YinkoShield

knowledge center / theme 04

pos, mpos, and sst runtime threats

Different surface area — different regulator, different runtime.

POS terminals, Android-based mPOS, and self-service Linux kiosks share a payments role with mobile but operate in a distinct attack surface and a distinct regulatory frame — PCI PTS for fixed-function terminals, PCI MPoC for SoftPOS / mPOS, country-specific certification for SST. Each article documents an attack class, the syscalls and OS surfaces it touches, the certification regime that defines the boundaries, and the signed Evidence Token shape produced when the substrate sees the technique.

5 articles · technical reference · cite as published

five attack classes · surface · regulator · entry

Each row maps an attack class to the device class it operates on and the certification regime that defines the boundary — PCI PTS, PCI MPoC, scheme terminal certifications, country SST regulations.

# attack surface regulator / regime
01 POS terminal tampering — physical and firmware attack surface fixed-function terminal PCI PTS
02 Side-loaded applications on Android-based mPOS Android mPOS / SoftPOS PCI MPoC
03 OS downgrade attacks on payment terminals terminal firmware PCI PTS / scheme cert
04 Kiosk-shell escape on Linux self-service terminals Linux SST / branch kiosk country-specific SST cert
05 Attestation drift across distributed terminal fleets fleet operations scheme estate-management