I don't recommend my friends or family put important information or sign in to any device that is running unmaintained OS software
Because I assume they're exploitable from a security point of view after that point
Of course no one follows that advice but what are we supposed to do?