Browse Definitions :
Definition

security through obsolescence

Security through obsolescence is the use of obsolete technologies whose vulnerabilities are no longer well known among the public.

Less common or obsolete software has fewer issues with malware as it lacks the market share that would make it attractive to a hacker. Furthermore, obsolete systems can be difficult for an attacker to target as the design, flaws, protocols and even programming may have fallen out of common knowledge.

Although security through obscurity is generally deprecated, security through obsolescence is still sometimes used in networking, such as the use of antiquated X.25 networks by ATMs.

Security through obsolesce, like security through minority is a strategy best confined to closed source software. While there are rare and obsolete variants of open source software, their source code is publicly available so that it is much easier for an attacker to find vulnerabilities.

Obsolete but still heavily used software can be about the worst possible option, however. Software at the end of a long lifespan, such as Windows XP, can provide a large target base. There is likely to be existing malware targeting it, while patches and support may have been discontinued.

This was last updated in July 2015

Continue Reading About security through obsolescence

SearchNetworking
  • network packet

    A network packet is a basic unit of data that's grouped together and transferred over a computer network, typically a ...

  • virtual network functions (VNFs)

    Virtual network functions (VNFs) are virtualized tasks formerly carried out by proprietary, dedicated hardware.

  • network functions virtualization (NFV)

    Network functions virtualization (NFV) is a network architecture model designed to virtualize network services that have ...

SearchSecurity
  • Domain-based Message Authentication, Reporting and Conformance (DMARC)

    The Domain-based Message Authentication, Reporting and Conformance (DMARC) protocol is one leg of the tripod of internet ...

  • data breach

    A data breach is a cyber attack in which sensitive, confidential or otherwise protected data has been accessed or disclosed in an...

  • insider threat

    An insider threat is a category of risk posed by those who have access to an organization's physical or digital assets.

SearchCIO
  • data privacy (information privacy)

    Data privacy, also called information privacy, is an aspect of data protection that addresses the proper storage, access, ...

  • leadership skills

    Leadership skills are the strengths and abilities individuals demonstrate that help to oversee processes, guide initiatives and ...

  • data governance policy

    A data governance policy is a documented set of guidelines for ensuring that an organization's data and information assets are ...

SearchHRSoftware
SearchCustomerExperience
  • recommerce

    Recommerce is the selling of previously owned items through online marketplaces to buyers who reuse, recycle or resell them.

  • implementation

    Implementation is the execution or practice of a plan, a method or any design, idea, model, specification, standard or policy for...

  • first call resolution (FCR)

    First call resolution (FCR) is when customer service agents properly address a customer's needs the first time they call.

Close