Tutti i fornitori

Vendor lineage

Crypto AG - when the vendor was the adversary

The limiting case for every supply-chain argument: the intelligence services did not plant a backdoor, they owned the company.

Crypto AG was a Swiss manufacturer of cipher machines, founded in 1952 and used by more than 120 governments, which was secretly owned by the CIA and the West German BND.

Every argument in this catalogue about whether a supplier can be trusted has a limiting case, and this is it. Crypto AG was a Swiss manufacturer of cipher machines, founded in 1952 and sold to more than 120 governments. From 1970 at the latest it was owned by the American CIA and the West German BND, which is not a story about a backdoor inserted into somebody else's product. The intelligence services were the company.

The programme was code-named Thesaurus and later Rubicon; the firm itself was Minerva. It ran for decades and was revealed only in February 2020, when the Washington Post and the German broadcaster ZDF obtained the CIA's own classified history of it. That history called the operation the intelligence coup of the century.

The structural point is the one that should stay with a reader, and it is worse than it first sounds. The customers were self-selected for caring about security. A government bought this equipment precisely because it wanted its diplomats and its soldiers protected - so the act of seeking protection is what placed it under surveillance. Buyers who did not care were not affected. Diligence was the vulnerability.

For this region the record is specific rather than abstract. Declassified material published alongside the reporting shows the machines carried the communications of Latin American governments, among them the Operation Condor regimes of Chile, Argentina and Uruguay, while those regimes were conducting repression across borders. The Washington Post noted that the agency histories largely avoid what the United States knew of that, and what it did or did not do about it. That gap in the record is where the account has to stop, because nothing published so far closes it.

Two further details matter for how such arrangements survive. Swiss officials appear to have known for decades and acted only when exposure became certain, and the profits from selling the machines went back to the services that owned the company. An operation of this length is not sustained by secrecy alone; it is sustained by the number of people whose interests are served by not asking.

None of this establishes that any particular vendor today is compromised. What it establishes is that the question is legitimate rather than paranoid, and that it applies symmetrically to every supplier under every government. For most of the working lives of most people in this industry, the largest case of a compromised vendor on record was not on record at all - which is worth remembering before anyone speaks confidently about the cases that remain unknown.

Sources