Apple's multi-year effort to develop its own servers and networking hardware has reportedly been driven in large part by security concerns, as the company worries that supply chain tampering may lead to deeply embedded vulnerabilities which are difficult to find and remediate.
Apple's fears center around the possibility that infrastructure equipment could be intercepted by third parties between the time it leaves the manufacturer and the time it arrives at Apple's datacenters, according to The Information. The company believes that malicious actors could be adding new or modified components that would enable unauthorized access.
This fear is said to have been a primary driver of the company's strategy to move as much infrastructure design as possible in-house. The gargantuan size of such a task — Apple's cloud services serve tens of billions of requests each day — has led to delays in reducing its reliance on outside service providers like Google and Amazon.
Unfortunately, Apple's worries are not unfounded.
While it may never be known who the targets were, information revealed by NSA leaker Edward Snowden revealed the existence of government programs designed to do exactly the thing Apple fears.
The National Security Agency's Tailored Operations Access unit was, and may still be, tasked with redirecting shipments of servers and routers headed for targeted organizations to government facilities. The packages would be opened, compromised firmware installed, and then the packages re-sealed and delivered.
One NSA manager described the program as "some of the most productive operations in TAO because they pre-position access points into hard target networks around the world."
Photos which accompanied the leaks showed intelligence agency workers modifying Cisco gear, infuriating the networking giant. Cisco later announced that it would address shipments to empty houses to avoid government tracking.
"We ship [boxes] to an address that's has nothing to do with the customer, and then you have no idea who ultimately it is going to," Cisco security chief John Stewart said at last year's CiscoLive 2015 conference.
"When customers are truly worried... it causes other issues to make [interception] more difficult in that [agencies] don't quite know where that router is going, so it's very hard to target - you'd have to target all of them. There is always going to be inherent risk."
Apple is said to have gone to extreme lengths to verify the integrity of products it receives, even comparing photographs of motherboards with explanations of each component and its function.
"You can't go take an X-Ray of every computer that hits the floor. You want to make sure there's no extracurricular activity" by building servers in-house, one source told the publication.
15 Comments
That guy's head makes me dizzy. :D
Wow. This kind of stuff is justified by governments as measures to prevent evil terrorists from winning. The way I see it this kind of stuff is proof that they already are.
The whole project makes me dizzy. Under what authority do they have the right to snoop on my network usage?
Sad days for civilisation !! Is it really a better world where anything and everything you say and do, anything you note down and record, text, a photo, a video, is available to someone you have never met who does not necessarily have your good will at heart. When will the microphone on your phone, tablet, watch, or even the camera switch on without your knowledge and become the eyes and ears through which your whole life is open to those who choose to watch and listen.
Interesting that some old scriptures written over 2,000 years ago referred to this stuff happening in the world at a time in the future. How did they know?