Banks running outdated ATMs to pay Microsoft to support old versions of Windows(chicagotribune.com)
chicagotribune.com
Banks running outdated ATMs to pay Microsoft to support old versions of Windows
http://www.chicagotribune.com/business/sns-rt-us-banks-atms-20140314,0,7225078.story
6 comments
I mean I don't know much about ATM operations but why would you ever base an ATM on Windows? I mean Windows has it's strengths but surely it's quite possibly the most inappropriate operating system to run an ATM.
Probably because Microsoft paid to run Windows through all the necessary certifications to be classified as "safe for monetary transactions" and nobody else did.
So, I suspect that the system designer had a choice of "Windows, and bank the money in 12-18 months" or "Anything else, and spend 12 months and a lot of money possibly getting certified and spend 12-18 months developing".
We call that decision a no-brainer, my friend.
So, I suspect that the system designer had a choice of "Windows, and bank the money in 12-18 months" or "Anything else, and spend 12 months and a lot of money possibly getting certified and spend 12-18 months developing".
We call that decision a no-brainer, my friend.
I think this is one of the major weaknesses of our economies. Should there ever come to be a "hot cyberwar" with one nation-state firing off all they've got against the infrastructure of another, then a lot of the security-by-certification stuff out there will fly in our faces.
You can never be sure you're secure, no matter what a company that you pay a lot of money tells you. Even moreso, considering that in case your certified system blows up, you will probably not get any money in damages, because the certifying company could well go heads up if the attack is wide-spread enough.
You can never be sure you're secure, no matter what a company that you pay a lot of money tells you. Even moreso, considering that in case your certified system blows up, you will probably not get any money in damages, because the certifying company could well go heads up if the attack is wide-spread enough.
Embedded Windows makes it is easy to find experienced programmers (UI & backend) and has very good development tools. You don't have a single program running and can remove services not needed, so it isn't that hard to lock down to make it quite safe.
Additionally, XP Embedded left "mainstream" support in 2011, and has "extended" support until 2016. It was my understanding that nearly all references to "XP" on ATMs referenced XP Embedded, and the sun-setting of support is only for standard XP.
The funny thing is how artificial this distinction is, especially as WEPOS/POSReady forces them to make the patches public. Back when XP SP2 went out of support, they posted the exact same patches Custom Support customers was supposed to pay for (because of WEPOS SP2): http://www.microsoft.com/en-us/download/details.aspx?id=2440... http://blog.securityactive.co.uk/2010/08/10/patching-windows...
"Windows XP currently supports around 95 percent of the world's ATMs."
Sweet fancy moses. Shameless plug: if you want to do something about the state of tech in the financial industry, join us - https://jobs.lever.co/standardtreasury.
Sweet fancy moses. Shameless plug: if you want to do something about the state of tech in the financial industry, join us - https://jobs.lever.co/standardtreasury.
This shouldn't surprise anyone in the industry. It is more the norm that certain segments of software need to last a long time. This is one of the arguments that we need to switch to a 64-bit time in embedded systems now since the embedded systems being deployed today will probably be still in use in 2038.
Why would you run a desktop OS on an ATM?! Heck, if you must use XP, why not XP Embedded? I don't get it.
My bank made the switch. The new OS is notably slower.
"<BigCorp> running outdated <some_software> to pay <BigVendor> to support old versions..." And this will apply to a lot of the Big Cos. Lot.
It is painful, bureaucratic and an absolute nightmare to change things at this level. But to be fair to big companies, change is not always easy and the cost of making an "incorrect" change can be very expensive and further more expensive to rollback.
I work for a very big I-bank and most of the projects I am involved with are multi-year. They take 1+ year to implement and pretty much most of the times, we hardly have solid rollback plan. Yes, I said it. It is more like "we have to put this in production after this many years and this much dollars spent. Let's roll this shit out and we will have a SWAT team ready to handle any fallouts"