Apple cut ties with server supplier Super Micro Computer in 2016 after unearthing a potential security vulnerability in at least one of its data center servers, reports The Information.

The vulnerability in the server, which was part of Apple's technical infrastructure powering its web-based services, was discovered in the early months of 2016. According to Super Micro senior vice president of technology Tau Leng, Apple ended its business relationship with Super Micro Computer shortly after uncovering the security issue.

supermicro
Leng's account of the incident makes it sound like Apple received bad firmware from an FTP site hosted by Super Micro that may have been infiltrated, which may have compromised the server.

According to Leng, when Apple was asked to provide the version number of the firmware it had downloaded after experiencing issues, Apple provided an invalid number. After that, Apple refused to provide more information to Super Micro.

Mr. Leng said Super Micro regularly provides firmware updates that data center customers like Apple can download from a private "FTP" site, hosted by Super Micro. He said the firmware updates come from outside chip manufacturers--in this case, a networking chip maker that he declined to name.

Sources who spoke to The Information said servers that handled Siri requests and App Store search functionality may have been compromised, but an Apple spokesperson said Apple did not receive bad firmware nor was any customer data stolen.

"Apple is deeply committed to protecting the privacy and security of our customers and the data we store," the spokesperson told The Information. "We are constantly monitoring for any attacks on our systems, working closely with vendors and regularly checking equipment for malware."

It's not quite clear what caused the vulnerability that led to the end of the agreement between Super Micro and Apple, but Apple has since moved on to other server suppliers, increasing orders from ZT and purchasing servers from Inspur.

Top Rated Comments

JoelTheSuperior Avatar
96 months ago
Funny to think Apple once made their own servers.
Score: 9 Votes (Like | Disagree)
Bart Kela Avatar
96 months ago
problem was that they weren't using SFTP to start with.
No, we don't know that. We are reading hearsay from the fired vendor and the word FTP is in quotation marks, so it possibly could have been SFTP.

SFTP doesn't guarantee that the downloads are clean or that the download server is safe, only that the download connection itself is secure.

Furthermore, both Supermicro and Apple contradict each other. Either someone is not telling the full truth or possibly both are not telling the complete truth. There's really no way to ascertain what happened from this article and we may never will.

The only real takeaway from this article is that Apple no longer sources server hardware from Supermicro. The rest of the words you can flush down the toilet.

My guess is that Mr. Leng is violating a confidentiality clause by discussing this with the media. If that is the case, it is likely that SuperMicro will never do business with Apple Inc. again as long as Tim Cook is in charge.

SuperMicro just burnt a bridge. Too bad for them.
Score: 6 Votes (Like | Disagree)
pat500000 Avatar
96 months ago
Terror of dependency. Good play, Apple.
Score: 4 Votes (Like | Disagree)
farewelwilliams Avatar
96 months ago
problem was that they weren't using SFTP to start with.
Score: 3 Votes (Like | Disagree)
now i see it Avatar
96 months ago
So maybe your iPhone is encrypted & secure... but apple's server farms are made by third parties and that's where the vulnerability lies. Dont get to cozy with iCloud.
Score: 3 Votes (Like | Disagree)
PortableLover Avatar
96 months ago
Well apple, its time to make your own servers again :)
Score: 3 Votes (Like | Disagree)

Popular Stories

Beyond iPhone 13 Better Blue Face ID Single Camera Hole

10 Reasons to Wait for Next Year's iPhone 17

Monday July 8, 2024 5:00 am PDT by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models simultaneously, which is why we sometimes get rumored feature leaks so far ahead of launch. The iPhone 17 series is no different – already we have some idea of what to expect from Apple's 2025 smartphone lineup. If you plan to skip...
iPhone 15 Pro Cameras

iPhone 17 Pro Max Will Be First Model to Feature Three 48MP Cameras

Thursday July 11, 2024 12:20 am PDT by
Next year's iPhone 17 Pro Max will feature an upgraded 48-megapixel Tetraprism camera for enhanced photo quality and zoom functionality, according to Apple analyst Ming-Chi Kuo. In his n-iphone-tetraprism-upgrade-ca62dd37e364">latest investor note published to Medium, Kuo said the key specification change would be a 1/2.6" 48MP CIS sensor, up from the 1/3.1" 12MP sensor expected to be used...
iPhone 16 Pro Front Update Blue

iPhone 16 Pro Rumored to Support 40W Fast Charging and 20W MagSafe

Wednesday July 10, 2024 3:57 am PDT by
Apple's forthcoming iPhone 16 Pro and iPhone 16 Pro Max will support 40W wired fast charging and 20W MagSafe charging, claims a rumor currently swirling around China. Right now, iPhone 15 and iPhone 15 Pro models are capable of up to 27W peak charging speeds with an appropriate USB-C power adapter, while official MagSafe chargers from Apple and authorized third parties can wirelessly charge...
AirPods Pro Beta Firmware

Apple Releases New AirPods Pro 2 Beta Firmware With Support for iOS 18 Features

Tuesday July 9, 2024 11:46 am PDT by
Apple today released a second beta firmware for the AirPods Pro 2, including both the Lightning and USB-C versions. The updated firmware has a build number 7A5244b and it is available to developers at the current time. This is the second firmware update that Apple has released since announcing new AirPods Pro 2 features in June. There are several new features that are coming to the AirPods...
Beyond iPhone 13 Better Blue Face ID

iPhone 16 Models Rumored to Have Face ID-Related Design Changes

Tuesday July 9, 2024 9:15 am PDT by
iPhone 16 models coming later this year could have some Face ID-related "design changes," supply chain publication DigiTimes said this week. The original source of this information is British newspaper The Telegraph, which six weeks ago reported that Face ID component supplier Coherent was considering selling or repurposing a manufacturing facility in Newton Aycliffe, a small town in...
orka desktop

MacStadium Releases Free Orka Desktop macOS Virtualization Software

Wednesday July 10, 2024 6:55 am PDT by
Mac cloud services provider MacStadium today unveiled Orka Desktop, a free virtualization tool that allows Mac users to create and manage macOS virtual machines locally via an easy-to-use admin panel. Orka users can create or download custom macOS images locally for their own personal use, or to collaborate with team members using a familiar workflow, versioning, audit, and review controls....