Live data from Hacker News

Private Cloud Compute: A new frontier for AI privacy in the cloud

security.apple.com

331–340 of 393 posts

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#331
post #311

Earlier quoted context omitted.

They're not trying to be clever, they're trying to point out the very important philisophy of maximizing self reliance that so many people like you eschew. How do you distinguish between a company who 'has built protecting privacy into their core value proposition' and one who just says they've done so? What are you going to do if a major privacy scandal comes out with Apple at the center? If you wouldn't jump ship f…

I'm taking aim at the Google bros who try to raise these arguments to muddy the waters into a sort of false equivalence between Apple and Google. If you're already using a dumb phone and eschewing modern software services, then I'm not really talking to you. Roll on brother/sister, you are living your ideals. > How do you distinguish between a company who 'has built protecting privacy into their core value propositio…

> but again if these are my two smartphone choices it seems fairly clear to me.

If you really perceive this as a binary choice, I have no idea how you could conclude that iOS is more secure than the Android Open Source Project.

...of course, it's not just a choice between a Google-spyware phone or an Apple-spyware phone. Many people like to reduce it to that so they can rationalize whichever company they pick, but in reality you have many choices including no smartphone at all. On Android's side, the Open Source images have enabled rigorous cross-referencing in OS capability, as well as forks that reduce the already-limited attack surface. Apple has a long track-record of letting zero-days fester in their inbox and failing to communicate promptly to security researchers, even for actively-exploited vulnerabilities.

It's not a "false equivalency" to highlight how Google, Apple and Microsoft all fold over like wet paper when the intelligence agencies come around. It's not a coincidence, either; all of those companies are enrolled in the NSA's domestic warrantless surveillance program.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#332
post #142

Earlier quoted context omitted.

Slightly off-topic, "open up the kimono" sounds disturbing and creepy to me as an Asian. I suspect I'm not alone in this.

That’s even better. I do think it’s disturbing and creepy when someone goes through my private data without my knowledge.

That's not what they meant or what the phrase means. It's mildly racist and misogynist, and the kinds of discomfort it elicits are not the kind that will make people trust you, the user of the phrase.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#333
post #294

Earlier quoted context omitted.

> Well, your messages have to be congruent with the expected messages from the real hardware, Yes, which is why you need the keys that are used to make real hardware. Provided you have those very secret and well protected keys (you are Apple being compelled by the government) that's not an issue. > and your fake hardware has to register with the real load balancers to receive user requests. Absolutely, but we're appl…

I think I misunderstood your point -- I took it to mean someone impersonating a server, but you're saying it's Apple. So the part you're attacking (as Apple) is: > The process involves multiple Apple teams that cross-check data from independent sources, and the process is further monitored by a third-party observer not affiliated with Apple. At the end, a certificate is issued for keys rooted in the Secure Enclave UI…

Well, the broader context of the proposal is as an alternative to the original comment in this HN thread

> Well, a 89-day "update-and-revert" schedule will take care of those pesky auditors asking too many questions about NSA's backdoor or CCP's backdoor and all that.

As a backdoor I am taking it to mean they can compel assistance from inside of Apple, it's not a hack where they have to break in and hide it from everyone (though certainly they would want to keep it to as few people as possible).

At least in the NSAs case I think it would be reasonable to imagine that they are limited to compromising a subset of the users data. Specific users they've gotten court orders against or something... so yes a subset of nodes and also circumventing user diffusion (which sounds like traffic analysis right up the NSAs alley, or a court order to whatever third party Apple has providing the service).

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#335

Earlier quoted context omitted.

I'm taking aim at the Google bros who try to raise these arguments to muddy the waters into a sort of false equivalence between Apple and Google. If you're already using a dumb phone and eschewing modern software services, then I'm not really talking to you. Roll on brother/sister, you are living your ideals. > How do you distinguish between a company who 'has built protecting privacy into their core value propositio…

> but again if these are my two smartphone choices it seems fairly clear to me. If you really perceive this as a binary choice, I have no idea how you could conclude that iOS is more secure than the Android Open Source Project. ...of course, it's not just a choice between a Google-spyware phone or an Apple-spyware phone. Many people like to reduce it to that so they can rationalize whichever company they pick, but in…

> but in reality you have many choices including no smartphone at all.

Oh come on man. This is why these conversations often aren’t even worth having.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#336

Earlier quoted context omitted.

> but again if these are my two smartphone choices it seems fairly clear to me. If you really perceive this as a binary choice, I have no idea how you could conclude that iOS is more secure than the Android Open Source Project. ...of course, it's not just a choice between a Google-spyware phone or an Apple-spyware phone. Many people like to reduce it to that so they can rationalize whichever company they pick, but in…

> but in reality you have many choices including no smartphone at all. Oh come on man. This is why these conversations often aren’t even worth having.

I'm sorry, hopefully you come back to reality soon. I just went 2 weeks without touching a smartphone, I'm certain you can too.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#337

Earlier quoted context omitted.

> but in reality you have many choices including no smartphone at all. Oh come on man. This is why these conversations often aren’t even worth having.

I'm sorry, hopefully you come back to reality soon. I just went 2 weeks without touching a smartphone, I'm certain you can too.

I think you’re the one not living in reality.

But, hey, at least the NSA won’t get ya.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#338

Earlier quoted context omitted.

I'm sorry, hopefully you come back to reality soon. I just went 2 weeks without touching a smartphone, I'm certain you can too.

I think you’re the one not living in reality. But, hey, at least the NSA won’t get ya.

Alright. Take care.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#339

Earlier quoted context omitted.

> Same has been proven with Apple not allowing FBI to open an iPhone, because it'd set a precedent. Future iPhone versions were made so that it's literally impossible for even Apple to open a locked iPhone. Right, but I have no reason to think that this isn't a marketing ploy either, just another story. There is simply no way that Apple is as big as it is, without providing whatever data the government requires. Corp…

Apple will obey government orders to give data they have and can access. No government order short of targeting a specific backdoored update to a specific person will allow them to give data they can't access. And if you're doing something that can make a TLA force Apple to create a targeted iOS update just for you, it's not something regular people can or should worry about. Apple keeps normal people safe from mass…

> No government order short of targeting a specific backdoored update to a specific person

I'm failing to see the what would be the challenge here. Apple can technically do that. The government can force them to do that.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#340

The thing with cloud and with anything related to it, anything that connects to the internet somehow... is that, unless it's open source and the servers decentralized, you are always trusting SOMEONE. Sure, Apple might make their best to ensure nobody – but them – have access to your data... but Apple controls all the end points. It controls the updates your iPhone receives, it controls the servers where this happens…

I don’t think that’s completely fair. It basically puts Apple in the same bucket as Google or OpenAI. Google obviously tracks everything you do for ads, recommendations, AI, you name it. They don’t even hide it, it’s a core part of their business model. Apple, on the other hand, has made a pretty serious effort to ensure that no employee can access your data on these AI systems. That’s hugely different! They’re going…

Disclaimer: I used to work on Google Search Ads quality models

> Google obviously tracks everything you do for ads, recommendations, AI, you name it. They don’t even hide it, it’s a core part of their business model.

This wasn't the experience I saw. Google is intentional about which data from which products go into their ads models (which are separate from their other user modeling), and you can see things like which data of yours is used in ads personalization on https://myadcenter.google.com/personalizationoff or in the "Why this ad" option on ads.

> and it’s very much not necessary or even a sound business idea for them to do something else

I agree that Apple plays into privacy with their advertising and product positioning. I think assuming all future products will be privacy-respecting because of this is over-trusting. There is _a lot_ of money in advertising / personal data

Post reply on HN