Saturday, April 19, 2014

XP Used in the Restaurants/Stores/Healthcare, etc Near You

XP support ended April 8.  Many (How many?  Don't know!) businesses, restaurants, health providers, ATMs:  any device used to process your transactions are still on XP.  (background)There are some things these enterprises can do to mitigate risk, but I wouldn't trust any of them.  You think you don't know all you need to know about security!  The conditions where you should be concerned are:

  1. XP is used somewhere in the path of a transaction (even if the clerk is recording your phone number or swiping your loyalty card) AND
  2. The information has a direct path, even through a firewall, to the outside, or the terminal and business do not protect against insertion of a usb flash drive in the XP computer.
 I'm not sure asking a clerk if XP is involved in any way in your transactions will result in an informed response.

I read this over and I say to myself, I guess many of my electronic transactions are at risk.  So, what to do?  Go all eTransactions?  Heartbleed anyone?  Truth is that us, as consumers, are at significant risk for the next several months.  Reading suggestions from other blogs, I think the prudent approach is to "profile":

  • Use cash in especially sensitive stores, such as independent gas stations and corner stores (I've also seen XP still in use in medical facilities, which may or may not be a problem.)
  • Do NOT use a debit card unless you are confident the store or ATM has all made the change over AND has mitigated against the Heartbleed defect.
  • Consider using "single use credit cards on line"  Google "single use credit card" to see who offers these and the terms of use
  • Your credit card should have a limit of $50 for unauthorized use and some companies will cancel any charges where "confirmed" fraud is involved.  So use a credit card if you can't use cash.
If all this sounds wishy-washy, it is.  There isn't a list of businesses that have removed XP from their data stream and business; or visa-versa.  Trust is not a virtue right now.

No comments:

Post a Comment

Printfriendly

Print Friendly and PDF