Live data from Hacker News

Why older tech is sometimes safer from hackers

bbc.com

61–70 of 87 posts

Re: Why older tech is sometimes safer from hackers

#61
post #38

Earlier quoted context omitted.

It makes sense to have them connected for a lot of reasons.

which reasons?

In addition to remote monitoring, central control over large systems clearly has benefits: quickly and automatically spinning up a power generation in one location in response to an outage or just increased demand in another one, or conversely spooling down generation in response to a large demand spike going away (many factories need to notify the grid before starting up or shutting down), shutting down water/gas flow upstream of a detected leak, or yes, working from home, which lots of people here regularly argue is a good thing.

You could absolutely make the case that it isn't worth the risk, but that isn't the same as not having benefits.

Re: Why older tech is sometimes safer from hackers

#62
post #44

Earlier quoted context omitted.

I think the argument is more the IMEI side of things, one might naively expect that they could could simply change SIM and that would change ones identity and that anything like an IMEI could be easily configurable like how a MAC is on a NIC is.

IMEI is needed to allow them to identify the device's capabilities, and know if it's been reported stolen.

Sure and of course surveil in general. To advertise capabilities one does not need a unique identifier it's clear that part of the rational for the development is to allow for control over the devices by telco's and/or the state, in a way that link layer for other networking technology did not. A while ago I brought a pixel second hand my intention to put a custom rom on it but it was locked by the carrier entirely and though unlocked the carrier simply decided to not allow their pixels to be flashed. All of that to say that obviously the decisions made where not entirely for simply because of the technical reality or for reasons beneficial to the users and lots of things that are hostile to privacy and real ownership of the device.

Re: Why older tech is sometimes safer from hackers

#63

This seems largely to be about security by obscurity. I was hoping it was gonna be about how our modern practices are making things less secure. For instance, we claim we need to be able to rapidly update clients so that we can patch security vulnerabilities as they are discovered (often without involving the user at all). And there are a lot of companies that have an incentive to push this narrative because they hav…

Right, the sub-headline "security through antiquity" is a nod to both the oft-repeated "security through obscurity," while pointing out the fact that antiquity is sometimes underutilized or undervalued as a security mechanism (even if not tamperproof). Cyber defenses are thus best multi-pronged, which offers the best protection- by maximizing the amount of time an intruder would need to spend to determine what system it is using.

About your second comment- newer systems CAN be less secure, but not always. But even if they are, falling back on things like eLoran are important.

Re: Why older tech is sometimes safer from hackers

#64

Sadly, the real lesson we need to learn from Battlestar Galactica is not this. They weren't saved by old software, they were saved by not having critical systems on the network unnecessarily. Our water and power utilities need to re-watch the pilot.

> the real lesson we need to learn from Battlestar Galactica It's the same lesson that we can learn from Star Trek, Star Wars, and all the other self-aggrandising lore that humanity concocts when gazing lovingly in the mirror. There is no greater enemy than greedy, barbaric humanity itself.

They're good lessons, so why insult it? Why mock quality storytelling that makes good impressions on people?

Re: Why older tech is sometimes safer from hackers

#65
post #16
post #2

MS-DOS: Over 45 years, and STILL NO remote holes in the default install!

Well, there is no protection against compromised floppy disk sent by snail mail. I have also seen virus source code published in books and magazines. We don't have such threats anymore.

Yes there is. Simply don't boot it or execute the virus. There is no autorun in MS-DOS, you know...

Re: Why older tech is sometimes safer from hackers

#67

I understand BBC may not have the technical background to critically assess this approach, but whoever using Eudora (I loved it in 2001 btw) for security should get their credentials removed via King's order. Security through "obsolescence" is no different from security through obscurity - therefore, it doesn't work. Somebody not bothering to look for holes in your software doesn't mean they don't exist - in the age…

> in the age of Claude - I am pretty sure I can destroy your legacy software in minutes.

Yes but you'd need to a) know that they use that particular software and b) have a reason to bother destroying it in the first place.

That is really the crux of the idea.

The client the guy in the article uses isn't secure because it has no security vulnerabilities - it is secure because nobody bothers to target Eudora users in general.

Of course as others mentioned, if the target switches from "Eudora users in general" to "that guy in particular" then the situation changes (though the attackers would still need to realize he uses Eudora - assuming this article didn't exist to reveal it anyway :-P).

But aside from that, even "in the age of Claude", i doubt anyone is wasting time and/or tokens scanning the open Internet for all sorts of old vulnerabilities in antique software that (relatively) nobody uses in hopes they catch some random passer-by as there is barely any ROI by doing that compared to taking advantage of vulnerabilities on software that people actually use.

Re: Why older tech is sometimes safer from hackers

#68
>The Irish Aviation Authority, for instance, recently decided to keep ground-based radio navigation beacons in use because supposedly the more modern satellite-based global positioning system (GPS) has proven so susceptible to jamming in recent years.

Back when my friend Jim (retired Pilot) and I visited Chicago's Approach Control facility, I asked one question "What would happen if GPS went away?", they didn't like the question one bit.

It's really not good the way we're getting rid of ground based navigation aids in the US.

Re: Why older tech is sometimes safer from hackers

#69

Sadly, the real lesson we need to learn from Battlestar Galactica is not this. They weren't saved by old software, they were saved by not having critical systems on the network unnecessarily. Our water and power utilities need to re-watch the pilot.

Why are our water and power utilities connected to the internet? Is it so that the employees controlling them can work from home? If so they are accepting too much risk relative to the benefit.

Because other replies aren't really stating it explicitly, let me add...

The water and power utilities are themselves large distributed systems. They need communications between elements just to function properly. They don't exist in a single location where people can go locally manage them in some air-gapped, offline fashion.

There is no option of not having a communication network to monitor and manage these geographically distributed elements. The question is which communication network you would use, and how you would secure it. Whether it is telephones, radio links, or people running around as messengers, it is still a communications network.

Will some "dedicated" network be any safer? If anything, I imagine the fantasy of a private network will lead to even less security. You cannot physically secure the entire signal path. You really need to treat it as untrusted and build your security on top with encryption, authentication, authorization, etc.

Re: Why older tech is sometimes safer from hackers

#70
post #53
post #49

Earlier quoted context omitted.

think about a grid responding to demand. The old model (like the titanic) had a remote manager phoning the site lead who phoned the control room who phoned the engineering room. Remote management has clear benefits, don’t be obtuse. I totally agree on the security risks, but the benefits are obvious.

I'm not seeing why it has to be connected to the internet. Make it a private, air-gapped intranet for all (or most) of the benefits of being "connected", but with no entry point for someone sitting on another continent to turn off the water.

Are you talking about the media layer or the application layer? What would be the alternative to using the internet media layer? Every utility running their own private media ? So a duplicate network of media, as broad physically as the internet, that’s not connected to the internet? That hackers could tap into, and with poorer security, because it wouldn’t be constantly probed.
Post reply on HN