If McDonalds ever gets hacked, this should come up for possible criminal liability.
If McDonalds ever gets hacked, this should come up for possible criminal liability.
Oh no, the criminals might find out about your disgusting eating habits! The horror!
Seriously though, what kind of damages might you as a customer expect to see from McDonalds kiosks getting hacked?
There are some comments here claiming that their experience with McDonald’s order kiosks in the US makes them feel this is unlikely to be hackable, but “employees regularly leave them unlocked” sure sounds like an invitation for someone to find other hacks.
when the credit card issuer fraudulent credits the charges back to your account, you no longer have any (meaningful) damages.
The "EOL" carping is mostly from the corporate interests; and as the other comments here explain, the actual secret part of the card processing happens on a complete separate machine which is definitely far more secured.
A fully patched copy of XP, with all the group/local policies set to lock it down, is very secure.
In a lot of cases, it may look like XP, but it's actually XP Embedded, which has a lot of stuff stripped out, which reduces the attack surface significantly.
It costs money to upgrade the checkout application for a new OS, and put it through rigorous testing - These things need to work almost 24/7 without crashing or needing admin intervention.
It's the old idiom: If it ain't broke, don't fix it.