Live data from Hacker News

Apple Private Cloud Compute SoC 3 audit reports

support.apple.com

51–60 of 61 posts

Re: Apple Private Cloud Compute SoC 3 audit reports

#51
post #40

can someone correct me - so apple is using servers that are running a closed down version of iOS on what I would assume is apple silicone, probably excess chips or older chips for the iCloud Private Cloud ?

Apple is definitely using custom silicon designed for PCC, as none of their existing chips have the memory capacity or bandwidth to serve LLMs to even a single client performantly, let alone many clients. The speed with which Apple Intelligence worked back when it actually used Apple's own PCC and not Google's cloud was still much higher than could be achieved with anything they sold to customers. Now of course, Siri AI is too big and expensive for even that, but hopefully Google's cloud is just a stopgap...

Re: Apple Private Cloud Compute SoC 3 audit reports

#54
post #52

Out of that whole report I got this gem, macOS Security Compliance Project https://pages.nist.gov/macos_security/

Wow very interesting. Makes me wonder if a DISA STIG for macOS is next…

This project can already generate baselines for DISA STIG for macOS

Re: Apple Private Cloud Compute SoC 3 audit reports

#55

Earlier quoted context omitted.

Hasn't Deel been run out of business though? IME SOC2 is still quite involved for any company, especially smaller ones without specialized security personnel.

I think both of you meant “Delve”, not “Deel”. Deel is a pretty successful HR startup that’s still growing at a good rate and AFAIK free of major scandals. Again, Deel is HR, not SOC2. Delve was the SOC2 company described in the article linked above.

Yes, you are right and I mixed them up. Too late to edit or delete the comment now though.

Deel is the ycombinator startup that allegedly spied on their competition while Delve is the ycombinator startup that allegedly fakes SOC2 compliance.

Re: Apple Private Cloud Compute SoC 3 audit reports

#56

Earlier quoted context omitted.

I think companies like Deel showed that SOC2 is more show than anything else. For context, this is how easy it is to get a SOC2: https://deepdelver.substack.com/p/delve-fake-compliance-as-a...

Delve. Not Deel. Very different startups.

Yes, you are right and I mixed them up. Too late to edit or delete the comment now though.

Deel is the ycombinator startup that allegedly spied on their competition while Delve is the ycombinator startup that allegedly fakes SOC2 compliance.

Re: Apple Private Cloud Compute SoC 3 audit reports

#57
post #48
post #12

Earlier quoted context omitted.

> "look I can afford 50k" Oh no. Looks like you never went through SOC2. 1. No, it does not require 50k, an auditor can cost way less (10k? maybe even less). 2. But the process of preparing for the audit will take a lot of work securing your systems (and increasing reliability and privacy as well), as long as you take it seriously. Of course you can lie to the auditor, but it's up on you. And auditor -- they might lo…

I'm scared of companies where SOC2 auditors are driving their security improvements. It's a bit like letting my toddler drive how I stock my pantry: surely by the end the pantry will be more full, but not really in the way I want.

It's not auditors, it's the compliance requirements and controls. You should not even reach to an auditor before fixing the controls (most of them, the ones you lack auditor must flag, as sometimes it's not feasible to fix most of the controls). I'd say going through an audit is easy, but preparing for the audit is hard.

PS: regarding "most of them" -- if you're one-person shop, you'll likely fail a control that requires your board of directors to be independent of company management (i.e. having directors that do not work for the company). That's OK, but will be reported on your SOC2 report.

Re: Apple Private Cloud Compute SoC 3 audit reports

#58
So Apple is publishing an audit of Apple private closed source components and declared them totally private... trust us bro.

I have absolutely 0 reasons to believe Apple Private Cloud is not a data extraction mechanism for the gullible. Unless I can manually inspect the source, or at least run the binaries on my own hardware that I can firewall and inspect the network traffic, I'm absolutely confident Apple steals all the data to build better ad targeting models, or to sell to the highest bidder.

Re: Apple Private Cloud Compute SoC 3 audit reports

#59
post #45
post #44

Earlier quoted context omitted.

From my 8 years of working SOC2 Type 2 audits done by PwC for a large PaaS Cloud with a worldwide presence (not the big 3) saying Type 2 is almost as trivial as type 1 is absolutely false. This might be true for someone running their own low volume SaaS in one region but for someone the size of Apple they are investing a lot of resource to stay on top of the controls, especially patching and permissions. If you've in…

I'm not going to, like, whip out my resume here, but I am going to confidently assert that if you structure your Type 1 carefully, you can trivialize your Type 2, and as someone currently operating a globally deployed public cloud I can tell you right now that SOC2 doesn't really touch on anything interesting in our engineering. I wrote an article about this, and I think it's the Correct advice for virtually every st…

For anyone reading along, both of tptacek's comments are saying the same thing I'm saying. Or I'm saying the same thing he's saying.

Either way, go read his links.

Re: Apple Private Cloud Compute SoC 3 audit reports

#60
post #57
post #48

Earlier quoted context omitted.

I'm scared of companies where SOC2 auditors are driving their security improvements. It's a bit like letting my toddler drive how I stock my pantry: surely by the end the pantry will be more full, but not really in the way I want.

It's not auditors, it's the compliance requirements and controls. You should not even reach to an auditor before fixing the controls (most of them, the ones you lack auditor must flag, as sometimes it's not feasible to fix most of the controls). I'd say going through an audit is easy, but preparing for the audit is hard. PS: regarding "most of them" -- if you're one-person shop, you'll likely fail a control that requ…

Security and compliance are totally different functions and one has little to do with the other.
Post reply on HN