Live data from Hacker News

Why older tech is sometimes safer from hackers

bbc.com

31–40 of 87 posts

Re: Why older tech is sometimes safer from hackers

#31
post #7

Earlier quoted context omitted.

Let's say your security budget is pretty limited, and you can say with relative certainly that there's only a 0.1% chance of any adversary bothering to check the known flaws in your FossileWare(tm) Firewall in a given month. Vs.how many dire flaws have been found in big-name security products in the past year, that even a low-budget adversary is likely to be regularly checking for?

There is no human making a decision on what attacks to run. They check for literally everything. 20 years ago, I ran a web server and would run 'tail -f' on the access logs. I watched the bots sending requests for files that only exist on linux, then send requests for files that only exist on windows. They don't know what kind of system they are hacking. They just know that there is a computer at that IP address. The…

Yep, this kind of stuff is easily automated these days and bots don't get bored.

Re: Why older tech is sometimes safer from hackers

#33
post #8

It's incredible how far back the surveillance state goes - GSM mobile phones have an IMEI number that's tied to the handset - and the SIM is tied to the subscriber, and your phone broadcasts imei to neighboring towers constantly. I haven't really gotten really into this, but from what I can tell, anything that has to do with mobile phones is strictly worse in terms of anonimity than Wifi. At least anything that ties…

> surveillance state

How do you suppose mobile phones are meant to work without subscriber info?

> I haven't really gotten really into this

Clearly.

Re: Why older tech is sometimes safer from hackers

#34
post #7

Earlier quoted context omitted.

Let's say your security budget is pretty limited, and you can say with relative certainly that there's only a 0.1% chance of any adversary bothering to check the known flaws in your FossileWare(tm) Firewall in a given month. Vs.how many dire flaws have been found in big-name security products in the past year, that even a low-budget adversary is likely to be regularly checking for?

> a 0.1% chance of any adversary bothering to check the known flaws in your FossileWare(tm) Firewall in a given month. How would you arrive at this percentage in your risk analysis?

If you're getting scanned, keep logs, and have a decent way to tag log entries with the associated vuln, then you can start building statistical models of how exploit attempt probabilities fade as the target software gets older and lower market share. No, the 0.1% won't be exact. Yes, such data and models can be shared.

Paying $$$ for a LatestGreatest(tm) Firewall won't make you 100% secure either. And the $$$ might better be spent on an extra layer of swiss cheese, or better recovery capability.

Re: Why older tech is sometimes safer from hackers

#35

Money defines the targets, and usually people running old software are thought not to have money. It is a zero sum game that shifts with the technology and ends when technology no longer is the theater where people can make or steal money.

Eh not really true at all with my experience. 100 million dollar industries commonly have old crap running for years that becomes nearly untouchable as staff rotates and everyone gets afraid to touch it.

Re: Why older tech is sometimes safer from hackers

#36

Sadly, the real lesson we need to learn from Battlestar Galactica is not this. They weren't saved by old software, they were saved by not having critical systems on the network unnecessarily. Our water and power utilities need to re-watch the pilot.

Why are our water and power utilities connected to the internet? Is it so that the employees controlling them can work from home? If so they are accepting too much risk relative to the benefit.

Re: Why older tech is sometimes safer from hackers

#37

Sadly, the real lesson we need to learn from Battlestar Galactica is not this. They weren't saved by old software, they were saved by not having critical systems on the network unnecessarily. Our water and power utilities need to re-watch the pilot.

Why are our water and power utilities connected to the internet? Is it so that the employees controlling them can work from home? If so they are accepting too much risk relative to the benefit.

It makes sense to have them connected for a lot of reasons.

Re: Why older tech is sometimes safer from hackers

#38

Earlier quoted context omitted.

Why are our water and power utilities connected to the internet? Is it so that the employees controlling them can work from home? If so they are accepting too much risk relative to the benefit.

It makes sense to have them connected for a lot of reasons.

which reasons?
Post reply on HN