Most sysadmins know that hash matching only mitigates a small subset of rare upstream attacks. Apple could still be MITMing the whole thing (SSL added and removed here :)) and no auditor would get the chance to check. The offered audit is so weak that I would not trust any FAANG business to administrate it.
Apple is once again demanding arbitrary centralization to give them an undeserved veto power. None of this is for security.
Just have an open house for anyone interested to come poke the hardware and software?
By the sound of it, Apple's offered audit doesn't include insight into the most dangerous parts of a system like this. This could easily lead to a situation where real security experts are denied access to promote influencer-adjacent Yes Men who rubberstamp the hashes matching without any question.
Hence my concern for "SSL added and removed here" - none of Google's famously backdoored infrastructure will be audited. For privacy purposes, Apple's promise is woefully incomplete.
How I understood it that they want _actual_ security researchers, not some random dude who once installed Kali Linux and ran nmap.
It's state of the art private compute according to actual experts and everyone will be wasting their time if the "researchers" need to be coached through the process and explained the basics of the system's operation.
So if they did that here, I doubt the EU would accept it. And even if they did as soon as a competitor of any side/credibility cried foul I’m sure the EU would make life very hard for Apple to prove they’re not being unfair in even the tiniest way.