There are unpatched 0-days that go back years that still make WinXP dangerous to have on any sort of network. Not only that, but they will never be fixed. Nor can you fix them yourself (no source code).
And yes, cash registers will be networked because of data mining. I can get an accurate picture of store utilization solely by watching registers. And also by seeing what was purchased, I can change inventory appropriately. So yes, networking is essential. Perhaps it's not for the small business that handles flea markets and such.
Windows XP Embedded is still supported and still gets security patches. I'm also pretty sure you can get the source to it too, if you pay Microsoft and sign an NDA.
Windows XP; the security researchers favorite distro.
There are few things better than showing up to a security review gig and have them running XP. Makes my job super easy and clients love when I rain down bugs. It's even better because we can actually write exploits in a short time frame. Love XP.
Somewhat related, check this out. In the video they theorize that the power line attack is obfuscated by software techniques. An old OS may have buggy USB drivers I can imagine but they claim the OS does not matter.
"0-day" is a vulnerability that's discovered at the same time there are already exploits in the wild. It means you have zero days to get a patch deployed before the target is vulnerable to attack. Obviously a very bad situation to be in.
And yet these days it gets thrown around as if it describes the severity of the vulnerability itself. Thus the above scoffing at "0-days that go back years". What does that mean? It's like saying you have a matinee movie on blue-ray that you'll watch tonight.
I suppose one could have a patched 0-day? It would need to be be fixed by the vendor without them ever acknowledging the underlying issue existed, right?
As for the "go back years" bit, the guy just has some XP vulns that were found ages back and he's never released them, and of course they still work.
So the machine connected to your Windows XP tills has internet access and/or external storage enabled. Of course that's not safe....if I said "not connected to a network" would that be better?
Nope. You just flipped one of your caveats: no internet connectivity.
I only specified networking.
Its also how Target was attacked. Their registers are networked yet there was a hole from the internet to their corporate net. That hole was through their HVAC control system.
The Tl;Dr. Is that you design a secure system, so that if one part fails, the whole system doesn't fall like a house of cards. Security through layers.
You can say that... but I think GP's point is that there's an obvious behavioral pattern to that, which is less data mining of your sales info and customer's buying habits, compared to the sometimes unobvious but major downside of the terminals being hacked. I think we've seem what choices businesses make when presented with the obvious upside over the poorly understood downside.
There are unpatched 0-days that go back years that still make WinXP dangerous to have on any sort of network. Not only that, but they will never be fixed. Nor can you fix them yourself (no source code).
And yes, cash registers will be networked because of data mining. I can get an accurate picture of store utilization solely by watching registers. And also by seeing what was purchased, I can change inventory appropriately. So yes, networking is essential. Perhaps it's not for the small business that handles flea markets and such.