6 ms·
Apple Private Cloud Compute SoC 3 audit reports
- bstsb 2mo agothe page keeps 301ing to the home page for me - could be a region issue https://archive.ph/JYC9B https://archive.ph/JYC9B
- rogerrogerr 2mo agoWorks for me on a major US cell network.
- fuomag9 2mo agoSame in Italy
- qurren 2mo agoI thought they were working on M5 already? Why are they still auditing M3?
- brcmthrowaway 2mo agoThats the only Studio available
- Havoc 2mo agoI'm glad they're doing them. Audits are decidedly imperfect, but on balance people tend to toe the line better on good practices when they know they're being audited.
- arkadiyt 2mo agoFor anyone unaware, a SOC3 is just a SOC2 with the audit details removed - it includes a high level statement from the company (Apple) and from the auditor (EY), that's it. Also Apple certainly does invest heavily in security and privacy but SOC2's are so commoditized that it's like saying "look I can afford 50k", it's not particularly interesting
- datakan 2mo agoEveryone lies on SOC2. Auditors don't understand the technologies and just take peoples word for it. It's a shit practice
- paulryanrogers 2mo agoCitation needed. This is not my experience at all, after participating in such efforts at three different companies.
- datakan 2mo agoI'll just cite my 30 years in IT/InfoSec. Believe it or not, I really don't give a damn. It's common knowledge int he field regardless of what your experience is.
- paulryanrogers 2mo agoCan you name the names of SOC auditors that are rubber stamping? Or point me to some public critiques within the industry?
- an0malous 2mo agoWasn’t that YC startup Delve doing exactly this? https://www.iansresearch.com/resources/all-blogs/post/security-blog/2026/04/19/delve-allegations-expose-weak-points-in-modern-compliance https://www.iansresearch.com/resources/all-blogs/post/securi...
- paulryanrogers 2mo agoThat I'm familiar with. Is it part of a trend or just one bad apple?
- tptacek 2mo agoI wouldn't put it the way they did but they're directionally sane about this. I would worry a lot more about someone repping their SOC2 as important or meaningful than I would worry about someone who was cynical about SOC2. (I don't mean Apple; Apple spends more on security than almost any firm in the world.) https://fly.io/blog/soc2-the-screenshots-will-continue-until-security-improves/ https://fly.io/blog/soc2-the-screenshots-will-continue-until...
- jtrn 2mo ago[flagged]
- throwfaraway4 2mo agoImagine the security for the high value products
- jtrn 2mo ago"Here are 2 things, but you can only have 1," it seems.
- dzonga 2mo agocan someone correct me - so apple is using servers that are running a closed down version of iOS on what I would assume is apple silicone, probably excess chips or older chips for the iCloud Private Cloud ?
- LoganDark 2mo agoApple is definitely using custom silicon designed for PCC, as none of their existing chips have the memory capacity or bandwidth to serve LLMs to even a single client performantly, let alone many clients. The speed with which Apple Intelligence worked back when it actually used Apple's own PCC and not Google's cloud was still much higher than could be achieved with anything they sold to customers. Now of course, Siri AI is too big and expensive for even that, but hopefully Google's cloud is just a stopgap...
- ProAm 2mo agoEvery audit is a cooked book audit. At least every single one Ive been a part of. Check mark tests.
- pjmlp 2mo agoOut of that whole report I got this gem, macOS Security Compliance Project https://pages.nist.gov/macos_security/ https://pages.nist.gov/macos_security/
- gigel82 2mo agoSo Apple is publishing an audit of Apple private closed source components and declared them totally private... trust us bro. I have absolutely 0 reasons to believe Apple Private Cloud is not a data extraction mechanism for the gullible. Unless I can manually inspect the source, or at least run the binaries on my own hardware that I can firewall and inspect the network traffic, I'm absolutely confident Apple steals all the data to build better ad targeting models, or to sell to the highest bidder.