Comments

Hacker News

I thought they were working on M5 already? Why are they still auditing M3?

by qurren

So Apple is publishing an audit of Apple private closed source components and declared them totally private... trust us bro.

I have absolutely 0 reasons to believe Apple Private Cloud is not a data extraction mechanism for the gullible. Unless I can manually inspect the source, or at least run the binaries on my own hardware that I can firewall and inspect the network traffic, I'm absolutely confident Apple steals all the data to build better ad targeting models, or to sell to the highest bidder.

by gigel82

Every audit is a cooked book audit. At least every single one Ive been a part of. Check mark tests.

by ProAm

can someone correct me - so apple is using servers that are running a closed down version of iOS on what I would assume is apple silicone, probably excess chips or older chips for the iCloud Private Cloud ?

by dzonga

I'm glad they're doing them.

Audits are decidedly imperfect, but on balance people tend to toe the line better on good practices when they know they're being audited.

by Havoc

For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it.

Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting

by arkadiyt

Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • I thought they were working on M5 already? Why are they still auditing M3?
  • So Apple is publishing an audit of Apple private closed source components and declared them totally private... trust us bro.

    I have absolutely 0 reasons to believe Apple Private Cloud is not a data extraction mechanism for the gullible. Unless I can manually inspect the source, or at least run the binaries on my own hardware that I can firewall and inspect the network traffic, I'm absolutely confident Apple steals all the data to build better ad targeting models, or to sell to the highest bidder.

  • Every audit is a cooked book audit. At least every single one Ive been a part of. Check mark tests.
  • the page keeps 301ing to the home page for me - could be a region issue

    https://archive.ph/JYC9B

  • can someone correct me - so apple is using servers that are running a closed down version of iOS on what I would assume is apple silicone, probably excess chips or older chips for the iCloud Private Cloud ?
  • I'm glad they're doing them.

    Audits are decidedly imperfect, but on balance people tend to toe the line better on good practices when they know they're being audited.

  • Out of that whole report I got this gem,

    macOS Security Compliance Project

    https://pages.nist.gov/macos_security/

  • For anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it.

    Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting