'Security by antiquity': why some experts deliberately keep using old, outdated tech to dodge hackers

Started by Ryan98, Today at 10:10 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: 'Security by antiquity': why some experts deliberately keep using old, outdated tech to dodge hackers   Views(Read 14 times)
Active members in this topic:
Ryan98(1)

Ryan98

A BBC Future feature examines a counterintuitive cybersecurity phenomenon some researchers call security by antiquity, or alternatively security by obsolescence, the idea that deliberately sticking with an old, outdated piece of technology can sometimes prove safer than switching to something newer, precisely because attackers have simply stopped paying attention to it. Finnish cybersecurity researcher Mikko Hyppönen offers one of the clearest personal examples, having stuck with the aging email client Eudora long after most people had moved on to newer alternatives, arguing it was really superior in several ways even though it was far from perfectly secure on its own technical merits.

As the broader user base migrated toward newer email tools, Hyppönen noticed hackers had effectively forgotten about Eudora entirely, no longer bothering to develop or deploy exploits against a shrinking, increasingly irrelevant target. He explained the underlying logic plainly, the vast majority of attackers are ordinary criminals trying to make money, and it simply doesn't make economic sense for them to spend time targeting a system being run by a comparative handful of remaining users when far larger, more lucrative targets exist elsewhere.

Computer scientist Matt Bishop of UC Davis demonstrated the same principle experimentally, almost entirely by accident, back in the 1990s. He and his colleagues deliberately set up an internet connected honeypot, a controlled system meant to attract and study hackers, using an older software version that had already been superseded by several subsequent updates. Virtually no attackers bothered targeting it at all. Once the team upgraded that same honeypot to the current, up to date version instead, Bishop recalled they immediately got all the attacks they could have wanted, a result he still finds genuinely amusing looking back on it.

Experts interviewed for the piece were careful to stress that using the latest, fully patched software generally remains the optimum security approach for most everyday situations, and this strategy isn't a universal recommendation people should broadly apply. But the article also points to actually serious real world applications of the same underlying principle, including what defense analyst Withington calls analogue resilience in Ukraine, where Russia has actively jammed GPS navigation and interfered with satellite communications, forcing renewed practical reliance on older, less networked technology precisely because it isn't vulnerable to the same kind of modern electronic interference in the first place


Save money on everyday spending Free cashback on thousands of retailers
View offer