I think Microsoft has a better approach for Windows. They deliver regular updates for N years, but security updates for a lot longer. I agree it's fine not to deliver regular updates after EOL, but for critical security vulnerabilities, I think they could do a lot better than just 5 years.
After all, it's not exactly environmentally friendly for working hardware to get ditched just because of some software turns it useless.