Live data from Hacker News

Why older tech is sometimes safer from hackers

bbc.com

51–60 of 87 posts

Re: Why older tech is sometimes safer from hackers

#51

I understand BBC may not have the technical background to critically assess this approach, but whoever using Eudora (I loved it in 2001 btw) for security should get their credentials removed via King's order. Security through "obsolescence" is no different from security through obscurity - therefore, it doesn't work. Somebody not bothering to look for holes in your software doesn't mean they don't exist - in the age…

I would be curious to know what kind of vulnerabilities the latest version of Eudora (7.1.0.9 I think) has. With how old it is (2006), surely there are several critical vulnerabilities, but all I could find when looking online is that an IMAP server or SMTP server can execute arbitrary code, which doesn't seem likely to cause a real problem, because I wouldn't expect Google, Yahoo, Microsoft, etc. to use this trick.

The article links to a vulnerability from 1998, which I expect is already fixed in the versions of Eudora people still use.

I agree it would probably be easy for AI to find exploitable bugs though.

Re: Why older tech is sometimes safer from hackers

#52
There is definitely a trough of vulnerability for older machines.

For Windows 3.1/95/98 I feel they were incredibly vulnerable in the 2000s and 2010s, but now they have aged so much where getting to them is becoming a hurdle and a chore preventing attackers from making it to the target.

Re: Why older tech is sometimes safer from hackers

#53
post #49

Earlier quoted context omitted.

Why are our water and power utilities connected to the internet? Is it so that the employees controlling them can work from home? If so they are accepting too much risk relative to the benefit.

think about a grid responding to demand. The old model (like the titanic) had a remote manager phoning the site lead who phoned the control room who phoned the engineering room. Remote management has clear benefits, don’t be obtuse. I totally agree on the security risks, but the benefits are obvious.

I'm not seeing why it has to be connected to the internet. Make it a private, air-gapped intranet for all (or most) of the benefits of being "connected", but with no entry point for someone sitting on another continent to turn off the water.

Re: Why older tech is sometimes safer from hackers

#54
post #43

I am one of those emacs users who use it for everything, it always worries me the way that it could be attacked given (particularly email some how evaling some elisp or something), Despite how easy emacs would be to exploit in many aspects I do not know of any attack done on emacs either through supply chain attack (think about how many third party libs an emacs mode might use) or one of the many ways that it's no do…

See "The Cuckoo's Egg" [1] by Cliff Stoll (who sometimes posts here [2]). A few related HN threads: [3] [4] [5]. The book describes tracking down a hacker in 1986 who exploited a vulnerability in early Emacs' movemail utility.

[1] https://en.wikipedia.org/wiki/The_Cuckoo%27s_Egg_(book)

[2] https://news.ycombinator.com/user?id=CliffStoll

[3] https://news.ycombinator.com/item?id=21830277

[4] https://news.ycombinator.com/item?id=39843930

[5] https://news.ycombinator.com/item?id=49406713

Re: Why older tech is sometimes safer from hackers

#55
post #8

It's incredible how far back the surveillance state goes - GSM mobile phones have an IMEI number that's tied to the handset - and the SIM is tied to the subscriber, and your phone broadcasts imei to neighboring towers constantly. I haven't really gotten really into this, but from what I can tell, anything that has to do with mobile phones is strictly worse in terms of anonimity than Wifi. At least anything that ties…

Doesn't the whole SIM architecture exist so that phones don't have to be trusted? I believe IMEI can be anything in practice, so long that there isn't a blatant duplicate nearby, a bit like Ethernet MAC address. I don't know if it's legal but phone nerds seem to be editing IMEI all the time for non-Apple phones as well, using those leaked vendor tools.

Re: Why older tech is sometimes safer from hackers

#56

Sadly, the real lesson we need to learn from Battlestar Galactica is not this. They weren't saved by old software, they were saved by not having critical systems on the network unnecessarily. Our water and power utilities need to re-watch the pilot.

Why are our water and power utilities connected to the internet? Is it so that the employees controlling them can work from home? If so they are accepting too much risk relative to the benefit.

Sounds like a good application of mesh networks.

Re: Why older tech is sometimes safer from hackers

#57
post #54
post #43

I am one of those emacs users who use it for everything, it always worries me the way that it could be attacked given (particularly email some how evaling some elisp or something), Despite how easy emacs would be to exploit in many aspects I do not know of any attack done on emacs either through supply chain attack (think about how many third party libs an emacs mode might use) or one of the many ways that it's no do…

See "The Cuckoo's Egg" [1] by Cliff Stoll (who sometimes posts here [2]). A few related HN threads: [3] [4] [5]. The book describes tracking down a hacker in 1986 who exploited a vulnerability in early Emacs' movemail utility. [1] https://en.wikipedia.org/wiki/The_Cuckoo%27s_Egg_(book) [2] https://news.ycombinator.com/user?id=CliffStoll [3] https://news.ycombinator.com/item?id=21830277 [4] https://news.ycombinator.co…

Very nice thank you!

Re: Why older tech is sometimes safer from hackers

#58
post #44

Earlier quoted context omitted.

> surveillance state How do you suppose mobile phones are meant to work without subscriber info? > I haven't really gotten really into this Clearly.

I think the argument is more the IMEI side of things, one might naively expect that they could could simply change SIM and that would change ones identity and that anything like an IMEI could be easily configurable like how a MAC is on a NIC is.

IMEI is needed to allow them to identify the device's capabilities, and know if it's been reported stolen.

Re: Why older tech is sometimes safer from hackers

#59
post #53
post #49

Earlier quoted context omitted.

think about a grid responding to demand. The old model (like the titanic) had a remote manager phoning the site lead who phoned the control room who phoned the engineering room. Remote management has clear benefits, don’t be obtuse. I totally agree on the security risks, but the benefits are obvious.

I'm not seeing why it has to be connected to the internet. Make it a private, air-gapped intranet for all (or most) of the benefits of being "connected", but with no entry point for someone sitting on another continent to turn off the water.

mostly, because setting up a separate network is harder.

a virtual network built upon the regular internet is much easier.

And yes, mostly done wrong

Re: Why older tech is sometimes safer from hackers

#60

Sadly, the real lesson we need to learn from Battlestar Galactica is not this. They weren't saved by old software, they were saved by not having critical systems on the network unnecessarily. Our water and power utilities need to re-watch the pilot.

> the real lesson we need to learn from Battlestar Galactica

It's the same lesson that we can learn from Star Trek, Star Wars, and all the other self-aggrandising lore that humanity concocts when gazing lovingly in the mirror.

There is no greater enemy than greedy, barbaric humanity itself.

Post reply on HN