[ The Symptom
"We manage a regional retail chain and recently upgraded to modern, Android-based touch-screen checkout registers. In the past week, several of our customers complained that their cards were compromised immediately after shopping at our stores, but our security audits show our card reader chip-readers are fully encrypted and intact.".
[ The Reality & Truth
The Layman's Reality
Hackers managed to break into the Android tablet running your register's screen and painted an invisible "fake" PIN pad over the top, stealing your customers' secret codes before they ever reached your secure payment chip.
The Technical Truth
Standard point-of-sale registers run custom Android Open Source Project (AOSP) builds. If an attacker accesses the primary application board's operating system, they can inject an unauthorized visual overlay script over the WebGL UI, harvesting cardholder PINs at the glass before the inputs reach the secure coprocessor.
[ The VALZOX Intercept
We deploy TSK-106-09 (AOSP ROM Active Defenses & Code-Signing). The proprietary security architecture enforces cryptographic code-signing on all web elements and layout files. The local NXP Kinetis host microcontroller runs daily cryptographic boot-state validations; if any unauthorized DOM-level write or script injection is detected in the browser view, the microcontroller instantly cuts off communication to the primary application board, protecting customer PINs and rendering the attack void.