That was a bit disconcerting.
Its crazy, but kinda reasonable
A rogue terminal can decide to authorize the transaction with a “signature” (there are legitimate uses for this)
Or even with no PIN at all (there are also legitimate uses for this)
It’s also possible to do either of these 2 things and then report back that the transaction what authorized with a PIN
Most cards aren't like this.
With my UK issued AmEx & Visa cards (both Charge/Credit), at certain places terminal didn't even ask me for a PIN, and the transaction just went through as "Chip & Signature"
Which is kinda pointless since if you are paying and receiving service at the counter - you aren't really receiving a service to tip for.
Checking which corresponds to what card is the hard step because you need access to an acquirer to my knowledge, and you'll lose that access quiet quickly if you attempt too many incorrect combinations.
EMV (the card standard used by all modern chip/contactless cards) supports PINs between 4-12 digits in length.
I’d change mine too except I use the PIN so infrequently (99% contactless now days) I’m worried I’d forget the new one!
Not clear how you would match the pin either without having some personal info on the user which you don't have.
In short, for the kiosk this is a anonymous transaction that was confirmed paid.
The most you could do is ask for more details in the kiosk app which would be clunky and very suspicious.
If you want to get creative with attacks you can, but sometimes comparing a creative attack to a "boring" attack can help frame the conversation.
I've written kiosk apps that landed across the US and while there was a ton of hand wringing about security, and in an informal setting I brought up a simple question:
If you reverse engineer the update process to have it show a penis, or you just carve a penis into the public display with a pocket knife, what's the difference and which is more likely to happen?
Also, vandalism is about the least interesting reason to hack kiosks. It can get you into an otherwise inaccessible network, which often contains all sorts of internal services with loose or no authentication (POS software often uses default creds because "it's on an internal netwok anyways"). Hacked kiosks are also often used as proxy servers for illegal activity and bots in DDoS botnets.
The update process can be backed on the kiosk side, hacking the remote side of the update process is a completely different story.
I mean in some cases that was a simple signed package hosted on an S3 bucket... how are you going to leverage that to vandalize a network of devices?
And the kiosks are never on an interesting network (if they were there's dozens of ethernet ports scattered about the place you can use to get access anyways)
Hacked kiosks being used as proxy servers when you need physical access to hack is also a very uninteresting problem. Why risk tying your physical self to a bot for nefarious usage when there are a million and one other "IoT" devices you can pwn instead?