// HACKER NEWS — CYBERSECURITY
Why older tech is sometimes safer from hackers
The fear of hacking has made some people turn to other forms of technology ignored by new generations of cyber criminals.
You might not expect a world-renowned cyber security expert to rely on old, potentially vulnerable email software. But, for years, that's what Mikko Hyppönen did. Shunning mainstream options such as Hotmail and Gmail, he instead chose obsolete email software called Eudora.
"I used to run it years after it was out of [technical] support," says Hyppönen, a Finnish computer security expert.
He preferred Eudora for various reasons, arguing it was "really superior in many ways". Although Eudora was far from perfectly secure, as people switched to newer email tools, Hyppönen realised that hackers were forgetting about Eudora.
Hyppönen calls it "security by antiquity". Others use the phrase "security by obsolescence" and in both cases this means relying on an older technology or system since it may prove, somewhat counterintuitively, safer than more recent alternatives.
While Hyppönen stresses that using the latest, fully patched and updated software is still "the optimum situation", there are specific cases where older tech could be preferable from a security standpoint.
"The vast majority of attackers are criminals trying to make money and it doesn't make any sense for them to target systems being run by 50 people," he explains.
Hyppönen isn't alone. The Irish Aviation Authority, for instance, recently decided to keep ground-based radio navigation beacons in use because supposedly the more modern satellite-based global positioning system (GPS) has proven so susceptible to jamming in recent years.
"Security by antiquity" is, it turns out, a quiet way of beating cyber-criminals, hackers and enemy attackers.
Matt Bishop, a computer scientist and professor emeritus at the University of California, Davis, has tested this principle, somewhat by accident. Back in the 1990s, he and his colleagues set up a system connected to the internet and deliberately left it accessible so that they could catch hackers and bots attempting to breach it. This is a common cyber-security research technique known as a honeypot – a kind of trap set up in carefully controlled conditions.