I understand BBC may not have the technical background to critically assess this approach, but whoever using Eudora (I loved it in 2001 btw) for security should get their credentials removed via King's order. Security through "obsolescence" is no different from security through obscurity - therefore, it doesn't work. Somebody not bothering to look for holes in your software doesn't mean they don't exist - in the age…
The article links to a vulnerability from 1998, which I expect is already fixed in the versions of Eudora people still use.
I agree it would probably be easy for AI to find exploitable bugs though.