Apple open-sources its Homomorphic Encryption library
thestack.technology
thestack.technology
https://www.swift.org/blog/announcing-swift-homomorphic-encr...
Intro:
Homomorphic encryption (HE) is a cryptographic technique that enables computation on encrypted data without revealing the underlying unencrypted data to the operating process. It provides a means for clients to send encrypted data to a server, which operates on that encrypted data and returns a result that the client can decrypt. During the execution of the request, the server itself never decrypts the original data or even has access to the decryption key. Such an approach presents new opportunities for cloud services to operate while protecting the privacy and security of a user’s data, which is obviously highly attractive for many scenarios.Q: Does this mean that encrypted data (stored files, communications via messengers etc) can be scanned for keywords, without the need to decrypt the entire file/message?
If so, isn't this a huge privacy problem?
https://developer.apple.com/documentation/sms_and_call_repor... (and links from there).
It seems (at a very high level) for 3rd parties to be able to hook into the incoming phone call path and filter what a user might see based on data of a server they control.
I don't quite understand it (so would be happy if people could fill me in). My naive guess is that this is to prevent such a service from getting a phone number, and instead get a blob that one can work on via HME means. That seems obviously wrong though, because if I'm using this encrypted blob to look up phone # data to return (spam et al) metadata to the user, presumably I created the data set locally, so could associate the incoming blob to an actual number then.
Not an expert but my understanding is that you can vend encrypted versions of otherwise proprietary datasets semi-publicly for random data scientists to do prediction on, then translate those predictions back to the prediction space you care about (e.g. stock price).
https://www.jeremykun.com/fhe-in-production/ seems worth glancing at, good detail but very few strong examples.
I was under the impression here, that I hand you an encrypted phone number and you provide meta data back suggesting scam / known business / etc. Hence having trouble grasping how you can mathematically approach a phone number you wouldn't know to then change it.
I recognize the use-case, have you the service provide info/data back based on my query, and I don't want you to know I am receiving a call from said phone#. But what do I add to the phone number when querying you the service or what are you adding via FHE operations? Or why are you adding to the phone number that you can't know? What results from the addition when I'm decrypting, a longer phone number or additional results regarding the unknown phone number?
Separately, why would I provide this service two phone numbers to then multiply? I'm not sure the axis which would result, but the string I would expect is not a valid phone number and wouldn't result in my knowing more than before? Are there other technical aspects which cause add / multiply to be novel per implementation which isn't resulting in classical plaintext data actions?