Theme 1 – Security through obscurity/antiquity is unreliable
Many commenters pointed out that relying on old or obscure software (e.g., Eudora, MS‑DOS) for safety is just “security through obsolescence,” which fails once an attacker decides to target you.
“Security through 'obsolescence' is no different from security through obscurity - therefore, it doesn't work.” – postexitus
“The client … isn't secure because it has no security vulnerabilities - it is secure because nobody bothers to target Eudora users in general.” – badsectoracula
Theme 2 – AI makes targeted attacks cheap and easy
Several users noted that AI dramatically reduces the effort needed to find and exploit niche systems, undermining the “nobody will bother” argument.
“Hey AI go individually research and target county clerks for getting direct access to their {specific system} is much more practical today than it was 10 years ago.” – jerf
“The whole ‘they won’t hack me because they won’t bother to target Eudora running on AIX 3.1’ is flawed in an age when AI is both ubiquitous and cheap.” – rbanffy
Theme 3 – Critical infrastructure must be networked, but needs proper security
The discussion on water/power utilities highlighted that geographic distribution demands communication links (often the internet for cost and simplicity), yet the connection must be treated as untrusted and protected with strong security measures.
“The water and power utilities are themselves large distributed systems. They need communications between elements … You really need to treat it as untrusted and build your security on top with encryption, authentication, authorization, etc.” – saltcured
“Remote monitoring … central control over large systems clearly has benefits … but the benefits are obvious, and the security risks must be managed.” – delecti (paraphrased)