• 0 Posts
  • 50 Comments
Joined 6 months ago
cake
Cake day: February 1st, 2026

help-circle











  • I know what I am talking about, but I cannot dissect the entire document in a comment. And even so it is worthless as it is not a technical document but something completely vague. Most of the stuff there is industry standard elevated (code signing, secure boot, memory safe languages, pointer authentication, encryption, stateless processing).

    The document totally ignore the elephant in the room: the trust root is circular -> iphone verify attestation correctly. So Apple controls client, keys, logs and servers. This is only as safe as much as I trust Apple. Transparency log is run by Apple only, and nothing guarantee that my device log will be the same as the researchers (and with 90 days delay).

    They actually admit to unmitigated memory remanence issues with the all “the address spaces are periodically recycled to limit the impact of any data that may have been unexpectedly retained in memory”

    How does Apple does moderation if the claim of stateless processing is true?

    There is more stuff for sure, but I got bored very fast looking at that document.


  • So Apple is saying: I will give Siri AI unrestricted access to user data and app because I trust my AI is good enough that it does not need a safety framework (permissions, visibility, accountability) to protect user data. But while Siri AI is safe (trust me bro), other AI provider are not so we will block them because the same unrestricted access we give Siri AI would cause issues. You see how delusional that sounds?

    Reality, step by step, is:

    1. Siri is trash
    2. Please Google, give me an AI model that is good enough
    3. Creating a safe environment for the model is hard, takes a lot of time, and the experience is bad for the user as security add too many blockers to the features
    4. I can bypass all this complexity by just telling the AI not to do unsafe stuff
    5. I cannot give third party access in this state, and I do not want to do it anyway as I like to keep total control like I do with App store. EU sucks







  • This statement tells more about Apple than about EU. What DMA says is that third party API access must be on the same level as first party API access.

    Apple would have to give any virtual assistant direct access to users’ private data — and the ability to directly control other installed applications

    This simply means that Siri AI has direct access to users private data and the ability to directly control other installed applications.

    the DMA requires Apple to give any AI system nearly unlimited access to a user’s device, as well as the ability to act on that access autonomously without a user’s ongoing visibility and control. That includes the ability to read and send messages, make purchases, access files, and execute actions across any app.

    This is what Siri AI is doing.

    The EU rejected Apple decision to not follow the law by giving Siri AI privileged access to users private data and apps while preventing others to do the same.