https://www.bbc.com/future/article/20260821-why-older-tech-is-sometimes-safer-from-hackers
The fear of hacking has made some people turn to other forms of technology ignored by new generations of cyber criminals.
You might not expect a world-renowned cyber security expert to rely on old, potentially vulnerable email software. But, for years, that's what Mikko Hyppönen did. Shunning mainstream options such as Hotmail and Gmail, he instead chose obsolete email software called Eudora.
"I used to run it years after it was out of [technical] support," says Hyppönen, a Finnish computer security expert.
He preferred Eudora for various reasons, arguing it was "really superior in many ways". Although Eudora was far from perfectly secure, as people switched to newer email tools, Hyppönen realised that hackers were forgetting about Eudora.
Hyppönen calls it "security by antiquity". Others use the phrase "security by obsolescence" and in both cases this means relying on an older technology or system since it may prove, somewhat counterintuitively, safer than more recent alternatives.
While Hyppönen stresses that using the latest, fully patched and updated software is still "the optimum situation", there are specific cases where older tech could be preferable from a security standpoint.
"The vast majority of attackers are criminals trying to make money and it doesn't make any sense for them to target systems being run by 50 people," he explains.
Hyppönen isn't alone. The Irish Aviation Authority, for instance, recently decided to keep ground-based radio navigation beacons in use because supposedly the more modern satellite-based global positioning system (GPS) has proven so susceptible to jamming in recent years.
"Security by antiquity" is, it turns out, a quiet way of beating cyber-criminals, hackers and enemy attackers.
Matt Bishop, a computer scientist and professor emeritus at the University of California, Davis, has tested this principle, somewhat by accident. Back in the 1990s, he and his colleagues set up a system connected to the internet and deliberately left it accessible so that they could catch hackers and bots attempting to breach it. This is a common cyber-security research technique known as a honeypot – a kind of trap set up in carefully controlled conditions.
But the team picked an older software version for their honeypot that had been upgraded multiple times since its release and, consequently, no hackers bothered to target it. "When we upgraded it to the new one, we had all the attacks we wanted," recalls Bishop. "I thought it was so amusing."
This possibility of evading nefarious activity by sticking to old tech can take many forms. Both Bishop and Hyppönen say they have friends who refuse to get a smartphone. "One person I know [uses] a Nokia 9210," says Hyppönen, referring to a simple, "dumb" mobile phone first released 25 years ago.
As technology has advanced, experts have often questioned whether the latest systems are actually more risky than older onesWhile hackers can't target it in quite the same way they might target a modern Android or iOS device, the phone's operating system, Symbian, does have some old, known vulnerabilities. The flipside is that "nobody's targeting them anymore", adds Hyppönen. Similarly, the Nokia could be more at risk from techniques that snoop on phone calls. But how many people will bother? It's a security trade-off.
As technology has advanced, experts have often questioned whether the latest systems are actually more risky than older ones. During the late 1990s, Bishop wrote a speech in which he argued that computers were "considerably less secure than the paper systems we still use, and that are rapidly being replaced".
Concerns about the shift from paper to digital technologies remain prevalent, especially when it comes to electronic voting systems. Some say electronic voting machines are desirable partly because they produce election results much more quickly than paper-based systems. That's not enough to sway others, though.
"Voting is the bedrock of our democracy," says Hyppönen. "It's one of the last things I'd like to weaken in any way, especially if the benefits are so small."
Militaries are also known for being reluctant to take chances. Even the world's most active militaries are known to occasionally rely on old technologies for reasons of reliability and security. "One thing I've seen in places like Ukraine is the use of paper maps, or laminated maps, and compasses," says Thomas Withington, associate fellow at the Royal United Services Institute, a think tank. "You can't jam that." It's a kind of "analogue resilience", he adds.
Jamming attacks hitting GPS-based navigation have forced some countries to make careful choices about which legacy technologies to retain, and which GPS alternatives to invest in, says Victor Tasiemski, a systems engineer at Overlook Systems Technologies, which works on navigation tech.
That's exactly what happened in Ireland, where a programme to replace ground-based radio beacons has been slowed down in order to keep those beacons operating for longer. A spokeswoman for the Irish Aviation Authority told the Irish Times in June that the beacons were being retained "as part of a planned resilience strategy".
Technologists who work with militaries are familiar with the challenge of designing systems that can link old and new technologies together. Stefan Kraus is co-founder and chief technical officer of Kraus Hamdani Aerospace, which has designed a drone-based communications platform that can connect military personnel to one another, no matter whether they are using older radios or newer ones. Military radio tech that has been around for decades is "tried, tested and secure", he says. "The US military isn't going away from that."
Tasiemski notes that one alternative to GPS-based navigation is eLoran, a radio-based navigation system that has its roots in military technology first developed during World War Two. With attacks targeting GPS systems, eLoran is arguably becoming increasingly desirable, says Tasiemski, because it uses a much more powerful signal and is therefore much trickier to jam: "Overpowering a one-megawatt transmitter is pretty hard."
Robustness is not easy to replace. This applies in the world of data storage, too, where magnetic tape – invented during the 1950s – still plays a huge role today. Companies, research institutions and government agencies continue to store vast amounts of data on reels of tape. The technology has improved significantly since it first appeared, with data storage densities having increased exponentially over the decades.
But the principle remains the same: spools of tape that hold information. The tape can be detached from computer systems, packaged, and transported to secure facilities, including difficult-to-breach underground caverns and repurposed mines.
"Ransomware is what, for me, kept tape in business the past 10 to 15 years," says Hugues Meyrath, chief executive of Quantum, a company that specialises in data storage.
An organisation locked out of its own computer systems may still be able to retrieve its most important data if staff have made good back-ups, for example on magnetic tape. Interest in magnetic tape is only increasing further today because the cost of random access memory (Ram), a form of computer memory that doesn't rely on tape, is skyrocketing. Meyrath says his company's clients use tape to store all kinds of data – from broadcasters' footage of baseball games to genomes mapped in detail by research facilities.
Tape's security attributes stem partly from the fact that most people don't tend to interact with it at all. It's obscure, clunky, old-school tech. "One way to attack a system is to rig a set of USB sticks and throw them around a parking lot," says Bishop, referring to the likelihood that someone will eventually pick up one of the USB sticks and insert it into their computer – a simple way to perpetrate a hack. As he puts it: "You'll never see magnetic tape thrown around a parking lot."
Experts who spoke to the BBC still recommend that people use the latest and most up-to-date technologies for everyday tasks, as it remains the safest approach. But it is worth acknowledging that "new" doesn't necessarily mean "best" in all scenarios. And knowing when and how to switch to older systems could become increasingly important, as cyber-attacks and other threats get more sophisticated.
Withington points again to Ukraine, where Russia has interfered with satellite communications and where GPS navigation has succumbed to significant jamming. Nowhere is "analogue resilience" more prized. "What do people do," asks Withington, "if there's no access to the technology they take for granted?"
(Score: 3, Interesting) by JoeMerchant on Friday August 28, @09:55PM (4 children)
Before Eudora was released, I recognized how lame e-mail clients of the day were, I bought books on SMTP and related topics, I was ready to launch a "better client" project... in my spare time.
So, Qualcomm released Eudora before I found my Round-Tuit, and then there was just no need.
My wife instantly took to Eudora and hung on to it deep into the period of time where it was getting problematic to run with modern browser interfaced mail services (yes, Gmail and others provided POP3, IMAP and other interfaces, but they periodically changed the rules making reliable service annoyingly difficult as the years went on - not to mention our original me@my.com e-mail addresses resembling the black knight after the blacklists got cranked up - every time some spammer set up operations remotely close to our service provider's domain another limb would come off... so we called it a draw as the smartphones came into play and retired our Eudora usage.
The old practice of keeping incoming mail in local folders had an interesting interaction with virus scanners in the 2003-4 timeframe: your local storage could have tens of thousands of SPAM messages and many / most of them contained virus payloads which were harmless when stored as data, but virus scanners would come back triumphantly proclaiming how many thousands of viruses they had valiantly saved you from on your own machine!
🌻🌻🌻🌻✌️ [google.com]
(Score: 3, Interesting) by looorg on Friday August 28, @10:49PM (3 children)
Eudora was pretty great. I have nothing but good memories of it really. That said those memories are now old and fading and I might be glossing over somethings. Something made me eventually switch to Thunderbird. Then eventually work forced those atrocious webclients and Outlook on us ...
I don't really remember now. But I think the support for HTML and javascript and all the other crud that is in an email client these days was not available at the time Eudora was the main mailclient for a lot of people. Or at least very limited. That is probably the reason. Was the main security issue that all was in plaintext? That is the main fault probably.
Is hacking email clients the way to go? If you want to read someonce email you hack the mail server and look there. Not the client. That sentence just made no sense.
We did that when I worked at a university to. We let unsecure Windows machine be connected to our network to see what happened. Very few even survived the night without being broken into, broken in when the door was more or less open. All that showed was that we knew people scanned our IP ranges around the clock. What did they use them for? FXP and storage. A European university have excellent high speed connections, reasonable new machines with large amounts of storage. The conclusion from this, since we had to write a report and not just play around and get infinite amount of pirated content and porn, was to limit local storage space on the machines. They became a lot less interesting as targets as soon as harddrive space was cut to a minimum.
Security by Obscurity, security by antiquity. More or less the same thing. One probably fits inside the other as a Venn diagram. Which is the outer bubble and which is the inner one I leave to someone else to figure out.
(Score: 2) by JoeMerchant on Saturday August 29, @01:59AM (1 child)
The joke at a US university was that an FTP server left open on port 22 (even with "security" turned on) would be pwned and serving its full capacity of porn within 24 hours of connection, but... same FTP software on some random port could last there years without harassment, probably because they were finding enough on 22 to not bother with the more difficult / easy to detect search.
🌻🌻🌻🌻✌️ [google.com]
(Score: 2) by Snotnose on Saturday August 29, @02:52AM
Be nice of Qualcomm would open source Eudora, I used it for years and loved it.
Being the dumbest idiot in the land and president of the US should be 2 different people.
(Score: 1, Insightful) by Anonymous Coward on Saturday August 29, @02:35AM
If the email client receives some mail and runs arbitrary code of the hackers choice then it's one way to go.
Somehow lots of programmers can't avoid buffer overflows and other stuff. Maybe this level of crappiness is intentional - more backdoors etc.
(Score: 2, Interesting) by JoeMerchant on Friday August 28, @10:02PM (2 children)
Back in the mid 90s we incorporated tape backups of our ~100MB drives for archival and cross-country transport of the data. The drives would get full every few weeks, so they would be swapped out, brought to the local hub, transferred to tape and the tape shipped cross country to the central data archive center.
Quickly they discovered that tape is not 100% reliable, so they started making triple backups - ship one, keep the other two at the remote hub, when the first shipped tape failed, make a copy of one of the two backups at the remote site and ship that backup to the hub. That got losses down from 5% to about 0.01%, but we still heard of occasional instances where all 3 tapes failed. They didn't want to spend the extra money to keep the hard drives on the shelf until the cross country backup was confirmed (requiring 2x the hard drives) so they just settled in and accepted that 1 session out of 10,000 was going to be lost.
🌻🌻🌻🌻✌️ [google.com]
(Score: 0) by Anonymous Coward on Saturday August 29, @12:16AM (1 child)
Curious, which type tape / drive(s) were you using? DAT, Travan, DLT, QIC, 8 MM, 1/2", 1", ... ?
(Score: 2) by Reziac on Saturday August 29, @02:40AM
I dunno about commercial solutions, but back in the era of QIC-80 tape I quickly learned that there was Sony, and garbage. The Sony tapes would format with no more than 4 bad sectors. Every other brand I ever tried was 25 and up. I took this to be a reasonable indicator of reliability.
And there is no Alkibiades to come back and save us from ourselves.
(Score: 3, Interesting) by krishnoid on Saturday August 29, @03:29AM
I thought this scene involving nuclear reactor longevity and repair [wordpress.com] from Foundation:
was a little far-fetched ... until I started seeing stories like these [youtu.be] in the news. It seems like repair know-how and even user interfaces age as software does.
(Score: 3, Insightful) by Common Joe on Saturday August 29, @03:36AM (5 children)
The article conflates two things. The first is actual hackable items (like Eudora or old Nokias). Old technology will be hacked by AI in the near future. The bad guys will knock on the door of the program, figure out what program is responding, and hack it fairly quickly using known exploits. The second is actual useful "old school technologies" like paper maps which are not hackable, but they are vulnerable to other problems like fire or data being outdated. (I keep an old Houston map from my grandfather just because. This 50 year old map has no actual value -- only sentimental value. The city is completely different now. Useless from a navigation point of view.)
So, it boils down to a particular philosophy which has been around forever but is still used very much today in the modern computer world: threat assessment. What is deemed to be a threat? How do one defend against those threats?
(Score: 2) by driverless on Sunday August 30, @05:41AM
Not necessarily. If 99.99% of the training data is for non-ancient systems, there'll be a paucity of info for the clanker to turn into any kind of attack. It'll see something vaguely like what it's been trained on and try something vaguely appropriate, but it won't work because it won't fit. I'm thinking for example trying to use SunOS 11 attacks and commands on a SunOS 4 system, which was the security-by-obsolescence thing a place I used to work for used. Not by design, it was just an old box that still kept going and they saw no need to replace it.
(Score: 3, Interesting) by VLM on Monday August 31, @01:28PM (3 children)
My experience is LLMs have been beyond useless for retrocomputing stuff, well into the negative productivity area.
There are no computers other than Windows 11 on amd64, and that sprang into existence from nothingness like the Book of Genesis describes.
(Score: 2) by Freeman on Monday August 31, @02:13PM
This doesn't preclude the possibility of someone training their own AI to deal with retrocomputing things.
Joshua 1:9 "Be strong and of a good courage; be not afraid, neither be thou dismayed: for the Lord thy God is with thee"
(Score: 2) by Common Joe on Tuesday September 01, @03:09AM (1 child)
That may be for now, but AIs are being trained on every old book the companies can find, and you have the retrocomputing clubs which talk about old technologies in detail or reverse engineering. It's a pretty safe bet that all of that is getting vacuumed up during AI training. As AIs get better, some of that is bound to surface.
(Score: 2) by VLM on Thursday September 03, @08:39PM
I have access to Anna's and archive.org and bitsavers and similar sites and there's just not that much out there.
Lots of lost data.