2026-06-30
Link: https://archive.org/details/lidl-sco
HN Discussion: 1 points, 0 comments
Someone uploaded a full SSD image of a Lidl self-checkout terminal — running GK Retail's point-of-sale stack — to the Internet Archive. That is the kind of artifact that almost never surfaces publicly. Retail POS software is a strange, expensive, NDA-fenced corner of enterprise computing: GK Software (now part of Fujitsu) powers checkouts for Lidl, Aldi Nord, Walmart, Hornbach, and a long tail of European grocers, but you will not find their binaries on any package mirror.
What likely sits inside an image like this is a goldmine for a specific kind of researcher:
For a security-minded audience the appeal is obvious. Self-checkout machines are physically accessible computers handling payment data; their threat model is interesting precisely because the adversary can stand in front of them with a screwdriver. Anyone who has ever watched a self-checkout drop to a Windows desktop or shown a barcode that crashed the till has wondered what is actually running under the hood. Now you can look.
For the reverse-engineering crowd, this is the same flavor of artifact as the leaked McDonald's kiosk images or the various ATM firmware dumps that occasionally surface — a chance to study production enterprise software that is otherwise gated behind seven-figure licensing deals. Expect writeups on hardcoded credentials, debug interfaces left enabled, the kiosk-escape tricks store staff actually use, and the protocols between terminal and store server.
The legal status is murky — this is almost certainly copyrighted proprietary code — so the upload may not stay up long. Worth grabbing a hash and a look while it's there, if only to understand what is running every time you scan a bag of apples.
