Live data from Hacker News

Private Cloud Compute: A new frontier for AI privacy in the cloud

security.apple.com

351–360 of 393 posts

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#351

Earlier quoted context omitted.

One hundred percent this. All these conversations always end up boiling down to someone thinking they’re being clever for pointing out you have to trust a company at the end of the day when it comes to security and privacy. Yes. Valid. So if you have to trust someone , doesn’t it make sense for it to be someone who has built protecting privacy into their core value proposition, versus a company that has baked violati…

It's not about being clever, it's about being perceptive. Apple's cloud commitment has a history of being sketchy, whether it's their government alliance in China, the FIVE-EYES/PRISM membership in America, or their obsession with creating "private" experiences that rely on the benefit of the doubt. Apple doesn't care about you, the individual. Your value as a singular customer is worthless. They do care about the wh…

If you are the target of a nation state level actor, you are already fucked. Most of us just don’t want our behavior sold to our insurance companies or whatever. Apple doesn’t do that because it would kill their brand for very little return.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#352

Earlier quoted context omitted.

Maybe, but I can totally firewall my own servers to my heart's desire, including completely blocking it off from the internet and only allowing connections via my own network's routes.

Sure, but then it doesn't work when you're out of the house, which isn't a good pairing with a phone.

I VPN (WireGuard) into my home network to access other selfhosted services (like Immich for photos, paperless-ngx, DNS adblock, etc.) and to prevent some tracking, so it would work great for me.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#353

All of this is interesting, but how easy is this to circumvent? When Apple changes their mind for whatever reason, don't they just return a key to a fake PCC node, which would bypass all of their listed protections? Furthermore, what prevents Apple from doing this for specific users?

iOS won’t send requests to it unless that node appears in the transparency log. If it appears in the transparency log, the whole world will be able to see that a suspicious node has started serving requests. If Apple changes iOS to remove that restriction, the whole world will be able to see that change because it’s client side. If Apple tries to deliver a custom version of iOS to a single user, the iOS hardware will…

Ok, I think you're referring to this:

> Specifically, the user’s device will wrap its request payload key only to the public keys of those PCC nodes whose attested measurements match a software release in the public transparency log.

But what’s stopping Apple from returning a node which lies about its “attested measurements” (possibly even to a specific user)? Whats to prevent any old machine, not running the TPM at all, from receiving a certificate?

I get that “the process is further monitored by a third-party observer not affiliated with Apple”, but I don’t know where I read their report, or even if they are still paid by Apple, so this feels like a trust-based proof.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#354
post #329

Earlier quoted context omitted.

Because there are so freaking many of us, and some of us trust each other. If we were better at coordinating about which parts of the code we trust and to what degree, we could determine which parts of it are untrustworthy and patch the problem out of it. The GrapheneOS people are doing this, for example. It's not crazy to consider your device vendor as part of your threat model, because like it or not, they are a th…

That’s a good point. It would be interesting if there was a “git blame” style command, but that showed a trust score for every line/block based on who has touched it.

I'm working on a system for data annotation that might support apps of that nature.

I'm focusing on simpler datasets for now, I want people to be able to annotate a paper restaurant menu with notes about allergens in a way that other people with those allergens can summon those annotations and steer clear--all without participation from the restaurant. Like an augmented reality layer for text.

I hope it grows up into something that would let you ask:

> How trusted is this line of code, and by whom?

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#355

Earlier quoted context omitted.

I'm sorry, hopefully you come back to reality soon. I just went 2 weeks without touching a smartphone, I'm certain you can too.

I think you’re the one not living in reality. But, hey, at least the NSA won’t get ya.

You know this is a growing trend with teens, right?

Like to eschew smartphones and just use basic feature phones and to interact in real physical settings and not digital ones.

There's a growing and warranted push back to pervasive and addictive digital technology.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#356
post #189

Earlier quoted context omitted.

What makes you think that internal access control at Apple is any better than Google's, Microsoft's or OpenAI's? Google employees have long reported that you can't access user data with standard credentials, for example. Also, what makes you think that Apple's investments on chip design and OS is superior to Google's? Google is known for OpenTitan and other in-house silicon projects. It's also been working in secure…

It’s not about technology. It’s about their business. Apple generally engineers their business so that there isn’t an incentive to violate those access controls or principles. Thats not where the money is for them. Behavior is always shaped by rewards and punishments. Positive reinforcement is always stronger.

I worked for Google for almost 14 years. Never did they, any other engineer, or even product manager I know of, ever suggest to snoop into cloud customer data, especially those using Shielded VMs and Customer Managed Encryption Keys for attached storage (https://cloud.google.com/kubernetes-engine/docs/how-to/using...). I've never seen even the slightest hint, and the security people at Google are incredibly anal to a T about the design and enforcement of these things.

This stuff is all designed so that even an employee with physical access to the machine would find it very difficult to get data. It's encrypted at rest by customer keys, stored in enclaves in volatile RAM. If you detached the computer or disk, you'd lose access. You'd have to perform an attack by somehow injecting code into the running system. But Shielded VMs/GKE instances makes that very hard.

I am not a Google employee anymore but this common tactic of just throwing out "oh, their business model contains ad model ergo, they will sell anything and everything, and violate contracts they sign to steal private data from your private cloud" is a bridge too far.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#357

Earlier quoted context omitted.

It's for shareholders. Microsoft and Nvidia have a bigger market cap than Apple now, thanks to the AI investor boom. Apple need to show they can be all about AI, too. But Apple have the institutional culture to maintain privacy.

This is exactly what I was thinking during the entire keynote. It was blatantly the WWSC (worldwide shareholder conference) and hackernews commenters are eating it up. Don't get me wrong, I've always appreciated apples on device ml/AI features, those have always been powerful, interesting and private but these announcements feel very rushed, it's literally a few weeks after Microsoft's announcements. They've basicall…

> How are they going to pay for all of that compute?

Hardware sales. Only the latest pro/max models will run these models, everyone else is going to have to upgrade.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#358

Earlier quoted context omitted.

It's not about being clever, it's about being perceptive. Apple's cloud commitment has a history of being sketchy, whether it's their government alliance in China, the FIVE-EYES/PRISM membership in America, or their obsession with creating "private" experiences that rely on the benefit of the doubt. Apple doesn't care about you, the individual. Your value as a singular customer is worthless. They do care about the wh…

If you are the target of a nation state level actor, you are already fucked. Most of us just don’t want our behavior sold to our insurance companies or whatever. Apple doesn’t do that because it would kill their brand for very little return.

That's the convenient line of blind apathy they rely on, to sell iPhones. If people cared, they would object to owning an iPhone just from the material and labor cost of it... but they don't. It's a running joke that nobody cares what next year's iPhone looks like as long as the trade-in value is good. Apple couldn't kill their brand if they tried, past this point. People don't pay attention anyways.

Which is why it's good for us to demand more from capable companies. Apple looks good when they're scared, and the market wins when they're forced to compete in novel and interesting ways. Success breeds complacency, the rest is distant history.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#359

Earlier quoted context omitted.

You would think that, but cell carriers have been found to retain both plaintext and encrypted traffic for several years in some cases: https://www.vice.com/en/article/m7vqkv/how-fbi-gets-phone-da...

Cell carriers aren't a bastion of end to end encryption, the tech just can't do it. That's why you use them just as dumb pipes forwarding encrypted data traffic from one place to another. No SMS, no phone calls if you can avoid it.

Speaking of tech, has anyone ever independently audited Apple's encrypted infrastructure a-la what they're promising for Private Compute? I'm unconvinced that the government couldn't crack that if they wanted.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#360

Earlier quoted context omitted.

It's not about being clever, it's about being perceptive. Apple's cloud commitment has a history of being sketchy, whether it's their government alliance in China, the FIVE-EYES/PRISM membership in America, or their obsession with creating "private" experiences that rely on the benefit of the doubt. Apple doesn't care about you, the individual. Your value as a singular customer is worthless. They do care about the wh…

If you are the target of a nation state level actor, you are already fucked. Most of us just don’t want our behavior sold to our insurance companies or whatever. Apple doesn’t do that because it would kill their brand for very little return.

This is the part that’s always so humorous to me about the super tinfoil hat security crowd. They think they’re in the plot of Mr Robot or something. When for the most part, no one actually cares about them at all.

My dad fits into this category. So worried about being “tracked by the government.” He’s not a dissident. He’s not a journalist. Not a freedom fighter. Just deeply inconveniencing his kids with some of his tech choices.

But if these people were the targets of APTs, all the massive technology lifestyle changes they’ve made to supposedly protect themselves wouldn’t really matter.

Post reply on HN