How can older technology provide greater cybersecurity than modern technology?

Finnish cybersecurity expert Mikko Hyppönen relies on an old email client called Eudora, whose technical support has been discontinued for years, preferring it over modern options such as Gmail and Hotmail, based on a principle he calls “security by obsolescence.” According to this approach, hackers tend to forget about targeting outdated technologies that are now used by only a small number of people. Hyppönen explains that the vast majority of attackers are criminals seeking profit, and it makes no sense for them to target systems used by only a handful of people.
This principle is illustrated in several cases. The Irish Aviation Authority recently decided to keep using ground-based radio navigation beacons because the newer Global Positioning System (GPS) has proven vulnerable to jamming. Similarly, computer scientist Matt Bishop from the University of California, Davis, conducted a practical test of this principle by setting up a honeypot using an old version of a software program that had never been attacked by hackers. However, as soon as he upgraded it to the latest version, it came under heavy attack.
• Some experts refuse to own smartphones, opting instead for simple phones such as the Nokia 9210, released 25 years ago. Hackers do not target such devices in the same way they target modern Android or iOS devices, despite known vulnerabilities in its Symbian operating system.
• Using outdated technologies as a means to avoid surveillance and hacking. Experts argue that older systems may be more secure in certain specific contexts, even if they are not updated.
Nevertheless, Hyppönen emphasizes that using the latest fully updated software remains the “optimal” approach from a security standpoint, and that “security by obsolescence” is not a substitute for security updates but rather a complementary strategy in specific situations.
Experts view the principle of “security by obsolescence” as a quiet way to outmaneuver cybercriminals, and maintaining older technologies may be a strategic choice in a world where the pace of cyber threats is accelerating, provided that users are fully aware of the associated risks.