Try to setup a windows 98 machine as a web server and see how it goes (Windows XP only came out in 2002). It doesn't do HTTP/1.1 so it's good question whether clients would be able to connect at all.
Windows 98 was a client OS, it was never intended for this. A proper test would be Windows NT 4.0 Server. Or more realistically for the time frame, Solaris 7 or 8.
Obviously forget about any security.
When you're running a server, TLS is not the only service you are dependent on; you're also dependent on security updates. If they're not backported, you'll need to make version upgrades.
Arguably it's better to think of every piece of software running on a server like it's a service, to maintain security and performance in an Internet full of hostile actors.
I don't even understand the mindset of wanting to run a live server on ancient software, aside from doing it as a hobby. In which case, it's pretty typical for such hobbies to require extra work and care. Driving around in a car from 1940s takes more maintenance work, and is less safe, than a modern car, and everyone gets that.
Of course, I was rolling my own query sanitizers, which was the style at the time; and my php.ini did allow GET/POST to inject global variables. Not to mention CVEs discovered between now and then. So I wouldn't want that server from year 2000 to stay running untouched, but win98 is a strawman.
Could have been yours ;)
Just so you know, Windows 2000 is vastly more stable than the 9x branch and is perfectly usable, so you should upgrade.
I think however, that authors point was moot already - your network connected machine can't be static, it shouldn't be in years. There are constantly new RCE's and other exploits since ages. Your network connected machine must be maintained, whether it's a basic web server or your phone.
Why not? Imagine if it's a purpose built webserver on a microcontroller[^1] which only serves strictly static pages or text files.
[^1]: http://tuxgraphics.org/electronics/200611/embedded-webserver...
For instance if I was running a server on an 50 yo IBM framework serving static pages, how many serious attack vectors have been left unpatched at this point ? (ignoring DDOS type of issues where the content is not compromised)
And many/most of them connected to the TSL/HTTPS-stack, due to the complexity it brings.
Of course people would need to be educated on those risks, which would probably be the biggest issue.
Frankly, that's impossible in any reasonable timeframe compared to just not allowing unsafe "huts".
If you don’t keep up the repairs, eventually the roof fails, rain gets in & then it’s a relatively quick slide into total ruin.
> (At the same time this is necessary to keep HTTPS secure, and HTTPS itself is necessary for the usual reasons. But let's not pretend that nothing is being lost in this shift.)
So, to stay within your analogy: He acknowledges the need for new houses, but says that huts had a unique flair which is lost now.