Apple Cut Ties With Supplier Super Micro Computer Over Server Security Concerns - MacRumors
Skip to Content

Apple Cut Ties With Supplier Super Micro Computer Over Server Security Concerns

by

Apple cut ties with server supplier Super Micro Computer in 2016 after unearthing a potential security vulnerability in at least one of its data center servers, reports The Information.

The vulnerability in the server, which was part of Apple's technical infrastructure powering its web-based services, was discovered in the early months of 2016. According to Super Micro senior vice president of technology Tau Leng, Apple ended its business relationship with Super Micro Computer shortly after uncovering the security issue.

supermicro
Leng's account of the incident makes it sound like Apple received bad firmware from an FTP site hosted by Super Micro that may have been infiltrated, which may have compromised the server.

According to Leng, when Apple was asked to provide the version number of the firmware it had downloaded after experiencing issues, Apple provided an invalid number. After that, Apple refused to provide more information to Super Micro.

Mr. Leng said Super Micro regularly provides firmware updates that data center customers like Apple can download from a private "FTP" site, hosted by Super Micro. He said the firmware updates come from outside chip manufacturers--in this case, a networking chip maker that he declined to name.

Sources who spoke to The Information said servers that handled Siri requests and App Store search functionality may have been compromised, but an Apple spokesperson said Apple did not receive bad firmware nor was any customer data stolen.

"Apple is deeply committed to protecting the privacy and security of our customers and the data we store," the spokesperson told The Information. "We are constantly monitoring for any attacks on our systems, working closely with vendors and regularly checking equipment for malware."

It's not quite clear what caused the vulnerability that led to the end of the agreement between Super Micro and Apple, but Apple has since moved on to other server suppliers, increasing orders from ZT and purchasing servers from Inspur.

Top Rated Comments

JoelTheSuperior Avatar
119 months ago
Funny to think Apple once made their own servers.
Score: 9 Votes (Like | Disagree)
Bart Kela Avatar
119 months ago
problem was that they weren't using SFTP to start with.
No, we don't know that. We are reading hearsay from the fired vendor and the word FTP is in quotation marks, so it possibly could have been SFTP.

SFTP doesn't guarantee that the downloads are clean or that the download server is safe, only that the download connection itself is secure.

Furthermore, both Supermicro and Apple contradict each other. Either someone is not telling the full truth or possibly both are not telling the complete truth. There's really no way to ascertain what happened from this article and we may never will.

The only real takeaway from this article is that Apple no longer sources server hardware from Supermicro. The rest of the words you can flush down the toilet.

My guess is that Mr. Leng is violating a confidentiality clause by discussing this with the media. If that is the case, it is likely that SuperMicro will never do business with Apple Inc. again as long as Tim Cook is in charge.

SuperMicro just burnt a bridge. Too bad for them.
Score: 6 Votes (Like | Disagree)
pat500000 Avatar
119 months ago
Terror of dependency. Good play, Apple.
Score: 4 Votes (Like | Disagree)
119 months ago
Well apple, its time to make your own servers again :)
Score: 3 Votes (Like | Disagree)
119 months ago
So maybe your iPhone is encrypted & secure... but apple's server farms are made by third parties and that's where the vulnerability lies. Dont get to cozy with iCloud.
Score: 3 Votes (Like | Disagree)
119 months ago
problem was that they weren't using SFTP to start with.
Score: 3 Votes (Like | Disagree)

Popular Stories

iOS 26

iOS 26.4 Adds Two New Features to CarPlay

Tuesday March 24, 2026 1:55 pm PDT by
iOS 26.4 was released today, and it includes a couple of new features for CarPlay: an Ambient Music widget and support for voice-based chatbot apps. To update your iPhone 11 or newer to iOS 26.4, open the Settings app and tap on General → Software Update. CarPlay will automatically offer the new features so long as the iPhone connected to your vehicle is running iOS 26.4 or later....
Apple Business hero

Apple Unveils 'Apple Business' All-in-One Platform

Tuesday March 24, 2026 8:53 am PDT by
Apple today announced Apple Business, a new all-in-one platform that unifies device management, productivity tools, and customer outreach features. The service is designed to be a consolidated replacement for several of Apple's existing business-focused offerings, including Apple Business Essentials, Apple Business Manager, and Apple Business Connect. It provides organizations with a single...
AirPods Pro Firmware Feature

Apple Releases New Firmware for AirPods Pro 3, AirPods Pro 2 and AirPods 4

Tuesday March 24, 2026 12:31 pm PDT by
Apple today released new firmware for the AirPods Pro 2, AirPods Pro 3, and the AirPods 4. The firmware has a version number of 8B39, up from 8B34 on the AirPods Pro 3, 8B28 on the AirPods Pro 2, and 8B21 on the AirPods 4. There is no word on what's included in the firmware, but Apple has a support document with limited notes. Most updates are limited to bug fixes and performance...