Earlier quoted context omitted.
Per that link: I think there's an interesting question about whether a nefarious actor who's infiltrated a cloud provider with physical access to machines that are running signed operating systems, with signed binaries, with TDX remote attestation, and with hardware supply chain verification, has the ability to break the privacy guarantees of a tenant with Apple's sophistication. Certainly, one could tamper with the…
Those datacentres would be in the same position of trust as a VPN provider in that the data must be unencrypted at points in the process. They could be making it very safe, and the things apple says they are doing would make it as safe as possible, but as a user there is no way of verifying the claims.
Apple reveals new AI architecture built around Google Gemini models
541–550 of 609 posts
Re: Apple reveals new AI architecture built around Google Gemini models
#542Earlier quoted context omitted.
From an EU perspective, Microsoft is doing data protection, Apple is doing data privacy. Microsoft's approach to data is basically "we promise nobody else but you and your government can access it, we can but we pinky swear we won't." This promise is mostly enforced at the legal layer and through legal consequences, not technical safeguards. If they think they can get away with it (or are forced to get away with it b…
There has been anecdotal statements/blogs from Apple employees about the data privacy. They have said building some internal capabilities or user facing features are extremely difficult or impossible because they aren't able to access user data at the level required.
Re: Apple reveals new AI architecture built around Google Gemini models
#543Earlier quoted context omitted.
Yes, but Siri can be turned off from invocation without turning off CarPlay. You can disable the side button and Hey Siri while leaving Siri "on."
No disrespect for your valuable discovery but this attitude of “it’s possible, if you do these non-obvious steps” feels a lot like victim blaming in UI. If Apple (or anyone else) wanted to make a feature used, they can. For everyone else, if Siri is off CarPlay doesn’t work. And that’s by design. Not the design of “ooh if Siri is off then voice in CarPlay won’t work” (warnable), but punishment if Siri is off. Again t…
I am sure that there was a meeting where they decided what to do when Siri was off and somebody decided (very possibly with ulterior motives) not to split the feature set - all or nothing. However I don't think the challenge they were faced with in this hypothetical meeting was an easy one.
The alternative is you open the Messages app and you can't send messages. You open Maps and you can't get directions (unless parked). Sure, I get that they could show a screen saying "Sending messages is not available when Siri is disabled" but now you're hitting error messages while driving.
Anyways, the main reason people would disable Siri is accidental activation, and Apple provides all the toggles needed to avoid that without disabling the core components needed for CarPlay.
Re: Apple reveals new AI architecture built around Google Gemini models
#544Earlier quoted context omitted.
You should read the paper. Like any good security paper, it doesn’t assert immunity to particular parties. Instead, covers things like how PCC attests that the running software image is identical to the publicly-available, forensically-studied one. Fear is real for sure, but don’t let fear be an excuse to lose rigor in thinking.
What if the CA certs are compromised, as was alluded to for GCP in the Snowden leaks? All server security measures are irrelevant if every client req/res is dragnet siphoned off to NSA servers in plaintext. It would also afford the corporation deniability even if they were aware or involved. This is why everything than can feasibly be E2EE (or performed locally) should be, unless the data is explicitly public. There…
Are you suggesting that PCC specifically is sending things in plaintext, or that the security promises in the server and arch are false, or that a compromised CA means… IDK what?
I’m with you on the big principles, but are you implying more specific attack vectors or just kind of maybe everything could be compromised somehow?
Re: Apple reveals new AI architecture built around Google Gemini models
#545Sorry to be off topic, but I have a question: has anyone installed the latest beta iOS and macOS, and if so what is the current status of Gemini integration?
Re: Apple reveals new AI architecture built around Google Gemini models
#546Earlier quoted context omitted.
There has been anecdotal statements/blogs from Apple employees about the data privacy. They have said building some internal capabilities or user facing features are extremely difficult or impossible because they aren't able to access user data at the level required.
Do you have any examples?
But to answer your question directly, I don't have any links for those blogs or comments
Re: Apple reveals new AI architecture built around Google Gemini models
#547Very Apple-ish approach to AI catch up: wrap an external tool in a privacy architecture, embed into the OS and productize the orchestration layer. It will be interesting to see if the Private Cloud Compute + on-device routing can make third-party model capabilities feel like a first-party system without leaking user context to the model provider. If Apple handles the Google-Apple boundary right, this will be an elega…
Re: Apple reveals new AI architecture built around Google Gemini models
#548Earlier quoted context omitted.
Per that link: I think there's an interesting question about whether a nefarious actor who's infiltrated a cloud provider with physical access to machines that are running signed operating systems, with signed binaries, with TDX remote attestation, and with hardware supply chain verification, has the ability to break the privacy guarantees of a tenant with Apple's sophistication. Certainly, one could tamper with the…
Why bother with all that cloak and dagger stuff when they can just buy the data? You believe Apple and/or Google isn't selling it? I have some land in Florida I'd like to talk about.
Google is 100% doing that because thats their entire incentive for the business. They sell low cost software / subsidized hardware on the grounds that you pay with your sharing data. That's the implied cost.
Show me the incentives - I will show you the outcomes.
Re: Apple reveals new AI architecture built around Google Gemini models
#549Earlier quoted context omitted.
From my understanding of the architecture, Apple and Google have basically developed a fork of Gemini that is built to run on Apple's PCC. There is no data being sent to any Google servers. From this MacRumors article: "The new architecture centers on Apple Foundation Models co-developed with Google, which Apple says are adapted to run both on-device and on servers through its existing Private Cloud Compute infrastru…
That seems to conflict with the recent security blog that says they are using Google Cloud infra and NVIDIA GPUs with PCC now [0]. They are allowing it to run on Intel and NVIDIA and Google chips meeting certain requirements now too instead of just Apple silicon because they think they’re secure enough now, but I suspect this decision might have been pushed by the need for Siri to be useful. I still definitely think…
Re: Apple reveals new AI architecture built around Google Gemini models
#550Earlier quoted context omitted.
From an EU perspective, Microsoft is doing data protection, Apple is doing data privacy. Microsoft's approach to data is basically "we promise nobody else but you and your government can access it, we can but we pinky swear we won't." This promise is mostly enforced at the legal layer and through legal consequences, not technical safeguards. If they think they can get away with it (or are forced to get away with it b…
There has been anecdotal statements/blogs from Apple employees about the data privacy. They have said building some internal capabilities or user facing features are extremely difficult or impossible because they aren't able to access user data at the level required.