Live data from Hacker News

Private Cloud Compute: A new frontier for AI privacy in the cloud

security.apple.com

391–393 of 393 posts

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#391

Earlier quoted context omitted.

It's not about being clever, it's about being perceptive. Apple's cloud commitment has a history of being sketchy, whether it's their government alliance in China, the FIVE-EYES/PRISM membership in America, or their obsession with creating "private" experiences that rely on the benefit of the doubt. Apple doesn't care about you, the individual. Your value as a singular customer is worthless. They do care about the wh…

> And worst off, Apple markets security. That's it; you can't go verify their veracity outside the dinky little whitepapers they publish. You can't know for sure if they have privacy violation baked-in to their system because you can't actually verify anything. Oh, boy, but this is deeply false. Apple literally provides security researchers models of their devices to verify their security claims on their most importa…

Can you explain to me how I might use such a device to verify the security properties of iBoot?

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#392

Earlier quoted context omitted.

The servers provide a hash of their environment to clients, who can compare it to the published list of audited environments. So the question is: could the hash be falsified? That’s why they’re publishing the source code to firmware and bootloader, so researchers can audit the secure boot foundations. I am sure there is some way that a completely malevolent Apple could design a weakness into this system so they could…

Sure I'm missing something, but isn't that just an untrusted server self-reporting its own hash? Apple publishes the bootloader source and we'd have to assume it's what's actually running and reporting honestly the hash of the OS it's hosting. So we need to go earlier in the chain. In the end, from afar, we don't know if we're communicating with an actual Secure Enclave/SGX whatever or something that just acts like o…

You're not missing anything.

Re: Private Cloud Compute: A new frontier for AI privacy in the cloud

#393
post #361

Earlier quoted context omitted.

Next time you "um akshually", do your homework first. > These are pretty strong guarantees, and really make it difficult for Apple to bypass. These guarantees rely entirely on trust in the hardware but it's not your hardware .

> These guarantees rely entirely on trust in the hardware but it's not your hardware. This exactly the problem that "trusted computing" is designed to solve. I'd encourage you to read for example the AWS Nitro Enclave outline here: https://aws.amazon.com/blogs/security/confidential-computing... . Nitro enclaves are similar in that they are designed to stop AWS operators from having access to the compute, even though…

No, it's not. This is because Apple is the one providing the enclave, so the party you have to trust is them. When a cloud vendor offers this they use trust rooted in the manufacturer of the chips they are using.
Post reply on HN