Volume 58
Volume 58 | June 11, 2024
Welcome to Brief 58, titled Apple's annual "World Wide Developer's Conference" (WWDC) from an Access Control Perspective” by Jonathan Hays, CEO of Silverpine and Access Control Executive Brief member.
In Brief 58, we have a special (and timely) contribution from Jonathan Hays, the CEO of Silverpine. Jonathan was fortunate enough to be among the attendees of this year's Apple World Wide Developer's Conference (WWDC). In his Brief, Jonathan delves into what was unveiled at the event, focusing specifically on its relevance to the access control industry. He discusses the significant updates across various operating systems and the implications of new features like AI and wallet metadata enhancements. Jonathan also highlights the meticulous planning and execution of Apple's security team during the event. Take advantage of his insightful analysis and firsthand experience at the WWDC. He is active on our member Slack channel, so please reach out to him there or on LinkedIn.
Thank you, Jonathan, for sharing your perspectives and for the quick turnaround on this Brief!
As always, your feedback is invaluable to us. Please let me know if there's any area where we can better meet your expectations.
Thank you!

PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!
Apple's annual "World Wide Developer's Conference" (WWDC) from an Access Control Perspective
by Jonathan Hays, CEO, Silverpine
Keynote stage at WWDC
Apple's annual "World Wide Developer's Conference" (or WWDC as it is more commonly known) took place yesterday at Apple's headquarters in Cupertino, California. The invite-only event brought approximately one thousand developers and press into Apple's incredibly impressive facility, where Apple unveiled the biggest changes to its upcoming operating system releases.
This year, there were a number of leaks ahead of the event, so some of the high-level details were largely known, but hearing information through unofficial channels versus hearing an official proclamation from Apple are two very different things.
Overall, the keynote was packed with announcements and improvements across VisionOS, TvOS, iPadOS, iOS, and MacOS. Many changes are designed to allow a greater customization experience for devices and a blend of things that make common tasks easier.
From an access control perspective, there were only a few announcements that might materially impact strategy or implementation. For example, there were no changes or improvements announced regarding NFC or Bluetooth.
On the small scale, Apple did announce additions to the wallet metadata experience that should allow wallet passes to include additional information to the user. Apple also added the ability for apps to introduce customized Control Center widgets that allow apps to quickly trigger actions. This includes the ability to launch an app action directly from the lock screen by replacing what are currently the camera and flashlight buttons. For access control systems that need to implement more than the simple Wallet tap to open, these are huge improvements.
On a larger scale, Apple finally introduced AI as part of its long term strategy. While the fact that AI would be a major part of this announcement was known, many of the specifics were not. What was revealed was a multi-prong approach that Apple is still at the very beginning of executing.
Tim Cook’s keynote at WWDC
The first prong of the strategy is that for many simple tasks, the "Apple Intelligence" features will run on-device without need for cloud computing. Things like asking Siri to schedule an appointment or help rewrite an email response will all occur privately on the device without ever having to transmit data.
However, Apple acknowledged that this won't work for more advanced features so they also introduced what they have dubbed as "Private Cloud Compute". This is the second prong of their strategy and they introduced a number of core principles within this framework to try and engender trust: stateless computation, enforceable guarantees, non-privileged runtime access, non-targetability, and verifiable transparency. Some of this could be vague hand-waving, but they did pledge to open source images of their server implementations to allow security researchers to validate their claims.
Finally, the third prong of their strategy is to (eventually) allow third party models to be plugged into their system. The first officially announced model to be supported is ChatGPT, but it won't be available until later in the year. This is the most unclear part of their implementation, and more details are expected to be revealed later.
From a hardware perspective, all newer M series devices and the latest A17 Pro chip in the iPhone 15 Pro are capable of running these new features. Older devices appear to be out of luck in regards to Apple Intelligence features, and this is clearly a key aspect of the forced upgrade cycle for Apple.
Every detail covered at WWDC
For application developers, the amount of AI related functionality that can be added is somewhat limited in scope. Apple is taking a cautious approach here, and much of the initial AI feature set will be found in built-in Apple apps and in high level widgets that will offer very little customization to developers. The message, however, is clear: AI is here to stay. Apple's approach is much more conservative from other companies in the same space, but they also aren't backing down.
For access control developers, there are going to be a lot of subtle implications that will become more clear as Apple reveals more details of their implementation over time. AI was a large topic at the recent ACS24 Europe event, and as an industry we are paying attention. But there isn't an obvious set of "must have" AI features, yet. As Apple opens up more capabilities, we will begin to see innovation in this space.
The convergence of AI and wallet features have put the mobile device at the forefront of changes to the access control ecosystem, so when Apple announces new capabilities in this space, it's worth paying attention. And while this year's WWDC didn't have an obvious thrust for the access control industry, there are a number of changes that align with where we are headed as an industry.
A view inside Apple’s HQ
On a related side note, the Apple campus is one of the most amazing architectural marvels I have ever witnessed. Seeing images and videos of the circular building do not do justice to the enormity of what the late Steve Jobs envisioned for his company. The building itself is a complete mile in diameter made completely of glass. It also has an enormous 4 story sliding glass door that can be opened and close to open up the guest atrium.
In addition, the Apple security team must be one of the best in the business. The event required every attendee to have an NFC enabled badge that was tied to a photo of the attendee that was taken upon badge issuance. It was also verified against a government issued id, and this process was repeated for almost 1000 visitors in a single day. In addition, access to the event was controlled for both arriving and departing attendees, and yet the campus and building were open to a degree that you felt like you were free to roam freely. The security team's operational efficiency combined with the enormity of the building was truly amazing. If you ever have the chance to visit the campus, do not turn it down.
Jonathan presenting at ACS24 Europe