Best not to apply common sense to computer security issues because it's an exceptionally complicated subject, a specialism that many IT Professionals don't fully understand either!
Security depends on multiple interacting elements ranging from human naivety through to some of the most obscure and difficult to understand maths on the planet via implementation shortcomings and the Law of Unexpected Consequences. The war against security loop-holes rages continually.
Generally, you can assume that old software is much less secure than new software, not least because large numbers of security problems have been identified since older software was written. Unless happy to take the risk, software should be kept up to date unless the computer is never connected to the internet. Too many are happy to take the risk because they have no idea what the risks are.
There are many ways weak computers can be abused. A Cabinet Office Report published in 2011 estimated the cost of Cyber Crime in the UK to be about £27Bn. Businesses suffered most due to loss of Intellectual Property, Espionage and Online Theft, but private users were also exploited on a grand scale, roughly:
- Online fraud – £1.2Bb (Paying for goods that don't exist and account milking.)
- Scareware – £100M (Software that frightens victims into paying unnecessary removal fees.)
- Identity Theft – £1.8Bn (Extracting enough private information about individuals so they can be impersonated. )
- Data Loss – £2.1Bn (Malicious software deletes data for fun.)
- Extortion – £2Bn (Software that locks and encrypts the computer so the owner cannot get anything in or out of it until he pays a fee to have it decrypted, which might never happen.)
- Fiscal Fraud – £2Bn (Bank and other account frauds)
Hacked computers are also used to send spam emails, and to host advertising, pornography and pirated software. This abuse is transparent until the owner investigates why his machine or network connection is unusually sluggish, or a policeman calls.
Of these I worry most about Identity Theft. All that's necessary is for my computer to leak enough personal information for someone else to establish themselves as me. Birthday, Mothers Maiden Name, Account Numbers, interests and memberships, doctor and medical details, and other trivia can be assembled into a convincing 'this chap must be Dave' portfolio. Playing back information to the victim is common to many confidence tricks, but more likely the impersonation is used to borrow money or buy goods in your name. Some unfortunates have had their houses sold whilst on holiday! Sorting out the resulting mess is massively inconvenient and some people have their identity used repeatedly for multiple frauds. Guess what happens to your financial credibility when someone successfully passes themselves as you! Especially if the police get the idea you are part of the fraud rather than a victim…
My advice, avoid lazy security and don't share personal information unnecessarily. Don't assume they won't notice little old you; the internet is scanned looking for the weaklings. If your machine admits to running Internet Explorer 5 on XP Whistler, hungry lions might home in on it because out of date computers suggest negligent or incompetent owners. Cyber crime is successfully hitting much tougher targets than Model Engineers: the US Department of Homeland Security and Microsoft were amongst the many victims of last year's Sunburst attack.
Dave
Edited By SillyOldDuffer on 03/03/2021 17:22:26