TECH Signal 471
Security experts reportedly rely on obsolete tech to evade modern cyberattacks
Some security professionals and organisations use outdated software or hardware to reduce exposure to contemporary hacking threats
Engineers often assume newer systems are inherently more secure, but this event shows that obsolescence can create a defensive advantage. The trade-off between known vulnerabilities and reduced attacker interest may be worth evaluating for niche or high-stakes systems. It also challenges the default assumption that patching and updates are always the best security strategy
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Older tech can avoid modern attack vectors simply because hackers no longer target it
Organisations like the Irish Aviation Authority retain obsolete systems to sidestep vulnerabilities in newer alternatives
Security trade-offs exist: older systems may lack patches but also lack attacker interest
THE READ
What the cluster adds up to.
The event describes a counterintuitive security strategy: using obsolete technology to reduce exposure to modern cyber threats. Security experts like Mikko Hyppönen and Matt Bishop have observed that older software, such as Eudora or early Symbian phones, attracts fewer attacks because hackers prioritise widely used systems. This phenomenon, termed 'security by antiquity' or 'security by obsolescence', suggests that the cost of maintaining outdated tech may be offset by the reduced likelihood of being targeted. However, this approach is not universally applicable; it works best in scenarios where the user base is small or the system is isolated from contemporary attack surfaces.
Adopting obsolete tech for security purposes comes with clear trade-offs. While older systems may avoid modern attack vectors, they often lack security patches, leaving them vulnerable to known exploits. For example, the Nokia 9210, while not targeted by modern malware, still has unpatched Symbian vulnerabilities. The strategy also assumes that attackers are rational actors who prioritise efficiency, targeting systems with the highest potential return. This may not hold true for state-sponsored actors or highly motivated attackers who could exploit older systems if they perceive a strategic advantage. Engineers must weigh these risks against the benefits of reduced attacker interest.
The event highlights specific use cases where obsolete tech has been retained for security reasons. The Irish Aviation Authority, for instance, continues to use ground-based radio navigation beacons because GPS systems are susceptible to jamming. Similarly, militaries like Ukraine’s have reverted to paper maps and compasses to avoid electronic interference. These examples demonstrate that 'security by antiquity' is not just a theoretical concept but a practical strategy in high-stakes environments. However, the approach is niche and typically reserved for systems where reliability and resilience outweigh the convenience or capabilities of modern alternatives.
The broader implication for engineers is that security is not solely a function of software updates or cutting-edge technology. Context matters: the threat model, the user base, and the system’s criticality all influence whether older tech could be a viable security measure. For most commercial or consumer applications, the risks of using obsolete systems, such as compatibility issues, lack of support, and known vulnerabilities, outweigh the benefits. However, in specialised or high-security environments, the strategy may offer a low-cost way to mitigate certain types of cyber threats. The key takeaway is that security decisions should be tailored to the specific risks and constraints of the system in question.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗