Live data from Hacker News

Private Cloud Compute: A new frontier for AI privacy in the cloud

security.apple.com

321–330 of 393 posts

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#321

The thing with cloud and with anything related to it, anything that connects to the internet somehow... is that, unless it's open source and the servers decentralized, you are always trusting SOMEONE. Sure, Apple might make their best to ensure nobody – but them – have access to your data... but Apple controls all the end points. It controls the updates your iPhone receives, it controls the servers where this happens…

Unless you personally validate hardware designs, manufacturing processes, and all software, even when running locally you're trusting many, many people.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#322

Earlier quoted context omitted.

If you’re presenting a conspiracy theory, you have to at least poke holes in the claims you consider false. Under the system described in the linked paper, your scenario is not possible. In fact, the whole thing looks to be designed to prevent exactly that scenario. Where do you see the weakness? How could a secret order result in undetectable data capture?

No. The information is all out there - secret courts, secret judgements, its all been put out there. I don't need to dissect any technical information, to recognise that I cannot know what I do not know. In case anyone was uncertain about whether to trust what we are told - we heard that the US government was taping millions of phone records from the Snowden revelations. So, we are told there are secrets, and we are…

Fair, go ahead and expect the worse, and handwave away any attempts to mitigate.

But I'm not sure where that leaves you. Is it just a nihilistic "no security matters, it's all a show" viewpoint?

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#323
not trusting any of the privacy/security mumbo-jumbo when their icloud free tier still allows for a paltry 5 gigs, when even google offers thrice as much for their public service.

i am happy for those who see the positives here, but for the skeptic a toggle to prevent any online processing would be more satisfactory.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#324

The only way to trust this is them selling "cloud compute" servers that folks can deploy and monitor in their own infrastructure. Nothing else can be guaranteed to not include malicious code to exfiltrate the data. Or better yet, make the APIs public and pluggable so that one can choose an off-device AI processor themselves if one is needed.

Your own infrastructure is definitely less secure than this or even, say, Google. You do not have the capability and teams of SREs to detect intrusions, and an attacker would know that your server processes your data.

Maybe, but I can totally firewall my own servers to my heart's desire, including completely blocking it off from the internet and only allowing connections via my own network's routes.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#325

Earlier quoted context omitted.

Do you not remember Edward Snowden? Eg this sort of info: > The scandal broke in early June 2013, external when the Guardian newspaper reported that the US National Security Agency (NSA) was collecting the telephone records of tens of millions of Americans. > The paper published the secret court order directing telecommunications company Verizon to hand over all its telephone data to the NSA on an "ongoing daily basi…

"telephone data" != "contents of every phone call"

You and I have no idea.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#326

Earlier quoted context omitted.

No. The information is all out there - secret courts, secret judgements, its all been put out there. I don't need to dissect any technical information, to recognise that I cannot know what I do not know. In case anyone was uncertain about whether to trust what we are told - we heard that the US government was taping millions of phone records from the Snowden revelations. So, we are told there are secrets, and we are…

Fair, go ahead and expect the worse, and handwave away any attempts to mitigate. But I'm not sure where that leaves you. Is it just a nihilistic "no security matters, it's all a show" viewpoint?

It is fair, I don't accept attempts to mitigate. The trust is gone, and nothing can recover it. The idea of trusting government and corporations was ridiculous in the first place as these entities are not your friends.

You wouldn't expect a repeat abuser to stop abusing just because of 'time' or a marketing campaign. And yet this is the case here. People keep looking to their tormentors for solutions.

Not expecting healing from those also inflicting the trauma, ie changing one's expectations, seems like a minimum effort/engagement in my view, but it's somehow inconceivable.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#327
post #268
post #189

Earlier quoted context omitted.

What makes you think that internal access control at Apple is any better than Google's, Microsoft's or OpenAI's? Google employees have long reported that you can't access user data with standard credentials, for example. Also, what makes you think that Apple's investments on chip design and OS is superior to Google's? Google is known for OpenTitan and other in-house silicon projects. It's also been working in secure…

That's not even getting to the fact that Apple is also running a display ads business: https://searchads.apple.com/

Indeed. Apropos to this: new features[1] to insert ads into videos in native apps.

[1]: https://developer.apple.com/videos/play/wwdc2024/10114/

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#328

Earlier quoted context omitted.

You can't mandate retention on stuff you're not storing anyway - or because of encryption can't store.

You would think that, but cell carriers have been found to retain both plaintext and encrypted traffic for several years in some cases: https://www.vice.com/en/article/m7vqkv/how-fbi-gets-phone-da...

Cell carriers aren't a bastion of end to end encryption, the tech just can't do it.

That's why you use them just as dumb pipes forwarding encrypted data traffic from one place to another.

No SMS, no phone calls if you can avoid it.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#329
post #145

Earlier quoted context omitted.

> should be possible What makes you think this?

Because there are so freaking many of us, and some of us trust each other. If we were better at coordinating about which parts of the code we trust and to what degree, we could determine which parts of it are untrustworthy and patch the problem out of it. The GrapheneOS people are doing this, for example. It's not crazy to consider your device vendor as part of your threat model, because like it or not, they are a th…

That’s a good point. It would be interesting if there was a “git blame” style command, but that showed a trust score for every line/block based on who has touched it.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#330

Earlier quoted context omitted.

Do you not remember Edward Snowden? Eg this sort of info: > The scandal broke in early June 2013, external when the Guardian newspaper reported that the US National Security Agency (NSA) was collecting the telephone records of tens of millions of Americans. > The paper published the secret court order directing telecommunications company Verizon to hand over all its telephone data to the NSA on an "ongoing daily basi…

"telephone data" != "contents of every phone call"

Contents of communications aren't as important as you may think; metadata is extremely dangerous.
Post reply on HN