Apple cut ties with server supplier Super Micro Computer in 2016 after unearthing a potential security vulnerability in at least one of its data center servers, reports The Information.

The vulnerability in the server, which was part of Apple's technical infrastructure powering its web-based services, was discovered in the early months of 2016. According to Super Micro senior vice president of technology Tau Leng, Apple ended its business relationship with Super Micro Computer shortly after uncovering the security issue.

supermicro
Leng's account of the incident makes it sound like Apple received bad firmware from an FTP site hosted by Super Micro that may have been infiltrated, which may have compromised the server.

According to Leng, when Apple was asked to provide the version number of the firmware it had downloaded after experiencing issues, Apple provided an invalid number. After that, Apple refused to provide more information to Super Micro.

Mr. Leng said Super Micro regularly provides firmware updates that data center customers like Apple can download from a private "FTP" site, hosted by Super Micro. He said the firmware updates come from outside chip manufacturers--in this case, a networking chip maker that he declined to name.

Sources who spoke to The Information said servers that handled Siri requests and App Store search functionality may have been compromised, but an Apple spokesperson said Apple did not receive bad firmware nor was any customer data stolen.

"Apple is deeply committed to protecting the privacy and security of our customers and the data we store," the spokesperson told The Information. "We are constantly monitoring for any attacks on our systems, working closely with vendors and regularly checking equipment for malware."

It's not quite clear what caused the vulnerability that led to the end of the agreement between Super Micro and Apple, but Apple has since moved on to other server suppliers, increasing orders from ZT and purchasing servers from Inspur.

Top Rated Comments

JoelTheSuperior Avatar
80 months ago
Funny to think Apple once made their own servers.
Score: 9 Votes (Like | Disagree)
Bart Kela Avatar
80 months ago
problem was that they weren't using SFTP to start with.
No, we don't know that. We are reading hearsay from the fired vendor and the word FTP is in quotation marks, so it possibly could have been SFTP.

SFTP doesn't guarantee that the downloads are clean or that the download server is safe, only that the download connection itself is secure.

Furthermore, both Supermicro and Apple contradict each other. Either someone is not telling the full truth or possibly both are not telling the complete truth. There's really no way to ascertain what happened from this article and we may never will.

The only real takeaway from this article is that Apple no longer sources server hardware from Supermicro. The rest of the words you can flush down the toilet.

My guess is that Mr. Leng is violating a confidentiality clause by discussing this with the media. If that is the case, it is likely that SuperMicro will never do business with Apple Inc. again as long as Tim Cook is in charge.

SuperMicro just burnt a bridge. Too bad for them.
Score: 6 Votes (Like | Disagree)
pat500000 Avatar
80 months ago
Terror of dependency. Good play, Apple.
Score: 4 Votes (Like | Disagree)
farewelwilliams Avatar
80 months ago
problem was that they weren't using SFTP to start with.
Score: 3 Votes (Like | Disagree)
now i see it Avatar
80 months ago
So maybe your iPhone is encrypted & secure... but apple's server farms are made by third parties and that's where the vulnerability lies. Dont get to cozy with iCloud.
Score: 3 Votes (Like | Disagree)
PortableLover Avatar
80 months ago
Well apple, its time to make your own servers again :)
Score: 3 Votes (Like | Disagree)

Popular Stories

iOS 17 on Phone Feature

Gurman: iOS 17 to Provide Several 'Most Requested Features'

Sunday March 26, 2023 6:05 am PDT by
Apple changed the strategy for iOS 17 later in its development process to add several new features, suggesting that the update may be more significant than previously thought, Bloomberg's Mark Gurman reports. In January, Gurman said that iOS 17 could be a less significant update than iPhone updates in previous years due to the company's intense focus on its long-awaited mixed-reality...
iOS 16

iOS 16.4 Will Add These 8 New Features to Your iPhone

Sunday March 26, 2023 8:06 am PDT by
Following nearly six weeks of beta testing, iOS 16.4 is expected to be released to the public as soon as this week. The software update includes a handful of new features and changes for the iPhone 8 and newer. To install an iOS update, open the Settings app on the iPhone, tap General → Software Update, and follow the on-screen instructions. Below, we have recapped eight new features and...
apple mixed reality headset concept by david lewis and marcus kane

Some Apple Employees Seriously Concerned About Mixed-Reality Headset as Announcement Draws Closer

Sunday March 26, 2023 8:25 am PDT by
Some Apple employees are concerned about the usefulness and price point of the company's upcoming mixed-reality headset, The New York Times reports. Apple headset concept by David Lewis and Marcus Kane Initial enthusiasm around the device at the company has apparently become skepticism, according to eight current and former Apple employees speaking to The New York Times. The change of tone...
iOS 16

Apple Releases iOS 16.4 With New Emoji, Safari Web Push Notifications, Beta Changes, Voice Isolation for Calls and More

Monday March 27, 2023 10:03 am PDT by
Apple today released iOS 16.4, the fourth major update to the iOS 16 operating system that initially came out last September. iOS 16.4 comes two months after the launch of iOS 16.3, an update that added Security Keys for Apple ID. iOS 16‌.4 and iPadOS 16.4 can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. It can take a few minutes...
Steve Jobs Theater dusk

Apple Reportedly Demoed Mixed-Reality Headset to Executives in the Steve Jobs Theater Last Week

Sunday March 26, 2023 5:53 am PDT by
Apple showcased its mixed-reality headset to the company's top 100 executives in the Steve Jobs Theater last week, according to Bloomberg's Mark Gurman. In the latest edition of his "Power On" newsletter, Gurman explained that the "momentous gathering" is a "key milestone" ahead of the headset's public announcement planned for June. The event was intended to rally Apple's top members of...
top stories 25mar2023

Top Stories: iPhone 15 Pro Design Leak, iOS 16.4 Coming Soon, and More

Saturday March 25, 2023 6:00 am PDT by
We're still almost six months away from the official unveiling of the iPhone 15 lineup, but it seems like every day we're learning more about what to expect from the next-generation models. Notably, this week gave us our clearest look yet at what appear to be some changes for the volume and mute control hardware. iOS 16.4 and associated releases are also right around the corner with some new ...
apple tv 4k red image

Apple Releases tvOS 16.4 for Apple TV 4K and Apple TV HD

Monday March 27, 2023 10:00 am PDT by
Apple today released tvOS 16.4, the fourth major point update to the tvOS 16 operating system that came out last September. Available for the Apple TV 4K and Apple TV HD, tvOS 16.4 comes two months following the release of tvOS 16.3. The tvOS 16.4 update can be downloaded over the air through the Settings app on the ‌‌‌‌Apple TV‌‌‌‌ by going to System > Software Update....