‘Security by antiquity’: Why older tech is sometimes safer from hackers
‘Security by antiquity’: Why older tech is sometimes safer from hackers
AlamyThe fear of hacking has made some people turn to other forms of technology ignored by new generations of cyber criminals.
You might not expect a world-renowned cyber security expert to rely on old, potentially vulnerable email software. But, for years, that’s what Mikko Hyppönen did. Shunning mainstream options such as Hotmail and Gmail, he instead chose obsolete email software called Eudora.
“I used to run it years after it was out of [technical] support,” says Hyppönen, a Finnish computer security expert. Â
He preferred Eudora for various reasons, arguing it was “really superior in many ways”. Although Eudora was far from perfectly secure, as people switched to newer email tools, Hyppönen realised that hackers were forgetting about Eudora.
Hyppönen calls it “security by antiquity”. Others use the phrase “security by obsolescence” and in both cases this means relying on an older technology or system since it may prove, somewhat counterintuitively, safer than more recent alternatives.
While Hyppönen stresses that using the latest, fully patched and updated software is still “the optimum situation”, there are specific cases where older tech could be preferable from a security standpoint.
“The vast majority of attackers are criminals trying to make money and it doesn’t make any sense for them to target systems being run by 50 people,” he explains.
Getty ImagesHyppönen isn’t alone. The Irish Aviation Authority, for instance, recently decided to keep ground-based radio navigation beacons in use because supposedly the more modern satellite-based global positioning system (GPS) has proven so susceptible to jamming in recent years.
“Security by antiquity” is, it turns out, a quiet way of beating cyber-criminals, hackers and enemy attackers.
Matt Bishop, a computer scientist and professor emeritus at the University of California, Davis, has tested this principle, somewhat by accident. Back in the 1990s, he and his colleagues set up a system connected to the internet and deliberately left it accessible so that they could catch hackers and bots attempting to breach it. This is a common cyber-security research technique known as a honeypot – a kind of trap set up in carefully controlled conditions.
But the team picked an older software version for their honeypot that had been upgraded multiple times since its release and, consequently, no hackers bothered to target it. “When we upgraded it to the new one, we had all the attacks we wanted,” recalls Bishop. “I thought it was so amusing.”
This possibility of evading nefarious activity by sticking to old tech can take many forms. Both Bishop and Hyppönen say they have friends who refuse to get a smartphone. “One person I know [uses] a Nokia 9210,” says Hyppönen, referring to a simple, “dumb” mobile phone first released 25 years ago.
As technology has advanced, experts have often questioned whether the latest systems are actually more risky than older ones
While hackers can’t target it in quite the same way they might target a modern Android or iOS device, the phone’s operating system, Symbian, does have some old, known vulnerabilities. The flipside is that “nobody’s targeting them anymore”, adds Hyppönen. Similarly, the Nokia could be more at risk from techniques that snoop on phone calls. But how many people will bother? It’s a security trade-off.
As technology has advanced, experts have often questioned whether the latest systems are actually more risky than older ones. During the late 1990s, Bishop wrote a speech in which he argued that computers were “considerably less secure than the paper systems we still use, and that are rapidly being replaced”.
Concerns about the shift from paper to digital technologies remain prevalent, especially when it comes to electronic voting systems. Some say electronic voting machines are desirable partly because they produce election results much more quickly than paper-based systems. That’s not enough to sway others, though.
“Voting is the bedrock of our democracy,” says Hyppönen. “It’s one of the last things I’d like to weaken in any way, especially if the benefits are so small.”
Militaries are also known for being reluctant to take chances. Even the world’s most active militaries are known to occasionally rely on old technologies for reasons of reliability and security. “One thing I’ve seen in places like Ukraine is the use of paper maps, or laminated maps, and compasses,” says Thomas Withington, associate fellow at the Royal United Services Institute, a think tank. “You can’t jam that.” It’s a kind of “analogue resilience”, he adds.
Getty ImagesJamming attacks hitting GPS-based navigation have forced some countries to make careful choices about which legacy technologies to retain, and which GPS alternatives to invest in, says Victor Tasiemski, a systems engineer at Overlook Systems Technologies, which works on navigation tech.
That’s exactly what happened in Ireland, where a programme to replace ground-based radio beacons has been slowed down in order to keep those beacons operating for longer. A spokeswoman for the Irish Aviation Authority told the Irish Times in June that the beacons were being retained “as part of a planned resilience strategy”.
Technologists who work with militaries are familiar with the challenge of designing systems that can link old and new technologies together. Stefan Kraus is co-founder and chief technical officer of Kraus Hamdani Aerospace, which has designed a drone-based communications platform that can connect military personnel to one another, no matter whether they are using older radios or newer ones. Military radio tech that has been around for decades is “tried, tested and secure”, he says. “The US military isn’t going away from that.”
Ransomware is what, for me, kept tape in business the past 10 to 15 years – Hugues Mayreth
Tasiemski notes that one alternative to GPS-based navigation is eLoran, a radio-based navigation system that has its roots in military technology first developed during World War Two. With attacks targeting GPS systems, eLoran is arguably becoming increasingly desirable, says Tasiemski, because it uses a much more powerful signal and is therefore much trickier to jam: “Overpowering a one-megawatt transmitter is pretty hard.”
Robustness is not easy to replace. This applies in the world of data storage, too, where magnetic tape – invented during the 1950s – still plays a huge role today. Companies, research institutions and government agencies continue to store vast amounts of data on reels of tape. The technology has improved significantly since it first appeared, with data storage densities having increased exponentially over the decades.
But the principle remains the same: spools of tape that hold information. The tape can be detached from computer systems, packaged, and transported to secure facilities, including difficult-to-breach underground caverns and repurposed mines.
Getty Images“Ransomware is what, for me, kept tape in business the past 10 to 15 years,” says Hugues Meyrath, chief executive of Quantum, a company that specialises in data storage.
An organisation locked out of its own computer systems may still be able to retrieve its most important data if staff have made good back-ups, for example on magnetic tape. Interest in magnetic tape is only increasing further today because the cost of random access memory (Ram), a form of computer memory that doesn’t rely on tape, is skyrocketing. Meyrath says his company’s clients use tape to store all kinds of data – from broadcasters’ footage of baseball games to genomes mapped in detail by research facilities.
More like this:
Tape’s security attributes stem partly from the fact that most people don’t tend to interact with it at all. It’s obscure, clunky, old-school tech. “One way to attack a system is to rig a set of USB sticks and throw them around a parking lot,” says Bishop, referring to the likelihood that someone will eventually pick up one of the USB sticks and insert it into their computer – a simple way to perpetrate a hack. As he puts it: “You’ll never see magnetic tape thrown around a parking lot.”
Experts who spoke to the BBC still recommend that people use the latest and most up-to-date technologies for everyday tasks, as it remains the safest approach. But it is worth acknowledging that “new” doesn’t necessarily mean “best” in all scenarios. And knowing when and how to switch to older systems could become increasingly important, as cyber-attacks and other threats get more sophisticated.
Withington points again to Ukraine, where Russia has interfered with satellite communications and where GPS navigation has succumbed to significant jamming. Nowhere is “analogue resilience” more prized. “What do people do,” asks Withington, “if there’s no access to the technology they take for granted?”
—
For more insights, sign up to our Tech Decoded newsletter, where Lily Jamali and Thomas Germain break down the biggest stories of the tech world, and help you live a better digital life. Sign up for free here.Â
Original source: https://www.bbc.com/
