Technology

Security by Antiquity: Why Older Tech Can Be Safer from Hackers

Outdated software and hardware may offer surprising protection against modern cybercriminals, experts say.

Security by Antiquity: Why Older Tech Can Be Safer from Hackers

Outdated software and hardware may offer surprising protection against modern cybercriminals, experts say.

The Eudora Example

Mikko Hyppönen, a renowned Finnish cybersecurity expert, deliberately used an obsolete email program called Eudora years after it lost technical support. While mainstream users flocked to services like Hotmail and Gmail, Hyppönen stuck with the older tool, arguing it was superior in many ways. He soon realized a hidden benefit: hackers had largely forgotten about Eudora. The vast majority of cybercriminals, he explains, are motivated by profit and have little incentive to target systems used by only a handful of people. Hyppönen calls this phenomenon “security by antiquity,” while others refer to it as “security by obsolescence.” He stresses that staying on the latest fully patched software remains the ideal, but in specific cases, older technology can offer a distinct advantage.

The Honeypot Test

Matt Bishop, a computer scientist and professor emeritus at the University of California, Davis, stumbled upon the same principle. In the 1990s, he and his colleagues set up an internet-connected system deliberately left accessible to catch hackers and bots—a common research technique known as a honeypot. They chose an older software version that had been upgraded multiple times since its release. To their surprise, no attackers bothered to target it. When they upgraded to the newer version, the attacks flooded in. “I thought it was so amusing,” Bishop recalled. The experiment demonstrated that older, less popular systems can fly under the radar of cybercriminals who focus on widely used platforms.

Trade-offs and Limitations

Both Hyppönen and Bishop say they know people who avoid smartphones altogether. Hyppönen mentioned a friend who still uses a Nokia 9210, a simple “dumb” phone first released 25 years ago. Its operating system, Symbian, has known vulnerabilities that could be exploited, but the key is that no one is actively targeting them anymore. The trade-off is clear: while the device may be more vulnerable to certain physical attacks, the likelihood of a remote hack is extremely low because the pool of potential victims is so small. The Irish Aviation Authority recently made a similar choice, opting for older technology after concluding that modern GPS systems were too vulnerable to jamming. Experts caution that “security by antiquity” is not a universal solution—it works best when the old system is obscure enough that attackers see no value in targeting it. For most users, keeping software up to date remains the safest bet, but for those who can tolerate the inconvenience, vintage tech can provide a quiet refuge from the hacking crowd.

Source: bbc.com

Related Articles