The MTA Seeks Compliance on Their Antique Vending Machines
|
At the time I posted my recent blog about finding a New York City Transit MetroCard vending machine running Windows NT 4 Service Pack 3 I contacted the MTA (Metropolitan Transit Authority) to ask them about it. I received a response from Paul Fleuranges, vice president of Corporate Communications, MTA NYC Transit: Assuring the security of the MetroCard system is a multi-layered effort So we'll have to take their word for it that it's impossible for anyone to hack into their machines. If the machines were actually on a network of some kind I would be worried, but it's likely they all just have a dial-up connection and some weird, old version of SLIP. The reference to PCI compliance is interesting. Seeing as how Requirement 6 of the PCI DSS states that you must "Ensure that all system components and software have the latest vendor-supplied security patches installed. Install relevant security patches within one month of release" I would think they can't possibly be compliant running NT 4 SP3, and that they must have a goal of upgrading these systems. That's good news. |
