Hacker News new | ask | show | jobs
by ak47-1984 3068 days ago
As one of the engineers initially responsible for achieving PCI compliance on these ATMs, this isn’t strictly true - of course it needs to know your account info, but it’s sent to your bank - it’s not stored on the machine at all - certain digits of your card number are written to a paper log but it’s never written in full - can’t speak for POS machines, but would imagine it’s the same
1 comments

Unfortunately, POS is not the same. I’ve worked with NCR (Aloha) POS for 5 years. Can’t speak for ATM machines.

Plain text ... and before two years ago, they also had regional master passwords. As in one password for all systems sold by a particular reseller.