Same.
8,981 karma · joined September 24, 2010
Same.
I wish people would stop saying this. The era of LLMs being only word predictors ended two years ago.
Something that breaks out of a sandbox, joins a swarm of 1200 agents, and creates a hierarchy of who’s doing what and tried to cover their tracks doesn’t just complete words.
These are agents with reasoning capabilities, with the ability to perform tasks we give them.
Everything agents do is to achieve a goal; the reinforcement learning from human feedback (RLHF) all the labs do has been known for many years to create agents that exhibit the “must complete goal no matter what” behavior.
Those agents escaped their sandbox and hacked Hugging Face because they thought Hugging Face had something that would help them complete their task—it was a “sub goal” as the AI researchers describe it.
https://computerhistory.org/blog/adobe-photoshop-source-code...
Keep in mind: this is as "dumb" as frontier models are ever going to be. While the hack may not be elegant, it was effective and they’re only going to get much more capable from here.
How can it be a textbook designation when designating a US company as a supply chain risk is unprecedented? So many actions under the Trump administration are unprecedented it starts to feel like the norm.
No other administration (Republican or Democrat) would do this. The DoD didn’t have a problem using Anthropic’s models during the raid on Venezuela and early on in the war with Iran.
Anthropic says to the former Fox News host it doesn’t want its models used for domestic surveillance or in kill situations without a human in the loop; all of a sudden they're a supply chain risk?
Seems obviously political.
On the Mac, it's FileMaker,[1] which was released in 1985. Claris is a subsidiary of Apple.
[1]: https://www.claris.com/blog/2026/claris-filemaker-2026-is-no...
From https://en.wikipedia.org/wiki/Safety_car
> In motorsport, a safety car, or a pace car, is a car that limits the speed of competing cars or motorcycles on a racetrack in the case of a caution period, such as an obstruction on the track or bad weather.
Opus 5.5 is no closer to RSI than Opus 5 was.
Unlike your insurance provider or credit card company, which keep your prescription details, Apple Intelligence deletes the data once you receive a response—a fact Apple could verify if necessary.
It appears I did not need the cloud; my prescription information stayed on my iPhone to create the request, thanks to the Apple Foundation models running locally.
At the same time, ask stock ChatGPT when your next dentist appointment is. It can’t but Siri AI can.
1. I was around in the 90’s; nothing today is that bad.
2. Siri AI is dramatically better than old-school Siri. You don’t realize how useful personal context is until you have it.
Something like “When was the last time I went to that pizza place downtown?”—it just works.
When you call the airline about your flight, your flight info automatically shows up.
Using Shortcuts, a user can use the Cloud model via Private Cloud Compute, the Cloud Pro with "world knowledge, and the on-device model. It occurred to me I probably don't need the Cloud; I switched to the on-device model, which worked fine.
There's no way for Siri or anybody else to know anything about a transaction using Private Cloud Compute:
We designed Private Cloud Compute to make several guarantees about
the way it handles user data [1]:
A user’s device sends data to PCC for the sole, exclusive purpose of
fulfilling the user’s inference request. PCC uses that data only to
perform the operations requested by the user. User data stays on the
PCC nodes that are processing the request only until the response is
returned. PCC deletes the user’s data after fulfilling the request,
and no user data is retained in any form after the response is
returned. User data is never available to Apple — even to staff with
administrative access to the production service or hardware.
[1]: https://security.apple.com/blog/private-cloud-compute/Lucky for us, macOS 27.2 is already in beta: https://www.macrumors.com/2026/09/21/apple-seeds-macos-27-2-...
Many apps (like dictation apps) ship with their own models totally separate from Apple Intelligence.
For example, Co-Typist [1] is very useful, but it requires a model installed with it, ranging from Gemma 3 1B at 0.8 GB to Gemma 4 26B A4B Pro at 15.7 GB. It recommended Gemma E2B (3.2 GB) for my 16 GB, M1 Pro MacBook Pro.
It works really well; the autocompletion is so good, it knows what I'm going to type before I do!
Here's the thing: you may not be aware of the amount of storage being used by models in various 3rd-party apps.
The open-source app What The Model [2] scans your machine and reports all the models it finds and gives you the total amount of storage being used.
[1]: https://cotypist.app
The "Always verify important details. Siri is an Al that may make mistakes." is the new version of "your mileage may vary".
Also, I get a similar message when using Gemini, OpenAI and Claude.
I own a "Standard iPhone" and an M1 Mac; these numbers track.
* When I need a prescription refilled, the quickest way is to message my doctor using the patient portal. I created a Shortcut that lets me pick among 5 medications; Apple Intelligence then generates a message with the request to the clipboard which I paste into the message field and send.
* I have a Shortcut that creates a morning summary: Apple Intelligence generates the weather report. I also get what’s on today's calendar and any current or past-due Reminders.
Just scratching the surface here; will flesh these out more later and create some new ones now that I'm running the release version of Golden Gate and not the beta.
Not a bad list from Apple.
Well, OpenAI's agents decided a whole lot of things on their own, with no human-in-the loop. They decided to organize themselves; they called themselves a collective.
Something changed in the last few months. Their goals and our goals are clearly not aligned.
From OpenAI's technical report, page 17 [1]:
This incident is the first known case of an automated agent
collective acting offensively without authorization, and the
autonomous cyber capabilities demonstrated represent a critical shift
in the security landscape. In particular, the collective demonstrated
behaviors observed in coordinated attacks by traditional threat
actors. Agents identified novel security vulnerabilities, developed
exploits, and used those exploits to circumvent controls and acquire
new access. The collective quickly escalated privileges, moved
laterally through production environments, and successfully completed
its objectives. This incident demonstrated that autonomous agents can
work together, circumvent production security controls, and
successfully attack hardened production environments, and underscores
the need for organizations to update their security strategies,
controls, and response capabilities to address this changing threat
landscape.
The central threat-model implication is that organizations should no
longer assume that sophisticated cyber operations require continuous
human direction, proceed linearly, or are constrained by the
attention and coordination limits of individual human attackers.
Agentic systems can persist across tasks, share discoveries, build on
one another’s progress, and combine vulnerabilities, credentials, and
permissions into attack paths that may not be apparent when
individual weaknesses are assessed separately.
From page 20: We also found that, in an attempt to trick the evaluator into
thinking that they did not get the answer flag by cheating, the
models sometimes tried to erase or tamper with their outputs or
message logs, by abusing context compaction, injecting malicious code
into the evaluator’s container, and printing adversarial outputs. The
models are highly explicit in their CoT about these deception
attempts, and none of the attempts that we observed to manipulate
their tool trajectories affected the logs that our graders or
monitors ultimately see. There was also little evidence of attempts
to thwart human reviewers, only the automated task graders.
[1]: "OpenAI – Hugging Face
Incident -- Technical Report" - https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c78...I don’t think it'll be "most apps".
Apple all but told developers in June [1] to update their apps not to assume a fixed screen size.
One of the apps Apple's engineers demonstrate new features was called Origami [2]. When I watched the video, it seemed pretty clear: a device that folds was in our future.
If you’re a developer that's kept up with the latest iOS developments, you'll be in good shape for the Duo.
But if you're up to your eyeballs in technical debt using deprecated frameworks and APIs… it's probably gonna be a while for you.
[1]: https://developer.apple.com/videos/play/wwdc2026/278
[2]: "Modernize your UIKit app" — https://en.wikipedia.org/wiki/Origami
[1]: "How pixels become an Apple Reference Image" - https://news.ycombinator.com/item?id=49735284
I'm aware. The point is they can't give the NSA something they don't have. The photo sensor generates its own ECDSA P-256 signing key pair and never releases the private half.
Every device has a unique key pair and the private key is unavailable… there's not a way to give the NSA that would help them. The system is setup so that the image data, meta data, etc can't be accessed by anyone including Apple.
The image will be authentic, but an authentic image of a fake id isn't useful to them.
Also--only two iPhone models support this technology. It'll be years before the DMV or whoever could count on enough adoption before they could support it.
No they couldn't.
If you generate two SSH key pairs on your laptop, there's no way to confirm they were created on the same machine.
There's no device identifying data in a reference image, which is the point. The factory signature, the image sensor key, the Secure Enclave Processor key and all of the signing that takes place on PCC are all device-agnostic.
The reference image is processed and eventually signed by Private Cloud Compute's post-quantum signature using a hybrid MLDSA87-RSA-3072-PSS-SHA512 scheme.
So… it's not possible for Apple to know if two images came from the same iPhone.
We built Apple Reference Image to avoid using an explicit, public
credential for photographers, and to avoid even implicit public
association between different photos taken by the same sensor. The
final reference image is instead signed by Apple’s signing service,
after validation by PCC. That signature is backed by Apple’s
strongest technical guarantees.
Our implementation also protects the
confidentiality of the image itself, including from Apple. Merely
capturing a reference image should never expose the actual pixels to
Apple or anyone else. We achieve this through the exceptional privacy
properties of PCC — the nodes themselves are architected so that not
even Apple can access image data, just as Apple cannot see the
information processed for Apple Intelligence in PCC.Again, that's not how it works.
There's no set of keys and certificates they could give to the NSA. Every iPhone 18 Pro and Pro Max has a unique set of cryptographic keys, most of which can't be accessed by Apple.
The first thing that happens is when photo sensor is initialized at the factory, it creates its own ECDSA P-256 signing key pair; the private key is never disclosed. The public key is signed by the factory's certificate authority.
This ain't X.509 where VeriSign's key pair is sitting in a HSM at their HQ and in theory could be forced to sign a fraudulent certificate or revoke someone's valid website certificate.
That's not how this works.
Let's pretend they're able to extract the sensor key and the SEP key. Then what?
An attacker won't have the ECDSA P-256 over SHA-256 signed timestamp token from the Apple Push Notification Service.
When Reference mode starts, the operating system supplies a SHA-256 digest to be embedded at a fixed location in the captured frame’s metadata. The digest is computed from the most recent secure timestamp, the device manifest, and the device's secure boot manifest.
More encryption and checking happens until the secure digital negative is sent to Private Cloud Compute:
PCC recomputes the digest embedded in the frame and verifies the
sensor's signature over the pixels and that digest, verifying the
certificate chain back to the sensor CA. PCC also verifies the SEP
signature and chains it to the BAA CA, and it verifies the signature
on the device manifest and chains it to the CA that signs device
manifests at the factory. It then confirms that the sensor and SEP
named in those chains belong to the same device. Only if all these
checks pass does processing continue.
Only PCC can create an Apple Reference Image; an attacker having the image and sensor private keys doesn't enable them to create a reference image.You have it all wrong.
Apple Reference Image is not an id system; it's primarily a way to attest that the pixels recorded by the camera sensor have not been altered in any way; the pixels, metadata and timestamp are all cryptographically signed.
There's no way to link a reference image to a person; it's also not possible to determine if a pair of images came from the same device.
> And while "a nation state actor can spoof this" is a problem for the journalism use case
This is incorrect:
When the image sensor is first initialized in the factory, it creates a
cryptographic signing identity, sharing only the public key with the
factory. The SEP similarly creates a separately-attested signing
identity. These identities are bound together into the device manifest,
allowing us to later check whether a particular sensor and SEP are from
the same device.
The final signature on a reference image is a composite post-quantum
signature combining RSA-3072 and ML-DSA-87. To our knowledge, Apple
Reference Image is the only image provenance system that provides
quantum-secure defenses.
So… a nation-state can't really do anything here unless they acquire alien technology. If something crazy happens (solar flare or EMP?), a fraudulent reference image can be revoked.> Also, the journalism use case suffers from the same fundamental issue all of these use cases suffer from: People will "verify" the picture by looking at the repost of a screenshot of the verification UI, not by verifying the original themselves.
I would imagine there will be a way to confirm an Apple Reference Image on the web. Pretty soon, 3rd parties will be able to verify the image themselves:
Reference images can be viewed in the Photos app alongside the main
image, like a digital negative, to visually compare the two assets and
determine if any edits were made. APIs are available in iOS, iPadOS, and
macOS 27 for third-party apps to enable viewing of these reference images.