Stories
Slash Boxes
Comments

SoylentNews is people

posted by janrinok on Monday June 25 2018, @02:05PM   Printer-friendly
from the about-time-too dept.

The Reserve Bank of India has given that country's banking sector a hard deadline to get Windows XP out of its ATMs: June 2019. That's more than five years beyond the May 2014 end of support for the OS.

In a notice to the nation's banks, issued last on June 21st, 2018, the Reserve Bank makes it clear that XP “and other unsupported operating systems” have been on its mind since at least April 2017, when it issued a circular outlining its concerns.

In spite of previous advisories instructing banks to put migration plans in place, things have not moved fast enough for the RBI.

“The slow progress on the part of the banks in addressing these issues has been viewed seriously by the RBI,” the notice said, adding that "the vulnerability arising from the banks’ ATMs operating on unsupported version of operating system and non-implementation of other security measures, could potentially affect the interests of the banks’ customers adversely".

The timetable says banks must reach 25 per cent deprecation by September 2018; 50 per cent by December 2018; and 75 per cent by March 2019.

The timetable also requires banks to implement anti-skimming technology, and to use whitelisting on ATMs so only approved software can run on them. Banks have been instructed to file their compliance plans by the end of July 2018.

[Editor's Note: Removed spurious line 1432UTC]


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by SomeGuy on Monday June 25 2018, @02:21PM (4 children)

    by SomeGuy (5632) on Monday June 25 2018, @02:21PM (#698129)

    Are we sure we aren't talking about about the Point of Sale version, which if I recall correctly is supported until 2019?

    Nothing really wrong with that, although they probably should consider some other OS that is better geared towares embedded environments.

    I'll also throw in that if if they are using the OS as the one and only line of defense, then they are doing something horribly retardedly wrong and stupid. I suppose they want to connect their ATMs to the public unfiltered WiFi so they can browse the web on it or some shit.

    If their communications are properly secured then it really shouldn't matter a hill of beans what old OS they are using other than the lack of support contracts.

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 4, Interesting) by RS3 on Monday June 25 2018, @04:18PM

    by RS3 (6367) on Monday June 25 2018, @04:18PM (#698176)

    I'm quietly proud to say I still run many XP machines and just got 4 new critical security patches 2 days ago. They're dated June 6, I'm not sure what exact date MS released them. XP (POSReady) is actively updated, like you said, and reportedly until 2019 sometime, and MS may push it longer.

    And yes, it's the same codebase MS used for "embedded" Windows for years. I'm not sure of all of the markets using "embedded" Windows, but I know in A/V land many (most?) mixing boards, lighting controllers, and video capture / editing / switching systems run on Windows embedded. Newer embedded systems are running a Win7 codebase.

  • (Score: 2) by edIII on Monday June 25 2018, @07:47PM (2 children)

    by edIII (791) on Monday June 25 2018, @07:47PM (#698328)

    Was wondering about that. A recent trip to the grocery store showed me they were still using XP PoS. Watched it for about 10 minutes boot. Fairly impressive actually, and the 3rd party programs on it were contacting a central server and updating software while I watched. Interestingly enough, watching it for about 10 minutes also showed me an exploit against the store. Not an easy one, but it did make it possible to get 50% off any item in the store.

    --
    Technically, lunchtime is at any moment. It's just a wave function.
    • (Score: 2) by Nuke on Tuesday June 26 2018, @01:09PM (1 child)

      by Nuke (3162) on Tuesday June 26 2018, @01:09PM (#698720)

      Was it you doing the exploit?

      • (Score: 3, Interesting) by edIII on Tuesday June 26 2018, @06:45PM

        by edIII (791) on Tuesday June 26 2018, @06:45PM (#698908)

        Absolutely not. That's black hat type shit, and I'm white hat. I would do it if the hired me for some pen testing though.

        --
        Technically, lunchtime is at any moment. It's just a wave function.