One reason is that traditionally any device that accepts PINs for payment cards needs to meet special tamper-proofing requirements. This was a big challenge that Square was working on when I worked there. Here's a thread on SO about it: https://security.stackexchange.com/questions/159118/how-does...