Security

Just how private is Apple's Private Cloud Compute? You can test it to find out

Also updates bug bounty program with $1M payout


In June, Apple used its Worldwide Developer Conference to announce the creation of the Private Cloud Compute platform to run its AI Intelligence applications, and now it's asking people to stress test the system for security holes.

Apple has revealed that the platform (PCC) runs on custom-built server hardware and runs a specially hardened operating system derived from the same code base as iOS and macOS. It's also issued a security guide to the system, and pentesters can set up a Virtual Research Environment that investigators can use to examine the platform's strengths and weaknesses.

"In the weeks after we announced Apple Intelligence and PCC, we provided third-party auditors and select security researchers early access to the resources we created to enable this inspection, including the PCC Virtual Research Environment (VRE)," the Apple Security Engineering and Architecture team wrote in a blog post on Thursday.

"Today we’re making these resources publicly available to invite all security and privacy researchers – or anyone with interest and a technical curiosity – to learn more about PCC and perform their own independent verification of our claims."

Apple is also releasing the full source code for some elements of the PCC, namely:

To further incentivize white-hat hackers, the fruit cart is also offering serious money for flaws. If you can remotely pull off arbitrary code execution with arbitrary entitlements there's up to a million dollars to be had, with $250,000 if you manage to pull data off a user's device. There are also bounties between $50,000 and $150,000 if you can hack the system from a privileged network position.

"We hope that you'll dive deeper into PCC's design with our Security Guide, explore the code yourself with the Virtual Research Environment, and report any issues you find through Apple Security Bounty," the team declared.

"We believe Private Cloud Compute is the most advanced security architecture ever deployed for cloud AI compute at scale, and we look forward to working with the research community to build trust in the system and make it even more secure and private over time." ®

Send us news
14 Comments

Apple throws shade on pokey AI PCs, claims its maxed out M4 chips are 4x faster

Busy week for Cupertino sees shrunken Mac minis, updated lappies, and new SoCs

Sysadmins rage over Apple’s ‘nightmarish’ SSL/TLS cert lifespan cuts plot

Max validity down from 398 days to proposed 45 by 2027

Wanted. Top infosec pros willing to defend Britain on shabby salaries

GCHQ job ads seek top talent with bottom-end pay packets

As Arm rivals cook up custom silicon, Mediatek sticks to tried-and-true Cortex recipe

Exec Chris Bergey tells us what the chip designer is doing to stay competitive

Apple quietly admits 8GB isn't enough in 2024, M4 iMac to ship with 16GB as standard

The silicon no longer limited to Cupertino's priciest iPads

Five Eyes nations tell tech startups to take infosec seriously. Again

Only took 'em a year to dish up some scary travel advice, and a Secure Innovation … Placemat?

Millions of Android and iOS users at risk from hardcoded creds in popular apps

Azure Blob Storage, AWS, and Twilio keys all up for grabs

Apple beats expectations, but drops in China

India saw an all-time revenue record and is poised for four more physical stores

Windows Themes zero-day bug exposes users to NTLM credential theft

Plus a free micropatch until Redmond fixes the flaw

Uncle Sam outs a Russian accused of developing Redline infostealing malware

Or: why using the same iCloud account for malware development and gaming is a bad idea

Sophos to snatch Secureworks in $859M buyout: Why fight when you can just buy?

Private equity giant Thoma Bravo adds another trophy to its growing collection

The billionaire behind Trump's 'unhackable' phone is on a mission to fight Tesla's FSD

Dan O'Dowd tells El Reg about the OS secrets and ongoing clash with Musk