> It's a useless PR tactic.
Maybe because a single whistleblower would bring down the mother of all class action lawsuits?
Hardcore anti-corporate types like to imagine that these companies are evil geniuses, where all 100,000 employees are operating in perfect alignment, with no mistakes or disagreements, and all secrets are kept perfectly.
It just doesn't work like that. Threat model it for a second: how many more phones is Apple going to sell with this? Maybe a 1% increase, to wildly overestimate it? And what would be the financial harm from a single engineer popping on HN and saying "it's all BS, phones send the keys to the cloud, I worked on the system to store them."?
> There's absolutely no _technical_ thing they could do to gain any trust.
Well, that's true. But there's also no non-technical thing they could do. It is literally impossible to prove perfect technical compliance on an ongoing basis using any combination of technical and non-technical means.
That goes for open source too. Evil compilers, etc, can turn perfectly solid source into malicious binaries. The compiler's source can even be perfectly secure.
At some point you have to think about probabilities and motivations, and move away from this "anything not 100% perfect, which BTW is not possible, is 100% useless" world view.