Can anyone familiar with CC processing provide insight on whether that's a reasonable explanation?
Regardless, a problem that requires a "software fix" from the vendor and manual visitations to each individual machine doesn't sound like a mere "setting"
1. Allow customers to download updates and flash over USB.
2. Boot device into a limited mode that allows signed updates. Certificate should be stored in secure memory.
I.e. low wage, minimal training, not technically proficient users with unsupervised physical access to the machine
A machine through which a large amount of cash (virtual or otherwise) flows.
The criteria of (a) being updatable by a semi-technical customer & (b) being secure against technically malicious or socially engineered ignorance attacks seem challenging to simultaneously satisfy.
It is not.