Comment by postexitus
9 hours ago
I understand BBC may not have the technical background to critically assess this approach, but whoever using Eudora (I loved it in 2001 btw) for security should get their credentials removed via King's order. Security through "obsolescence" is no different from security through obscurity - therefore, it doesn't work. Somebody not bothering to look for holes in your software doesn't mean they don't exist - in the age of Claude - I am pretty sure I can destroy your legacy software in minutes.
> in the age of Claude - I am pretty sure I can destroy your legacy software in minutes.
Yes but you'd need to a) know that they use that particular software and b) have a reason to bother destroying it in the first place.
That is really the crux of the idea.
The client the guy in the article uses isn't secure because it has no security vulnerabilities - it is secure because nobody bothers to target Eudora users in general.
Of course as others mentioned, if the target switches from "Eudora users in general" to "that guy in particular" then the situation changes (though the attackers would still need to realize he uses Eudora - assuming this article didn't exist to reveal it anyway :-P).
But aside from that, even "in the age of Claude", i doubt anyone is wasting time and/or tokens scanning the open Internet for all sorts of old vulnerabilities in antique software that (relatively) nobody uses in hopes they catch some random passer-by as there is barely any ROI by doing that compared to taking advantage of vulnerabilities on software that people actually use.
I would be curious to know what kind of vulnerabilities the latest version of Eudora (7.1.0.9 I think) has. With how old it is (2006), surely there are several critical vulnerabilities, but all I could find when looking online is that an IMAP server or SMTP server can execute arbitrary code, which doesn't seem likely to cause a real problem, because I wouldn't expect Google, Yahoo, Microsoft, etc. to use this trick.
The article links to a vulnerability from 1998, which I expect is already fixed in the versions of Eudora people still use.
I agree it would probably be easy for AI to find exploitable bugs though.
> I understand BBC may not have the technical background...
This is BBC Future - the BBC's tech clickbait publisher - not BBC News.
BBC consists of the non-profit news bureau as well as at least a dozen for-profit clickbait and listicle publishers. BBC's ad-free mandate is only for the UK.
> in the age of Claude - I am pretty sure I can destroy your legacy software in minutes
Yep. One of our PortCos has unrestricted access to Anthropic and GPT models. With whitebox testing, it's trivial to identify vulns in legacy environments. With blackbox testing, it takes some effort but it doable with the right steering.
wait until you find out that a large percentage of operating system developers use mutt, alpine or mail.