Live data from Hacker News

Private Cloud Compute: A new frontier for AI privacy in the cloud

security.apple.com

361–370 of 393 posts

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#361
post #262

Earlier quoted context omitted.

No, this really isn't right . To quote: verifiable transparency, goes one step further and does away with the hypothetical: security researchers must be able to verify the security and privacy guarantees of Private Cloud Compute, and they must be able to verify that the software that’s running in the PCC production environment is the same as the software they inspected when verifying the guarantees. So how does this…

Next time you "um akshually", do your homework first. > These are pretty strong guarantees, and really make it difficult for Apple to bypass. These guarantees rely entirely on trust in the hardware but it's not your hardware .

> These guarantees rely entirely on trust in the hardware but it's not your hardware.

This exactly the problem that "trusted computing" is designed to solve.

I'd encourage you to read for example the AWS Nitro Enclave outline here: https://aws.amazon.com/blogs/security/confidential-computing....

Nitro enclaves are similar in that they are designed to stop AWS operators from having access to the compute, even though it isn't owned by you.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#362
post #251

Earlier quoted context omitted.

This isn't right. If you trust math you can prove the software is what they say it is. Yes it is work to do this, but this is a big step forward.

It's not fully homomorphic encryption. The compute is happening in the plain on the other side, and given the scale of models they are running, it's not likely that all of the data involved in a computation is happening inside a single instance of particularly secure and hardened hardware. I don't think it's reasonable for most individuals to expect to be protected from nation-state actors or something, but their cla…

> it's not likely that all of the data involved in a computation is happening inside a single instance of particularly secure and hardened hardware.

Actually it is. Read their docs on what they do linked below.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#363

Earlier quoted context omitted.

It's completely fair, because regardless of third party audits, chips, etc, there are backdoors right along the line, that are going to provide Apple and the government with secret legal access to your data. They can simply go to a secret court, receive a secret judgment, and be authorised to secretly view your data. Does anyone really think this is not already the case? There is no transparency. A licensed third par…

The best protection against "secret orders" is to use mathematics. Build your system so that it can't be decrypted, don't log anything etc. Mullvad has been doing this with VPNs and law enforcement has tested it - there's nothing for them to get. Same has been proven with Apple not allowing FBI to open an iPhone, because it'd set a precedent. Future iPhone versions were made so that it's literally impossible for even…

> Same has been proven with Apple not allowing FBI to open an iPhone, because it'd set a precedent.

I thought the outcome of that case was that no precedent was set, since the iPhone was unlocked before the FBI could test their argument in court.

> Future iPhone versions were made so that it's literally impossible for even Apple to open a locked iPhone.

Firmware signed by apple is what runs to verify your biometrics and decide whether or not to unlock the device. At any point apple could sign firmware with a backdoor for this processor which lets them unlock any phone. How did they prevent this in future iPhone versions?

> theshrike79 18 hours ago | parent | context | flag | on: Private Cloud Compute: A new frontier for AI priva...

The best protection against "secret orders" is to use mathematics.

Build your system so that it can't be decrypted, don't log anything etc. Mullvad has been doing this with VPNs and law enforcement has tested it - there's nothing for them to get.

Same has been proven with Apple not allowing FBI to open an iPhone, because it'd set a precedent. Future iPhone versions were made so that it's literally impossible for even Apple to open a locked iPhone.

> There's no reason why they wouldn't go to same lengths on their private cloud compute. It's the one thing they can do that Google can't.

They did go to the same length, they have the ability to see your data whenever they choose to since they own the signing keys.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#364
post #227

Earlier quoted context omitted.

> unless it's open source and the servers decentralized, you are always trusting SOMEONE Specifically, open-source and self-hostable . Open source doesn't save you if people can't run their own servers, because you never know whether what's in the public repo is the exact same thing that's running on the cloud servers.

You can by having an attestation of the signed software components up from the secure boot process, and having the client device validate said attestation corresponds to the known public version of each component, and randomize client connections across infrastructure. Other than obvious "open source software isn't perfectly secure" attack scenarios, this would require a non-targeted hardware attack, where the entire…

Attestation of software signed by who?

If apple holds the signing keys for the servers, can they not change the code at any time?

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#365
post #268
post #189

Earlier quoted context omitted.

What makes you think that internal access control at Apple is any better than Google's, Microsoft's or OpenAI's? Google employees have long reported that you can't access user data with standard credentials, for example. Also, what makes you think that Apple's investments on chip design and OS is superior to Google's? Google is known for OpenTitan and other in-house silicon projects. It's also been working in secure…

That's not even getting to the fact that Apple is also running a display ads business: https://searchads.apple.com/

Such a lazy take. Yes, they show ads based on what you search for in the App Store. They will also show apps based on location if the customer opts in to that feature. No other data is used. No browsing history, no purchase history, nothing like what other companies are collecting.

https://searchads.apple.com/privacy

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#366
post #262

Earlier quoted context omitted.

The only thing the math tells you is that the server software gave you a correct key. It does not tell you how it got that key. A compromised server would send you the key all the same. You still have to trust in the security infrastructure. Trust that Apple is running the hardware it says it is, Trust that apple is running the software it says it is. Security audits help build that trust, but it is not and never wil…

No, this really isn't right . To quote: verifiable transparency, goes one step further and does away with the hypothetical: security researchers must be able to verify the security and privacy guarantees of Private Cloud Compute, and they must be able to verify that the software that’s running in the PCC production environment is the same as the software they inspected when verifying the guarantees. So how does this…

What changes with your analysis with the understanding that apple holds the signing keys for the PCC nodes?

How does the client verify that the code running on the PCC is the code that has been audited publicly, and not a modified version logging your data or using it for other purposes(signed by apple).

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#367
post #110

Earlier quoted context omitted.

Apple’s rich enough to build and own their own datacenters. Savvy enough, too. I’d imagine the chassis are custom Apple-NOC-specific M-chip powered servers.

So basically, a Mac mini.

Well, I was thinking more like the equivalent of 16 or 32 mac minis in a 2U rack enclosure.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#368
post #268

Earlier quoted context omitted.

That's not even getting to the fact that Apple is also running a display ads business: https://searchads.apple.com/

Such a lazy take. Yes, they show ads based on what you search for in the App Store. They will also show apps based on location if the customer opts in to that feature. No other data is used. No browsing history, no purchase history, nothing like what other companies are collecting. https://searchads.apple.com/privacy

Eventually the addressable market for iPhones will saturate, but the growth imperative will remain.

If I were king of Apple and I truly valued user privacy, I would be careful not to tie any revenue streams to products that entail the progressive violation of user privacy.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#369

The thing with cloud and with anything related to it, anything that connects to the internet somehow... is that, unless it's open source and the servers decentralized, you are always trusting SOMEONE. Sure, Apple might make their best to ensure nobody – but them – have access to your data... but Apple controls all the end points. It controls the updates your iPhone receives, it controls the servers where this happens…

I don’t think that’s completely fair. It basically puts Apple in the same bucket as Google or OpenAI. Google obviously tracks everything you do for ads, recommendations, AI, you name it. They don’t even hide it, it’s a core part of their business model. Apple, on the other hand, has made a pretty serious effort to ensure that no employee can access your data on these AI systems. That’s hugely different! They’re going…

Apple uses your information for advertising as well.

https://www.apple.com/legal/privacy/data/en/apple-advertisin...

It also exempts itself from normal tracking opt-outs in iOS. It has _another_ set of settings you need to opt out off to disable _their_ advertising tracking.

https://support.apple.com/en-us/105131

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#370

Earlier quoted context omitted.

One hundred percent this. All these conversations always end up boiling down to someone thinking they’re being clever for pointing out you have to trust a company at the end of the day when it comes to security and privacy. Yes. Valid. So if you have to trust someone , doesn’t it make sense for it to be someone who has built protecting privacy into their core value proposition, versus a company that has baked violati…

It's not about being clever, it's about being perceptive. Apple's cloud commitment has a history of being sketchy, whether it's their government alliance in China, the FIVE-EYES/PRISM membership in America, or their obsession with creating "private" experiences that rely on the benefit of the doubt. Apple doesn't care about you, the individual. Your value as a singular customer is worthless. They do care about the wh…

> And worst off, Apple markets security. That's it; you can't go verify their veracity outside the dinky little whitepapers they publish. You can't know for sure if they have privacy violation baked-in to their system because you can't actually verify anything.

Oh, boy, but this is deeply false. Apple literally provides security researchers models of their devices to verify their security claims on their most important cash cow, the iPhone.

This is just an incredibly bold and verifiably false claim.

Wow.

Post reply on HN