August 10, 2026 CKF_OS_LOCKING_OK asks a PKCS#11 library to make itself thread-safe. The standard says a library that cannot must refuse. Measured on a current commercial provider: two threads calling C_Initialize kill the process, twenty times out of twenty.
August 9, 2026 Configuration baselines prescribe exact settings, which is what makes them useful and what makes them collide with a machine that has no network at sign-in. The RHEL 9 STIG requires certificate-based smart card login and, in the same breath, requires OCSP to check the certificate.
August 9, 2026 ISO states each control as an outcome with a purpose rather than a prescribed mechanism, so an unattended device never collides with it head-on the way it does with a prescriptive standard. The difficulty moves to producing evidence an auditor can accept from a machine with no connectivity.
August 9, 2026 AAL3 is the level people reach for when they mean 'serious'. Read against an unattended device, part of it fits exactly, part is inapplicable because there is no remote verifier to attack, and one requirement is simply not met unless the hardware is chosen for it.
August 9, 2026 Several Requirement 8 controls assume a reachable server. On an unattended device some of them cannot be implemented literally — but PCI DSS 4.0 states an objective for each one, and the customized approach is the route to meeting it.
August 9, 2026 Jackpotting is the story vendors tell about ATM security. The European industry figures for 2025 record one logical attack and no losses from it, while explosive attacks took €13.5 million. Worth knowing before buying anything to prevent the wrong thing.
August 9, 2026 SP 800-207 places the policy engine and policy administrator at the centre of the architecture. Read closely, the document treats their unreachability as an outage to be engineered away — not as a normal operating condition, which is what it is for an unattended device.
August 7, 2026 How Zero Trust principles map onto the layers of a Linux estate — network, service-to-service, human sign-in to a host, privileges inside the OS. What each layer covers, where it runs out, and what to do about devices with no permanent connectivity.
July 28, 2026 How PCI DSS 4.0 authentication and account requirements apply to ATM fleets — and what passwordless, certificate-based sign-in changes: MFA, password rotation, shared accounts.