They don’t mean websec, they mean textsec. The old site doesn’t have the level of text scraper defenses that the new site does, without which Reddit can’t monetize the written output of their userbase for AI training. Putting old behind a login wall solves that.
Having previously recommended on HN that blogs put up a simple basicauth that takes any password to stop AI theft dead in its tracks, I definitely agree with their reasoning; if nothing else, it’ll result in an honest accounting of users left using it.