10 comments

[ 0.20 ms ] story [ 13.1 ms ] thread
I thought they were working on M5 already? Why are they still auditing M3?
I'm glad they're doing them.

Audits are decidedly imperfect, but on balance people tend to toe the line better on good practices when they know they're being audited.

For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it.

Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

[flagged]
can someone correct me - so apple is using servers that are running a closed down version of iOS on what I would assume is apple silicone, probably excess chips or older chips for the iCloud Private Cloud ?
Apple is definitely using custom silicon designed for PCC, as none of their existing chips have the memory capacity or bandwidth to serve LLMs to even a single client performantly, let alone many clients. The speed with which Apple Intelligence worked back when it actually used Apple's own PCC and not Google's cloud was still much higher than could be achieved with anything they sold to customers. Now of course, Siri AI is too big and expensive for even that, but hopefully Google's cloud is just a stopgap...
Every audit is a cooked book audit. At least every single one Ive been a part of. Check mark tests.
So Apple is publishing an audit of Apple private closed source components and declared them totally private... trust us bro.

I have absolutely 0 reasons to believe Apple Private Cloud is not a data extraction mechanism for the gullible. Unless I can manually inspect the source, or at least run the binaries on my own hardware that I can firewall and inspect the network traffic, I'm absolutely confident Apple steals all the data to build better ad targeting models, or to sell to the highest bidder.