted.

Allow me to introduce you to HSMs: https://en.m.wikipedia.org/wiki/Hardware_security_module

I'm well aware of these. They don't solve the problem at hand. You need a way to put keys into new hardware. Thus you need a way to get keys out of wherever you've stored your cryptographic material. Thus it can't be on a HSM (or it can be if it's a master key signing child keys, but in that case the attack only needs a signed child key).

From: https://support.apple.com/guide/security/secure-enclave-sec5...

“A randomly generated UID is fused into the SoC at manufacturing time. Starting with A9 SoCs, the UID is generated by the Secure Enclave TRNG during manufacturing and written to the fuses using a software process that runs entirely in the Secure Enclave. This process protects the UID from being visible outside the device during manufacturing and therefore isn’t available for access or storage by Apple or any of its suppliers.“

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#292
post #124

Earlier quoted context omitted.

Threads also is popular. Probably the mainstream Twitter alternative at this point?

Threads is far from mainstream and just filled with spam and OnlyFans spammers at this point.

That sounds far more like Twitter than Threads. I get so much spam on Twitter now that I hit rate limits reporting it all.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#293

Earlier quoted context omitted.

If it is all a lie, Apple will lose so much money from class action lawsuits and regulatory penalties. > It’d be trivial to just use a fake hash You have to go deeper to support this. Apple is publishing source code to firmware and bootloader, and the software above that is available to researchers. The volume hash is computed way up in the stack, subject to the chain of trust from these components. Are you suggestin…

I don't know if they will. It is highly unlikely. But theoretically, it is possible, and very well within their technical capabilities to do so. It's also not as complicated as you make it sound here. Because Apple controls the hardware, and thus also the data passing into attestation, they can freely attest whatever they want - no need to truly run the whole stack.

It is as complicated as I make it sound. Technically, it's trivial, of course.

But operationally it is incredibly complicated to deliver and operate this kind of false attestation at massive scale.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#294
post #116

Earlier quoted context omitted.

No, because the log of what source was used will still show the backdoored version, and you can't unpublish the information that it was used. Reverting doesn't solve the problem that people will be able to say "this software was attested 90 days ago and it hasn't been released". If you're trying to do a quiet backdoor and you have the power to compel Apple to assist, the route to take is to simply misuse the keys tha…

> simply use them to forge messages attesting to be running software on hardware that you aren't Well, your messages have to be congruent with the expected messages from the real hardware, and your fake hardware has to register with the real load balancers to receive user requests. > RCE That’s probably the best attack vector, and presumably why Apple is only making binary executables available. Not that that stops R…

> Well, your messages have to be congruent with the expected messages from the real hardware,

Yes, which is why you need the keys that are used to make real hardware. Provided you have those very secret and well protected keys (you are Apple being compelled by the government) that's not an issue.

> and your fake hardware has to register with the real load balancers to receive user requests.

Absolutely, but we're apple in this scenario so that's "easy".

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#295

Earlier quoted context omitted.

I don’t think that’s completely fair. It basically puts Apple in the same bucket as Google or OpenAI. Google obviously tracks everything you do for ads, recommendations, AI, you name it. They don’t even hide it, it’s a core part of their business model. Apple, on the other hand, has made a pretty serious effort to ensure that no employee can access your data on these AI systems. That’s hugely different! They’re going…

"I think another facet of trust here is that a rather big part of Apple's business model is privacy. They've been very successful financially by creating products that generate money in other ways, and it's very much not necessary or even a sound business idea for them to do something else." If a third party wants that data, whether the third party is an online criminal, government law enforcement or a "business part…

> Of course, do what is necessary, trust whomever; no one is faulting anyone for making practical choices, but let's not pretend choosing Apple and trusting it solves these problems introduced by so-called "tech" company competitors. Apple pursues online advertising, cloud computing and data collection. All at the expense of privacy. With billions in cash on hand, it is one of the wealthiest companies on Earth, does it really need to do that.

Yeah. I feel like the conversation needs some guard rails like, "Within the realm of big tech, which has discovered that one of its most profitable models is to make you the product, Apple is really quite privacy friendly!"

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#296
post #291
post #260

Earlier quoted context omitted.

I'm well aware of these. They don't solve the problem at hand. You need a way to put keys into new hardware. Thus you need a way to get keys out of wherever you've stored your cryptographic material. Thus it can't be on a HSM (or it can be if it's a master key signing child keys, but in that case the attack only needs a signed child key).

From: https://support.apple.com/guide/security/secure-enclave-sec5... “A randomly generated UID is fused into the SoC at manufacturing time. Starting with A9 SoCs, the UID is generated by the Secure Enclave TRNG during manufacturing and written to the fuses using a software process that runs entirely in the Secure Enclave. This process protects the UID from being visible outside the device during manufacturing and th…

Sure, and even Apple can't imitate a different server that they made.

They're making new servers though. Take the keys that are used to vouch for the UIDs in actual secure enclaves, and use them to vouch for the UID in your evil simulated "secure" enclave. Your simulated secure enclave doesn't present as any particular real secure enclave, it just presents as a newly made secure enclave that Apple has vouched for as being a secure enclave.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#297
post #259

Earlier quoted context omitted.

Thank you for mentioning this. I thought I was going crazy, because I heard this too, but kept seeing comment after comment on other sites asking if a person could choose not to use OpenAI, or that it was happening magically in the background. The way I heard it, the user was in control. I think this goes back to what Steve said in 2010. https://youtube.com/watch?v=Ij-jlF98SzA And yes, while the data might not be lin…

I’m not sure but I thought I saw it mentioned that OpenAI is still allowed to train on the data received from Apple customers.

Actually the opposite. They’re explicitly not allowed to.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#298
post #23

Some good comments on this from cryptographer Matt Green here: https://x.com/matthew_d_green/status/1800291897245835616?t=C... (I wonder if Matt realizes nobody can read his tweets without a X account? Use BlueSky or Masto man) Edit: here's his thread combined https://threadreaderapp.com/thread/1800291897245835616.html?...

If he really wanted no one to be reading his tweets he’d be using BluSky or Masto…

Or maybe (gasp!) a blog?

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#299

I have a big question here. Who is this for? Dont get me wrong I think it's a great effort. This is some A+ nerd stuff right here. It's speaking my languge. But Im just going to figure out how to turn off "calls home". Cause I dont want it doing this at all. Is this speaking to me so I tell others "apple is the most secure option"? I don't want to tell others "linux" because I don't want to do tech support for that.…

It’s for their competitors who have pushed a narrative that Apple was caught “flat-footed”. Well there is actually a line of LLM and cloud infrastructure at iPhone scale. This is not merely 2 years of work. They push the privacy because it’s expected of them.

Gemini could claim privacy but I think people would assume that if true, it would make it less effective.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#300
post #179

Earlier quoted context omitted.

> (I wonder if Matt realizes nobody can read his tweets without a X account? Use BlueSky or Masto man) He actually has an active Mastodon account, but this particular story is not on there (yet): https://ioc.exchange/@matthew_d_green

Inactive since 2 months

You were right until a couple of hours ago. Then this happened: https://ioc.exchange/@matthew_d_green/112597917470493480
Post reply on HN