Well, let's just say it's an architecture Square knows well. :)
[0] http://www.s3.eurecom.fr/tools/avatar/
[1] https://www.usenix.org/conference/usenixsecurity13/technical...
Their first credit card readers were entirely analog devices, which were very easy to use to skim cards.
Hopefully the latest batches have per-device unique keys (based on some centrally-known KDF) so a compromise of one doesn't re-enable such an exploit.
Yes, that's how it works.