Browse Definitions :
Definition

security through obsolescence

Security through obsolescence is the use of obsolete technologies whose vulnerabilities are no longer well known among the public.

Less common or obsolete software has fewer issues with malware as it lacks the market share that would make it attractive to a hacker. Furthermore, obsolete systems can be difficult for an attacker to target as the design, flaws, protocols and even programming may have fallen out of common knowledge.

Although security through obscurity is generally deprecated, security through obsolescence is still sometimes used in networking, such as the use of antiquated X.25 networks by ATMs.

Security through obsolesce, like security through minority is a strategy best confined to closed source software. While there are rare and obsolete variants of open source software, their source code is publicly available so that it is much easier for an attacker to find vulnerabilities.

Obsolete but still heavily used software can be about the worst possible option, however. Software at the end of a long lifespan, such as Windows XP, can provide a large target base. There is likely to be existing malware targeting it, while patches and support may have been discontinued.

This was last updated in July 2015

Continue Reading About security through obsolescence

SearchCompliance
  • pure risk

    Pure risk refers to risks that are beyond human control and result in a loss or no loss with no possibility of financial gain.

  • risk reporting

    Risk reporting is a method of identifying risks tied to or potentially impacting an organization's business processes.

  • risk profile

    A risk profile is a quantitative analysis of the types of threats an organization, asset, project or individual faces.

SearchSecurity
  • script kiddie

    Script kiddie is a derogative term that computer hackers coined to refer to immature, but often just as dangerous, exploiters of ...

  • cipher

    In cryptography, a cipher is an algorithm for encrypting and decrypting data.

  • What is risk analysis?

    Risk analysis is the process of identifying and analyzing potential issues that could negatively impact key business initiatives ...

SearchHealthIT
SearchDisasterRecovery
  • What is risk mitigation?

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • fault-tolerant

    Fault-tolerant technology is a capability of a computer system, electronic system or network to deliver uninterrupted service, ...

  • synchronous replication

    Synchronous replication is the process of copying data over a storage area network, local area network or wide area network so ...

SearchStorage
  • gigabyte (GB)

    A gigabyte (GB) -- pronounced with two hard Gs -- is a unit of data storage capacity that is roughly equivalent to 1 billion ...

  • MRAM (magnetoresistive random access memory)

    MRAM (magnetoresistive random access memory) is a method of storing data bits using magnetic states instead of the electrical ...

  • storage volume

    A storage volume is an identifiable unit of data storage. It can be a removable hard disk, but it does not have to be a unit that...

Close