upvote
Thats what Apple wants you to think. In reality it has nothing to do with privacy. Apple could let 3rd parties tap into these APIs but only after the user clicks away a big scary message telling the user they are leaving the comfort of the apple curated garden.

This allows competition, but also allows privacy for those who want it. See? Simple really, but Apple being Apple dont want to let 3rd parties use its AI APIs and so we have this standoff.

reply
Apple is using Cloud compute as well to enable Siri AI.

If you want to you could still use Apple or another provider you decide to trust - or even one that does everything locally. The competition would still have to follow GDPR after all.

reply
Apple PCC has been independently audited to be ultra secure.

Will the EU enforce the same for 3rd party integrations?

reply
If Apple had e.g. required competitors to undergo similar independent audits that would probably be allowed as it is quite similar to how Apple solved the third party app store issue.
reply
Are we sure the EU would allow that? Or would it be seen as a way to stifle competition?
reply
I mean, Apple's PCC audits require them to individually vet each auditor before they're allowed to see the PCC nodes.

If Apple extended that philosophy to other vendors then yeah, it would be deliberately unfair and anticompetitive.

reply
It sounds like they are whitelisting the hashes of all the Google software and OSes and stuff to ensure nothing is changed out from under them without them knowing.

Even if you could make all the other possible vendors run private cloud compute style stuff that would be a lot to manage.

And I can’t imagine the EU would like, and as a user I would certainly hate, the “OK you can use Grok but you lose all privacy too bad“ dialogue box they could make.

reply
I don't even think it offers a meaningful degree of security. It's a form of theater, you have to be hand-selected to perform the audit that Apple promised.

Most sysadmins know that hash matching only mitigates a small subset of rare upstream attacks. Apple could still be MITMing the whole thing (SSL added and removed here :)) and no auditor would get the chance to check. The offered audit is so weak that I would not trust any FAANG business to administrate it.

Apple is once again demanding arbitrary centralization to give them an undeserved veto power. None of this is for security.

reply
If they're not "hand-selected", what would be the way to select the auditors?

Just have an open house for anyone interested to come poke the hardware and software?

reply
This is mostly wrong. The DMA has a process to determine if a service provider acts a gatekeeper to the market, and let's be honest if Apple is not one, then I don't know who else besides Google.. So there is no privacy argument in there except Apple didn't want to design a interface that complies and is safe.
reply