1) is not connected to the internet
2) you can't add external storage
I see people getting upset all the time about cashier tills running windows xp - but that doesn't make any sense. If the software works fine in that situation then it could be just as well running windows 3.11 and I don't see a problem.
There are unpatched 0-days that go back years that still make WinXP dangerous to have on any sort of network. Not only that, but they will never be fixed. Nor can you fix them yourself (no source code).
And yes, cash registers will be networked because of data mining. I can get an accurate picture of store utilization solely by watching registers. And also by seeing what was purchased, I can change inventory appropriately. So yes, networking is essential. Perhaps it's not for the small business that handles flea markets and such.
I only specified networking.
Its also how Target was attacked. Their registers are networked yet there was a hole from the internet to their corporate net. That hole was through their HVAC control system.
The Tl;Dr. Is that you design a secure system, so that if one part fails, the whole system doesn't fall like a house of cards. Security through layers.
There are few things better than showing up to a security review gig and have them running XP. Makes my job super easy and clients love when I rain down bugs. It's even better because we can actually write exploits in a short time frame. Love XP.
https://www.youtube.com/watch?v=mdnHHNeesPE and this https://www.youtube.com/watch?v=HxQUKAjq-7w
does not compute....
"0-day" is a vulnerability that's discovered at the same time there are already exploits in the wild. It means you have zero days to get a patch deployed before the target is vulnerable to attack. Obviously a very bad situation to be in.
And yet these days it gets thrown around as if it describes the severity of the vulnerability itself. Thus the above scoffing at "0-days that go back years". What does that mean? It's like saying you have a matinee movie on blue-ray that you'll watch tonight.
I suppose one could have a patched 0-day? It would need to be be fixed by the vendor without them ever acknowledging the underlying issue existed, right?
As for the "go back years" bit, the guy just has some XP vulns that were found ages back and he's never released them, and of course they still work.
(Having worked somewhere close to the field of XP-for-POS, the answer appears to be that the customers really do not like having to do updates. They'd much rather just firewall the tills and hope they don't suffer a stuxnet. They're attacked surprisingly rarely because you can't steal money over the internet this way.)
For instance, the USB port could be on a daughter board, and requires you to enter a password on the plugged in keyboard before the daughter board would complete the connection to the main motherboard.
The really simple method would be to at least have a USB Lock that plugs into the USB port, and once locked it hooks into a USB port and if physically ripped out without unlocking, it would rip out the USB port with it. This is something they can retrofit quickly while figuring out other problems with their software problems.
We then allowed them to be re-enabled selectively based on a challenge-response touch screen input (didn't require connectivity, just pre-shared keys to verify the response) or via our server (if connectivity was stable and the touch screen had an issue).
Assuming you have a team competent enough to build a platform that you can at minimum reboot and ensure it'll always come back up, you'd never, ever want to automatically let someone access your system.
Having a usb outside is invitation to do something with it.
What a stupid vulnerability.