The fear of hacking is prompting some people to look beyond the latest cybersecurity tools and consider an unexpected alternative: old technology.
While outdated software is generally considered vulnerable because it no longer receives security updates, some cybersecurity experts argue that obsolete systems can sometimes offer a different kind of protection. The idea is that cybercriminals may simply stop targeting technologies that are no longer widely used.
One expert who has adopted this approach is Finnish cybersecurity specialist Mikko Hyppönen, who for years avoided mainstream email services such as Hotmail and Gmail in favour of the now-obsolete email software Eudora.
Hyppönen continued using Eudora even years after it had stopped receiving technical support. He said he preferred the software because he considered it superior in several ways.
Security by Obsolescence Offers an Unusual Approach
Hyppönen describes his strategy as “security by antiquity.” Others refer to the concept as “security by obsolescence.”
The idea is relatively simple: technology that is no longer popular may attract less attention from hackers because there are fewer potential victims and less incentive to develop new attacks against it.
As users moved away from older email platforms and adopted modern services, Hyppönen noticed that cybercriminals appeared to lose interest in Eudora.
However, this does not mean obsolete technology is inherently secure. Older software can contain unpatched vulnerabilities and may lack modern security protections.
Cybercriminals generally look for targets that provide the greatest potential reward. Popular operating systems, widely used applications and major online platforms can offer access to millions of potential victims.
By contrast, an obsolete programme with a very small user base may not be worth the effort required to develop a specialised attack.
This creates a form of security through obscurity, although security experts generally warn that obscurity alone should never replace proper cybersecurity measures.
The strategy can therefore work only in very specific circumstances and should not be interpreted as a recommendation to abandon security updates.
The concept of security by obsolescence comes with significant risks.
Unsupported software does not receive patches for newly discovered vulnerabilities, meaning hackers who do target it could potentially exploit weaknesses that will never be fixed.
Modern applications also contain security features that older programmes may lack, including stronger encryption, multi-factor authentication and protections against increasingly sophisticated attacks.
For most users, cybersecurity professionals continue to recommend keeping software updated and using supported products.
Cybersecurity Requires More Than Old Technology
The story of Eudora highlights an unusual aspect of cybersecurity: sometimes being outside the mainstream can reduce attention from attackers, but that does not automatically make a system secure.
The safest approach for most people remains a combination of regular software updates, strong passwords, multi-factor authentication, security awareness and reliable security tools.
Hyppönen’s experience nevertheless demonstrates how the changing behaviour of cybercriminals can create unexpected security advantages for technologies that have largely disappeared from everyday use.


