I think the real question is “what is the physical security model of the OS/2?”
I would imagine a determined attacker could infiltrate the system in-person. The question then becomes - how easy is it to compromise the system given physical access? And, assuming total compromise, how much damage and loss of life can be caused? (Do the subways have physical fail-safes?)
Cameras, locks, and obfuscation, basically. Ti hack it, you need to be alone with it long enough to find the flaws, figure out how dispensor works, etc. People hardly ever try to bypass them.
Recently, hackers have been buying, studying, and hacking ATM's. They're not secure. You can see them in action searching for DEFCON ATM hacking on YouTube.
I would imagine a determined attacker could infiltrate the system in-person. The question then becomes - how easy is it to compromise the system given physical access? And, assuming total compromise, how much damage and loss of life can be caused? (Do the subways have physical fail-safes?)