Even as someone who enjoys "retro tech" far more than anything modern anymore, I'm hardly going to berate people to bend over backwards to keep supporting my ancient systems with modern software.
If someone wants to backport newer software as a hobby (such as Cameron Kaiser with TenFourFox, and the many downstream derivatives that spawned over the years) it's a welcome delight. But it should never be an "obligation"
Those "security reasons" start more and more to look like "think of the children". The biggest entry point for exploits nowadays is the web browser, yet nobody cares about it (just look at the list of CVEs fixed at every browser release).
Some developers seem proud doing that, somehow feeling that extra 5-10 lines of code for backwards compatibility is too much.