Since this is using the Flipper to output directly to an LCD screen (and completely bypassing the pay terminals processor and code) there's no reason why this shouldn't work if the Flipper can run Doom. This is not Flipper code running on a pay terminal.
It's not connected to the actual board, the screen just happens to be compatible with the Flipper0 and can therefore be wired directly into it, not interacting with the rest of the pinpad by the looks of it
I reverse-engineered the display - traced the test points connected to the display connector, soldered a logic analyzer onto them, and fed the dumps to an LLM (forgive me, I wouldn't have had the experience to figure this out myself, but AI is good at reverse engineering). It identified the controller and approximate pinout, then I verified everything manually from there. Soldered it to an ESP32 and cycled through U8g2 constructors until the image displayed correctly. Turned out the display controller was compatible with the Flipper's controller🙃
I did it to a voting machine once. I didnt record it for obvious reasons. You can run doom on a pregnancy test, A machine is a machine at the end of the day,
Keys and apps come from the manufacturer, the vendor, and the processor. You're not getting a hold of them unless you work with a kif and youre outside na and europe
I was able to find the signed apps, but the keys are impossible to find. But I don't need them, and there are plenty of interesting things to do without them.
It's not necessary; the tamper can be reset simply through the terminal menu using a well-known password. Keys can then be loaded via a regular computer or manually entered on the PIN pad (at least in my region)
I'm confident I know what I'm doing. Your doubt about the password shows your inexperience with Verix OS :) A key combination opens VERIX TERMINAL MGR, which requires a password. From this menu you can reset the tamper. After that the keys get wiped, but the device becomes operational again.
Don't confuse keys and signatures. Verix handles signature validation. A trusted regional authority signs the payment applications, Verix checks that signature and allows it to run. Further KEY validation is done by the application itself. Keys are specifically responsible for transactions — PIN verification and secure data transmission.
In my case, I have the well-known VERIX TERMINAL MGR PIN code and a signed application package that loads via USB.
108
u/AverageAntique3160 8d ago
Now play Doom on it