Implementation · Apple Private Cloud Compute

Google Cloud attestation combines affected TEE components

On this page

← All known flaws

SignificantOpen questionOpenInherited evidence

Evidence scope

An applicability question for PCC on Google Cloud, which uses Intel TDX. The cited attacks do not evaluate PCC's combined roots of trust, and do not attack its Apple-silicon deployment. A compromised TDX component alone does not establish a break of the complete PCC trust chain 3 7 9.

Apple reports that PCC on Google Cloud uses Intel TDX, NVIDIA confidential computing and Titan. Components that could exfiltrate user data if compromised have at least two independent vendor roots of trust, and attested keys are held in a separate confidential VM 3. The TEE findings document physical-host TDX forgery and an H100 relay demonstration 7 9. Whether PCC's combined protections resist those attacks remains an open question.

Sources: [3] · [7] · [9]

Search

Full search page