I think the most impressive part is that apparently the same system and code had been running for 15 years as the number of transactions reported on had increased exponentially
Good point. Just under 5 transactions a day really. I think the point that's really annoyed the sec is the number of years they have to go back and correct now that they have the right data.
i think the bad kind of impressive would be replacing a system that's had thousands of man-years of real world user testing without a really really really critical reason.
I'd have to disagree on that part. The ATMs that the company I work for run Windows. We are the largest manufacturer, until the other 2 big ones finish merging.
Besides, C is 44 years old and used on a ton of stuff.
I took this in the UK two years ago: https://4z2.de/atm_windows.jpg - I don't know enough about how the various versions of Windows look but maybe this helps.
You need to trust the bank's network security more than you trust the ATM itself.
There were some high profile breaches at some retailers in the past couple years that exploited some 0days. How can you defend your POS/ATM against a 0day if the retailer/bank has bad network security practices?
In the US, we have private leased lines to connect with some of the major banks. But the banks most likely use something else to connect to the ATMs.
Most attacks are physically breaking into the cash safe but there were some attacks a couple years ago where people were plugging into the USB port and getting money or something.