the fUtUrE oF cOmPuTiNg lmaoRemember on AVP launch day when pundits were trying to convince people that, like, their dentists would be wearing AVP soon? All the while the internet was just viciously roasting the thing. 🤣
the fUtUrE oF cOmPuTiNg lmaoRemember on AVP launch day when pundits were trying to convince people that, like, their dentists would be wearing AVP soon? All the while the internet was just viciously roasting the thing. 🤣
The answer is a lot simpler. Just put in the Apple User Agreement something like, "If your data is leaked by Apple or its subcontractors Apple will compensate the User a minimum of $100,000".How about if a panel of respected computer experts carefully selected from academia and industry and vetted and supervised by a panel of international judges were allowed full access to the Google code that Apple was running on its servers and could go through it line by line to confirm that no data was being leaked out to Google before the system was allowed to go live (even if that took years)? Would that prove that the code was safe? Well no because who's to say that somehow every one of those experts and everyone on the overseeing panel hadn't been bribed to say that everything was OK when it wasn't.
That's obviously a pretty silly (extreme) example but I was trying to make the point that in reality no one can 100% prove anything if you're willing to ramp up your distrust to a high enough level. Once you reach a certain level of suspicion the only solution is to stop using computing devices at all.
One possible sensible answer to at least achieve a high level of assurance would be for Apple to use monitoring software to monitor network traffic going in and out of its data centres and look for any suspicious activity that might indicate transfer of data outwards to some external server. I would be pretty confident that such perimeter monitoring is happening anyway, at least on critical Apple systems. That for instance is what alerted LastPass some years ago that it had a data breach in its password manager infrastructure when some unusual network activity alerted it to the fact that someone was doing unauthorised downloads of large quantities of data. (Luckily all the passwords that the hackers downloaded were zero-knowledge encrypted. I was a customer at the time and didn't have any of my passwords compromised.)
Yes indeed.If anyone here thinks there is anyway to completely keep your info private you are fooling yourself. Nothing is private. Only way is to live in cabin in the woods with no contact with the outside world.
Use the word privacy often enough and the public will believe it. Especially those living in a TLDR world.Very curious how Apple intends to pull this off from a privacy angle.
Think you got that backwardsThe next logical step: merge iOS and Android? All the features of iOS with the "security" of Android?
I literally did — I laid it out for you — a requirement of public transparency, the usage of Private Cloud Compute, and the additional incentive third-parties have to prove someone who vocally makes claims of privacy to not only be caught lying, but actually has a reward set up for anyone who finds issues.All I said is that you can't prove it and you still have not. In your example of recordings for training, all that happened is they said, "Oops, our bad". But the data was still used.
Sure public pressure can do a lot, but that still does not mean it is secure and your data is not shared unless it is in the Usage Agreement. Which it won't be, because it is too much of a liability.
Read the information — Google won’t be holding any data, hosting any of the software, connecting to any of it’s services, nor involved in transmission of data. It is exactly like how it works with anonymous ChatGPT if not logged into an individual account — an extension that runs locally — and if anything needs to be sent out — it only goes to Apple's Private Cloud Compute... Not any Google servers. Literally all they are using is the machine language model, nothing else. It isn’t just sending the request to Google’s Gemini implementation.But how can Apple, as a champion of privacy, justify this marriage with Google's Gemini?
Read the information — Google won’t be holding any data, hosting any of the software, connecting to any of it’s services, nor involved in transmission of data. It is exactly like how it works with anonymous ChatGPT if not logged into an individual account — an extension that runs locally — and if anything needs to be sent out — it only goes to Apple's Private Cloud Compute... Not any Google servers. Literally all they are using is the machine language model, nothing else. It isn’t just sending the request to Google’s Gemini implementation.
I understand your arguments but they rely on one trusting a company ... any company. The companies we are talking about are huge, and not all their employees, even (especially?) at the senior level, are necessarily honest. There's a lot of intra-company politics that might tempt some to take shortcuts to "success" within the company.
In Apple's case, there are numerous examples of successful lawsuits against them in which they stole ideas, or failed to pay royalties on inventions or previously-licensed software. I have experience of a particular case, and ultimately this was due to a small group of employees thinking they could save a little money for Apple by stopping agreed licence payments for SW used in the then-current iPhone models. It was not official Apple policy to be dishonest, but it happened anyway.
That's the problem ... can we trust what companies say about privacy?
With respect, you are conflating issues. I agree — people shouldn’t just trust companies at their word — but that’s not what is happening here. From a privacy standpoint, apple has provided third party transparency for Private Cloud Compute — so they made a "framework for allowing independent security experts and researchers to verify that user data remains private during AI processing". This initiative moves beyond traditional "trust us" cloud models by enabling external validation of Apple’s security promises, such as stateless processing and data encryption. It can be independently verified. Apple publishes cryptographic, tamper-proof logs of all code running on PCC nodes. They make the binary software images (operating systems, applications, and executables) used in production available for independent inspection. Apple provides a VRE that simulates the PCC environment, allowing researchers to analyze the software, identify vulnerabilities, and verify functionality. Also, to incentivize inspection, Apple offers up to $1 million for identifying significant security or privacy breaches in the PCC system. They go beyond the industry standard to provide transparency in this area — they shouldn’t get a pass on other things because they are doing things right here but with the same token they shouldn’t be punished here for things they have done in the past in other avenues.
You have valid points (and I share them) about these other situations — and not just about apple, but all companies — but this is not that. We have to put our biases aside and judge situations in isolation. On this, they are approaching privacy correctly, and better than other companies by a large margin.
I defer to your understanding of this topic, which is far deeper than mine.
But I'm still uncomfortable about the possibility of internal actions inside Apple, where employees do not follow company policy (at least, stated company policy).