Report: Apple building its own servers to prevent snooping
9to5mac.com
9to5mac.com
https://raptorengineeringinc.com/TALOS/prerelease.php
If Apple is concerned about tampering enroute, they could have the flash chips for the system firmware provided separately by a trusted party and transported like a bank shipment. Then flash and install them at the datacenter. That should thwart adversaries who cannot do their own manufacturing runs of modified versions of the chips, which is just about everyone. I guess the manufacturer/fabrication plant could do a custom compromised chip, but given that the costs involved are prohibitive, I doubt that would happen.
Apple could do the same with the firmware and flash for every other component in their datacenter that has a microprocessor such as the hard drives, the NICs, etcetera. They are large enough that part manufacturers would likely turn over the source code for their firmware in order to secure their business along with anything else that they need/want.
If you think the NSA/state level adversaries have not penetrated bank shipments, you are dangerously naive. Instead, maybe transport it like the CIA moves the communication hardware for its quiet rooms, or like the Russians move the bugs destined for US embassies.
Apple is interesting because it's one of the few organizations that could plausibly do this.
OpenPOWER is awesome though. I'm hoping Talos will get enough interest; I'm ready to throw money at them if it succeeds. POWER chips are super good, I don't know how IBM has managed to keep up with Intel's R&D but they're definitely competitive in performance.
The A9 has PCI Express lanes for NVMe flash that could be used to add wired networking and storage while the secure boot and code signing would allow them to build a microserver that only runs their code. This arrangement would also be incredibly cost effective for them.
They would want to give their SoCs have properly protected internal data paths and the necessary logic for ECC RAM before using them in micro-servers if those chip features are not already there though. If they are, I doubt that the ECC is being used in their iDevices.
They have the luxury of having enough cash, and enough profitability, to do things that have negative ROI. The recently concluded lawsuit comes to mind — there was no business case for not settling it at the earliest. They didn't settle at all, and took it to the US Supreme Court.
And if a secure architecture requires a custom-designed backend server farm, they can do it, and even probably make it revenue-neutral, by re-introducing the Xserve product line.
I don't think they will do a full-blown custom design, and the advantage of having their own hardware stack is that they can leverage existing technology, and make a few tweaks. And they must have been running at least designs on this possibility, because they do want to take notebook/desktop processor manufacture in-house in the medium term, and end reliance on Intel.
I'm inclined to disagree. Apple is a global company, and many of its customers would not look favorably upon the US government being able to force Apple to decrypt their data. I actually think that Apple would have gone as far as to move a good portion of their operations outside the US and create separate legal entities to protect against this had they lost the case.
And while globally people tend to have mixed opinions of Americans, the US government and its three-letter agencies are almost universally despised around the world. Apple being seen as a willing cooperator with the US government (especially on the issue of privacy / espionage) would be a huge blow to their global brand.
http://www.bloomberg.com/politics/articles/2016-03-07/apple-...
http://blog.fosketts.net/2011/06/06/datacenter-equipment-app...
Don't know how robust it is compared to e.g. VMWare or VirtualBox, but it seems to be working well enough in my simple tests.
I was really excited about that project but it doesn't appear to be getting much attention.
This isn't "simple" except perhaps for some US (and US only, by virtue of Intel being head-quartered there) agency with huge procurement budgets and persuasive legal instruments, and I'd expect push-back even then.
If you coerce them (with those persuasive legal instruments) you get minimum compliance to keep people out of jail.
If you actually get some cooperation established, I'll guess that gives a much better support experience.
The BIOS doesn't need to load the ME firmware - that wouldn't be very useful since the ME is what gets the CPU out of reset these days.
However, there are more binary components on a contemporary Intel device (listing the variants used with coreboot. other firmware may look slightly different, but the parts are pretty much the same internally): CPU microcode updates (useful because they can't manage to ship CPUs that work correctly on the first try); FSP (memory initialization code that's totally boring but guarded like a state secret); graphics initialization code (VGA BIOS or GOP driver. likewise boring-but-secret); sometimes some more hardware initialization, but we try to get most of that opened up (with varying success).
And then there are some more signed binary components that aren't directly related to host firmware: TXT and SGX require intel-signed code, and - newest addition, I think - GPU firmware binaries. Because they were so well received with AMD and nVidia hardware.
source: am a coreboot developer.
[0] It's also a NOR part, not NAND, and it may be multiple SPI devices that the firmware hub exposes like a single one, but either detail is beyond nit-picking for the current discussion.
Maybe I had misunderstood as I can find no reference to substantiate that.
https://media.ccc.de/v/32c3-7352-towards_reasonably_trustwor...
I feel like the entire world has gone insane, and every boundary is being pushed to its limits ... and then pushed beyond those limits. Where does this end?
Echelon dates to the late 1960s.
COINTELPRO went on for two decades starting from 1956.
Privacy and rights abuses have been rampant among the three letter agencies since their originations. Today, they can scale the privacy invasion. That's the sole difference from their side. Previously they'd just violate someone's rights and go about their business, good luck proving it or fighting it at a small scale as a specific target of one of these agencies.
The list of rationalized extensions of the US Government into what becomes in retrospect a blatant abuse of power would be an interesting one.
Watergate was a quaint bespoke little operation. Much wider unconstrained eavesdropping capability is available to grunts like Snowden on tap. And all the perpetrators were indicted or jailed[0]. A president even was made to resign.
If anything, the magnitude of the threat the Un-American Activities Committee dealt with, and the constrains Nixon faced (both technical during, and legal after the fact) provide a contrast to the post-PATRIOT-Act reality of threats and constrains, all imaginary at best.
[0] http://watergate.info/analysis/casualties-and-convictions
you must be kidding. https://en.wikipedia.org/wiki/Crypto_AG#Compromised_machines
In the current era, the targets are often domestic and they're willing to compromise U.S. companies on a large scale to do it.
I'm sorry to say it, but I read this and think "plausible deniability for future-Apple when they open the (back) doors".
Wow, so this is very interesting given, pretty much, everything that has been going on.
Will apple actually be the bastion of freedom (both in market and privacy) that the US supposedly stands for??
Google makes its own machines, as does facebook (actually more interested in FB's fiber switches/routers, but thats beside the point)....
But Apple has made "servers" for years... I guess they didnt consume them in their own DCs?? So I basically take it that they are effectively joining their take on Open Compute (mobos that can be mounted in controlled environments, where controlled now also means they can ID if anything was modded/changed in shipping?)
EDIT: I would really like to know how long "long" is from "apple long suspected"....
I was informed of NSA back-doors in Cisco gear in 1997 - WTF is Cisco's stance on any of this -- I haven't heard anything from them at all (or I missed anything they said)
https://en.wikipedia.org/wiki/Xserve http://readwrite.com/2014/08/26/apple-icloud-amazon-web-serv...
Basically like what Oracle does with Exadata without fitting a yacht into the purchase price.
[0] http://www.pbs.org/wgbh/frontline/article/how-the-nsas-secre...
How many machines have you purchased in your career? I've purchased THOUSANDS - which of these have been intercepted and compromised?
I have no clue.
~All of them, though likely without bothering to intercept your specific hardware, since you were relatively unimportant. Instead, the breaches were built into commodity hardware far upstream of you, for fully general attacks.
That is not necessary. Just get the shipping company to redirect the hardware to a facility that flashes the Intel ME with signed malware, reseals it and reships it without the recipient seeing anything different. That way fewer people need to know about it, which decreases the chance of detection:
http://www.pcworld.com/article/2083300/report-nsa-intercepts... https://libreboot.org/faq/#intelme
Not even Intel needs to know if they are compromised successfully, just like Google did not need to know about those fiber taps between their datacenters. That means countries like China that have things being shipped to possible targets can do this too if their hackers gain the necessary secrets.
@iam-TJ 's point was in reference to the suggestion that Apple could pick the servers up directly from the manufacturer to avoid the interception while the servers are in the shipping company's hands.
Until it hits customs.
How long would an operation like that take? And can't a company with Apple's clout ask the supplier for a spec sheet that lists all the chips and a diagram showing the location of said chips?
So are they going to run these in another country? Because Congress is pretty idiotic when it comes to technology and they can pass laws to force Apple (and others) to allow snooping.
Not only that, but they can confirm the firmware after receiving the equipment, unless they suspect the CPUs machine code, but then who will they get their CPUs from?
And besides, it's not like they'll be tearing out all the netapp, dells and Cisco --everyone even amazon have them all, from what I hear.
https://www.kickstarter.com/projects/designshift/orwl-the-fi...
But they may want to build their own chips, too, because they probably shouldn't trust Intel (they do some of that already, but they may need more powerful chips for their datacenters).
When he mentioned it, he didn't even blink. It was eerie.
It is real.
It has been around forever.
[1] http://www.siliconinvestigations.com/ [2] http://www.istgroup.com/english/3_service/03_01_detail.php?M...
Last time I checked, Apple was not in the business of making data center equipment, so it's not like they would give up IP that is central to their business model.
I'm quite uneasy regardless of who holds my data.
If their software and network security is similar now.. then they should spend resources there rather than care too much about modified hardware by a governmental agency.
So unless Apple are going to put their best and poach other industry bests, their result will likely not deliver on premise or promise.
My comment just meant that I needed 1 hour to find a way to get a shell in a couple of their servers. That is more worrisome to me than the NSA snooping around. And I'm not a great pentester, I probably wouldn't find a bug in Google even if I spent a couple weeks.
Or are the margins of error on repeated benchmarks larger than any performance hit due to a backdoor, or can something be backdoored without any performance hit?
What about power consumption?
In another note, hard RTOS are not used in servers, so performance cannot be compared with benchmarking tools.
It may seem surprising, but performance is easily determined by side channel attacks.
https://www.google.com/search?q=blackhat+side+channel+web+ti...
If they didn't make that horrible mistake of their recent multi-billion dollar purchases, they'd have extra billion atleast towards a fab plant.
I'm laughing at Apple right now. Idiots. You Apple board... are stupid.
(I mean, I'm sure they'll try to action something, but we all know security is a compromise not a guarantee).