Private Cloud Compute (Apple Intelligence) Security Guide

(security.apple.com)

1 points | by mmooss 1 hour ago

1 comments

  • mmooss 1 hour ago
    The Guide describes in detail how Apple protects confidentiality of Apple Intelligence cloud transactions. Just the stated guarantees are impressive:

    * Stateless computation on personal user data: PCC must use the personal user data that it receives exclusively for the purpose of fulfilling the user’s request. User data must not be accessible after the response is returned to the user.

    * Enforceable guarantees: It must be possible to constrain and analyze all the components that critically contribute to the guarantees of the overall PCC system.

    * No privileged runtime access: PCC must not contain privileged interfaces that might enable Apple site reliability staff to bypass PCC privacy guarantees.

    * Non-targetability: An attacker should not be able to attempt to compromise personal data that belongs to specific, targeted PCC users without attempting a broad compromise of the entire PCC system.

    * Verifiable transparency: Security researchers need to be able to verify, with a high degree of confidence, that our privacy and security guarantees for PCC match our public promises.