They should be required to provide a secure token-based API. The fact that Mint has to store your bank password in plain text is asking for trouble.
Big Banks Lock Horns with Personal-Finance Web Portals
41–50 of 108 posts
Re: Big Banks Lock Horns with Personal-Finance Web Portals
#42I'm leaving SF to travel around the US for 6-12 months, which means I need to switch off the local credit union that I'm currently using. I may as well choose something that will work for the indefinite future, including whereever I land next (it will be in the US). Any recommendations? I'd prefer an organization that was less culpable for the financial crisis.
Re: Big Banks Lock Horns with Personal-Finance Web Portals
#43They should be required to provide a secure token-based API. The fact that Mint has to store your bank password in plain text is asking for trouble.
Yes, on the "banks should be required to provide a secure, open feed" (though good luck in the one chosen resembling any modern format).
But... securing information of this kind is not rocket science. Sharding secrets into multiple tokens split across minimal service machines, etc. It's just that best practices are so rarely followed.
Re: Big Banks Lock Horns with Personal-Finance Web Portals
#44This is the major difference between the US and EU. In the EU this isn't the "bank's customer data" this is the "customer's data." The customer actually has a legal right to see what data is held about them by the bank, and the bank has a legal obligation to make sure that data is accurate and up to date.
The dumb part is banks are more than willing to support Quicken's Express Web Connect, which literally stores your username/password on Intuit's servers, logs into your online banking portal and downloads the .qfx files you would get if you did it by hand. This is the same company that owns Mint, and it's literally doing the same thing! Oh well, until banks decide to stop allowing users to manually save .qfx files th…
Re: Big Banks Lock Horns with Personal-Finance Web Portals
#45On the second half of the argument. Banks need address the fact that users needs are changing and they want access to their own data, that they own, not the bank. A bank could create an API service with API keys specifically for these types of aggregate services to use. This could be done at first for just read only access, whereby the API does not allow you to transfer funds, etc. It would be a secure interface to access your data from third trusted third parties or your own apps.
A secure standard API would be beneficial to customers, to third party services, and to the banks that offer them. Freeing information inside of hoarding it, when it doesn't belong to them in the first place.
Credit unions could have a major advantage here if they would start using modern tech.
Re: Big Banks Lock Horns with Personal-Finance Web Portals
#46If the banks cared they would provide either token-based API like oAuth or at the very least, a read-only password for users to give these sites that aren't fully credentialed. Customers will always want to extract their data.
Re: Big Banks Lock Horns with Personal-Finance Web Portals
#47Earlier quoted context omitted.
The dumb part is banks are more than willing to support Quicken's Express Web Connect, which literally stores your username/password on Intuit's servers, logs into your online banking portal and downloads the .qfx files you would get if you did it by hand. This is the same company that owns Mint, and it's literally doing the same thing! Oh well, until banks decide to stop allowing users to manually save .qfx files th…
As a (reluctant) Quicken user, I was not aware that Express Web Connect credentials are stored on Quicken servers. Do you have anything to back that assertion up?
Expand the "Express Web Connect / Quicken Connect - Details" section underneath the comparison matrix and you will see this:
* Your login credentials are stored on Intuit-hosted servers. This makes updates faster for you.
* Your financial data is stored on Intuit-hosted servers. This provides a more complete history of your financial transactions than is typical for data stored on financial institution servers.
* We use state-of-the-art security measures to protect your login credentials and your financial data.
----
This is half of why I pay $9.99/mo to use Direct Connect with my Wells Fargo account (that, and having bill pay within Quicken is pretty handy).
Re: Big Banks Lock Horns with Personal-Finance Web Portals
#48Earlier quoted context omitted.
The dumb part is banks are more than willing to support Quicken's Express Web Connect, which literally stores your username/password on Intuit's servers, logs into your online banking portal and downloads the .qfx files you would get if you did it by hand. This is the same company that owns Mint, and it's literally doing the same thing! Oh well, until banks decide to stop allowing users to manually save .qfx files th…
As a (reluctant) Quicken user, I was not aware that Express Web Connect credentials are stored on Quicken servers. Do you have anything to back that assertion up?
When using Express Web connect to automate Web connect downloads from your financial institution's Web site, your user name and password are encrypted and, depending on your financial institution's procedures, will be stored on our firewall-protected servers or in your Quicken software. Your financial information is transmitted using secure socket layer technology and is encrypted, so it is unreadable during transmission. It is then stored on our firewall-protected servers and is securely transmitted directly to your desktop computer when you initiate One Step Update. Your information is confidential and is not used for anything other than providing and maintaining the One Step Update service.
http://quicken.intuit.com/support/help/account-transaction-i...
Re: Big Banks Lock Horns with Personal-Finance Web Portals
#49They should be required to provide a secure token-based API. The fact that Mint has to store your bank password in plain text is asking for trouble.
Why does Mint have to store your bank password in plain text?
Re: Big Banks Lock Horns with Personal-Finance Web Portals
#50I agree with the banks in part. Giving your online account credentials to access your banking information is complete madness. It's a giant security risk that neither company would likely cover if someone got a hold of your login details. This is the reason I purposely never signed up for Mint. On the second half of the argument. Banks need address the fact that users needs are changing and they want access to their…
As someone who collects these daily; I'd rather not collect them. The lengths I have to go to to ensure that they're not a major risk for our product? Significant. It's not a hard problem to solve, but the question is: "do banks want to solve it?" There's not much incentive for big banks to DECREASE account stickiness, and a lot of us waiting for great aggregation tools to totally dis-intermediate the big banks from their customers 8 ways till Tuesday.
But to be honest, financial data is all sort of like this. For example, once someone has your ACH routing and account numbers, the only thing that really stops them from building a fraud factory is the fact that it's difficult to get permission to interact with the ACH network. You need to handle those with at least as much care as bank login info.
And then, there was the MASSIVE fraud spree that everyone who didn't implement yellow path validation for ApplePay opened up. I personally had well over 80k stolen from my account in less than 1 day via that outrageous fraud loop. Thanks, Apple Stores and Chase, for pretending that someone else's fingerprint constitutes my biometric permission.
On the subject of Chase, everyone in the industry was completely shut down without warning at the worst possible time by Chase. We're all pretty spicy about how it was handled.