Live data from Hacker News

Private Cloud Compute: A new frontier for AI privacy in the cloud

security.apple.com

311–320 of 393 posts

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#311

Earlier quoted context omitted.

It’s not about technology. It’s about their business. Apple generally engineers their business so that there isn’t an incentive to violate those access controls or principles. Thats not where the money is for them. Behavior is always shaped by rewards and punishments. Positive reinforcement is always stronger.

One hundred percent this. All these conversations always end up boiling down to someone thinking they’re being clever for pointing out you have to trust a company at the end of the day when it comes to security and privacy. Yes. Valid. So if you have to trust someone , doesn’t it make sense for it to be someone who has built protecting privacy into their core value proposition, versus a company that has baked violati…

They're not trying to be clever, they're trying to point out the very important philisophy of maximizing self reliance that so many people like you eschew.

How do you distinguish between a company who 'has built protecting privacy into their core value proposition' and one who just says they've done so?

What are you going to do if a major privacy scandal comes out with Apple at the center? If you wouldn't jump ship from Apple after a major privacy scandal then why does your input on this matter at all?

Some people feel that is inevitable so it's best to just rip that bandaid off now.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#312

Earlier quoted context omitted.

NSA already has all our data and if they don't, they have direct contacts at Meta and Alphabet to get it same-day delivery. I'm trusting Apple more in this case, they have an incentive to keep things private and according to experts they're doing everything they can to do so. "Indeed, if you gave an excellent team a huge pile of money and told them to build the best “private” cloud in the world, it would probably loo…

The NSA partners directly with telecoms companies, especially AT&T. Its easier when companies like Meta and Facebook will play along, but that's not the only way they get access to a bunch of our data.

How do telecom companies unravel public key encryption in transit?

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#313

Earlier quoted context omitted.

Apple will obey government orders to give data they have and can access. No government order short of targeting a specific backdoored update to a specific person will allow them to give data they can't access. And if you're doing something that can make a TLA force Apple to create a targeted iOS update just for you, it's not something regular people can or should worry about. Apple keeps normal people safe from mass…

Do you not remember Edward Snowden? Eg this sort of info: > The scandal broke in early June 2013, external when the Guardian newspaper reported that the US National Security Agency (NSA) was collecting the telephone records of tens of millions of Americans. > The paper published the secret court order directing telecommunications company Verizon to hand over all its telephone data to the NSA on an "ongoing daily basi…

"telephone data" != "contents of every phone call"

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#314

Earlier quoted context omitted.

> What makes you think that internal access control at Apple is any better There are multiple verified stories on the lengths Apple goes internally to keep things secret. I saw a talk years ago about (I think) booting up some bits of the iCloud infrastructure, which needed two different USB keys with different keys to boot up. Then both keys were destroyed so that nobody knows the encryption keys and can't decrypt th…

Destroyed? Where? In all places where they were stored? Or just in some of them? How can you tell? You still need to trust them they didn't copy them somewhere.

It's impossible to use any technology if you don't trust anyone.

Any piece of technology MAY have a backdoor or secondary function you don't know of and can't find out without breaking said device.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#315
post #311

Earlier quoted context omitted.

One hundred percent this. All these conversations always end up boiling down to someone thinking they’re being clever for pointing out you have to trust a company at the end of the day when it comes to security and privacy. Yes. Valid. So if you have to trust someone , doesn’t it make sense for it to be someone who has built protecting privacy into their core value proposition, versus a company that has baked violati…

They're not trying to be clever, they're trying to point out the very important philisophy of maximizing self reliance that so many people like you eschew. How do you distinguish between a company who 'has built protecting privacy into their core value proposition' and one who just says they've done so? What are you going to do if a major privacy scandal comes out with Apple at the center? If you wouldn't jump ship f…

I'm taking aim at the Google bros who try to raise these arguments to muddy the waters into a sort of false equivalence between Apple and Google.

If you're already using a dumb phone and eschewing modern software services, then I'm not really talking to you. Roll on brother/sister, you are living your ideals.

> How do you distinguish between a company who 'has built protecting privacy into their core value proposition' and one who just says they've done so?

The business incentives. Apple's brand and market valuation to some extent depends on being the secure and privacy oriented company you and your family can trust. While Google's valuation and profit depends almost entirely on exploiting as much of your personal data as they possibly can get away with. The business models speaks for themselves.

Does this guarantee privacy and security? Does Apple have a perfect track record here? No of course not, but again if these are my two smartphone choices it seems fairly clear to me.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#316
post #171

Who pays for the costs of private cloud compute, is it free of charge for the iPhone owner (at least until they turn it into a subscription)? What about second hand iPhone users?

> Who pays for the costs of private cloud compute, is it free of charge for the iPhone owner (at least until they turn it into a subscription)?

My guess is that this is similar to how iOS upgrades are “free”, how Apple Maps is free, how iMessage is free, how iCloud Mail is free, etc. To a good extent, it’s all paid for by the price paid by the customer for the hardware.

I’d also wager that there will be a paid service/subscription that will get baked into iCloud+ at some point in time (maybe a year from now). This will offer a lot more and Apple will try to attract more customers into its paid services net.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#317

Earlier quoted context omitted.

If your AI model sucks, you have to use other gimmicks to lure customers. That's marketing 101. Create irrational fear about piracy, push privacy focused products and profits as the sheeple promptly fall for this

I've never seen someone use "sheeple" in an anti-privacy argument.

the most successful sheeple operation is the one the sheeple and the entire world is completely oblivious of it.

jokes aside, this is no different from people selling bunker beds, gold, ammunition, crypto, vpns. It is specifically for the set of gullible people who think they and their data is so important. Reality (except for 10,000 people or so) is, most lives and their 'precious' data is worthless. (I'm not talking about SSN, Bank Accounts -- those are well protected by tech cos HN seem to hate on)

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#318
post #247
post #221

Wow! This is incredibly exciting. Apple's Private Cloud Compute seems to be conceptually equivalent with System Transparency - an open-source software project my colleagues and I started six years ago. I'm very much looking forward to more technical details. Should anyone at Apple see this, please feel free to reach out to me at stromberg@mullvad.net. I'd be more than happy to discuss our design, your design, and/or…

https://en.m.wikipedia.org/wiki/Confidential_computing This is what they are doing. Search implementations of this to understand more technical details.

It's not, AFAICT from the press release.

Confidential Compute involves technologies such as SGX and SEV, and for which I think Asylo is an abstraction for (not sure), where the operator (eg Azure) cannot _hardware intercept_ data. The description of what Apple is doing "just" uses their existing code signing and secure boot mechanisms to ensure that everything from the boot firmware (the computers that start before the actual computer starts) to the application, is what you intended it to be. Once it lands in the PCC node it is inspectable though.

Confidential Compute goes a step further to ensure that the operator cannot observe the data being operated on, thus also defeating shared workloads that exploit speculative barriers, and hardware bus intercept devices.

Confidential Compute also allows attestation of the software being run, something Apple is not providing here. EDIT: looks like they do have attestation, however it's different to how SEV etc attestation works. The client still has to trust that the private key isn't leaked, so this is dependent on other infrastructure working correctly. It also depends on the client getting a correct public key. There's no description of how the client attests that.

Interesting that they go through all this effort just for (let's be honest) AI marketing. All your data in the past (location, photos, contacts, safari history) is just as sensitive and deserving of such protection. But apparently PCC will apply only to AI inference workloads. Siri was already and continues to be a kind of cloud AI.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#320
post #294

Earlier quoted context omitted.

> simply use them to forge messages attesting to be running software on hardware that you aren't Well, your messages have to be congruent with the expected messages from the real hardware, and your fake hardware has to register with the real load balancers to receive user requests. > RCE That’s probably the best attack vector, and presumably why Apple is only making binary executables available. Not that that stops R…

> Well, your messages have to be congruent with the expected messages from the real hardware, Yes, which is why you need the keys that are used to make real hardware. Provided you have those very secret and well protected keys (you are Apple being compelled by the government) that's not an issue. > and your fake hardware has to register with the real load balancers to receive user requests. Absolutely, but we're appl…

I think I misunderstood your point -- I took it to mean someone impersonating a server, but you're saying it's Apple. So the part you're attacking (as Apple) is:

> The process involves multiple Apple teams that cross-check data from independent sources, and the process is further monitored by a third-party observer not affiliated with Apple. At the end, a certificate is issued for keys rooted in the Secure Enclave UID for each PCC node.

So, in your scenario, the in-house certificate issuer is compelled to provide certificates for unverified hardware, which will then be loaded with a parallel software stack that is malicious but reports the attestation ID of a verified stack.

So far, so good. Seems like a lot of people involved, but probably still just tens of people, so maybe possible.

Are you envisioning this being done on every server, so there are no real ones in use? Or a subset? Just for sampling, or also with a way to circumvent user diffusion so you can target specific users?

It's an interesting thought exercise but the complexity of getting anything of real value from this without leaks or errors that expose the program seems pretty small.

Post reply on HN