HNHacker News
TopNewBestAskShowJobs

davidczech

112 karma · joined June 10, 2024

Secure Fruit Cultivator

https://davidzech.com

submissionscomments
davidczech··on We can now fix McDonald's ice cream machines
Isn't the same machine used for milkshakes? That's kind of staple of burger joints.
davidczech··on Security research on Private Cloud Compute
No, but the binaries executed will be available for download.
davidczech··on Security research on Private Cloud Compute
The OS build and cryptex binaries aligning to the hashes found in the transparency log will be made available for download. These are reconcilable with attestations signed by the SEP.

The source code provided is for reference to help with disassembly.

Edit link: https://security.apple.com/documentation/private-cloud-compu...

davidczech··on Security research on Private Cloud Compute
> cannot protect against that because Apple is a "trusted software publisher" in the chain.

That's the whole point of the transparency log. Anything published, and thus to be trusted by client devices, is publicly inspectable.

davidczech··on Security research on Private Cloud Compute
> It is a supply-chain / MITM protection measure

It is so much more than that, but you are entitled to your own opinion.

davidczech··on Security research on Private Cloud Compute
> How can anyone verify that all the code paths append to the log? I'm pretty sure they can just not append to the log from their ExfiltrateDataForAdvertisment() and ExfiltrateDataForGovernments() functions.

I think we have different understandings of what the transparency log is utilized for.

The log is used effectively as an append-only hash set of trusted software hashes a PCC node is allowed to run, accomplished using Merkle Trees. The client device (iPhone) uses the log to determine if the software measurements from an attestation should be rejected or not.

https://security.apple.com/documentation/private-cloud-compu...

davidczech··on Security research on Private Cloud Compute
> they can choose to emit whatever logs they want into the "transparent logs" and then emit whatever else they don't want into non-transparent logs.

The log is publicly accessible and append-only, so such an event would not go un-noticed. Not sure what a non-transparent log is.

davidczech··on Security research on Private Cloud Compute
Similar, but a lot of documentation is provided, source code for cross reference, and a VM based research environment instead of applying for a physical security research device.
davidczech··on Google must open Android for third-party stores, rules Epic judge
I wish that was true, but the exit and prompt return of seemingly every PC game developer back to Steam doesn't give much hope.
davidczech··on TouchArcade Is Shutting Down
Darn, I remember checking this website everyday for new games when I had the 1st generation iPod Touch.
davidczech··on Windows NT vs. Unix: A design comparison
Neo
davidczech··on AES-GCM and breaking it on nonce reuse
I've seen the problem surface in designs where a single key is shared across many devices.
davidczech··on Private Cloud Compute: A new frontier for AI privacy in the cloud
Servers send signed statements describing its state, and clients make the yes/no determination.
← PreviousPage 2 of 2