Live data from Hacker News

Big Banks Lock Horns with Personal-Finance Web Portals

on.wsj.com

51–60 of 108 posts

Re: Big Banks Lock Horns with Personal-Finance Web Portals

#51
post #44

Earlier quoted context omitted.

As a (reluctant) Quicken user, I was not aware that Express Web Connect credentials are stored on Quicken servers. Do you have anything to back that assertion up?

From Quicken's security guide (emphasis added): When using Express Web connect to automate Web connect downloads from your financial institution's Web site, your user name and password are encrypted and, depending on your financial institution's procedures, will be stored on our firewall-protected servers or in your Quicken software. Your financial information is transmitted using secure socket layer technology and i…

Yes. They store your credentials at rest in a data store, and the creds are decrypted on demand when API requests are made.

Re: Big Banks Lock Horns with Personal-Finance Web Portals

#52
I used Mint for a long time, but eventually decided I didn't like them having all my bank login information, including security questions. So I switched to a setup where I download OFX data directly from my banks using a Python script [1], and use Ledger [2] to track spending, balances, etc.

A big bonus of this approach is that I have complete control over the data, so if an import get screwed up somehow I can fix it manually. Mint's "black box" approach is good when everything works flawlessly, but you're stuck doing weird hacks if anything goes wrong or you want to do something it wasn't designed for.

Ledger, incidentally, is from the same one who is now maintaining Emacs, if I'm not mistaken.

[1] http://captin411.github.io/ofxclient/ [2] http://www.ledger-cli.org

Re: Big Banks Lock Horns with Personal-Finance Web Portals

#53
post #6

This is the major difference between the US and EU. In the EU this isn't the "bank's customer data" this is the "customer's data." The customer actually has a legal right to see what data is held about them by the bank, and the bank has a legal obligation to make sure that data is accurate and up to date.

In the US they also have a fiduciary requirement to protect your money to the best of their ability. I appreciate that some of the larger banks might actually consider the impact of a data breach at an aggregator but reading this a couple of times it really sounds like a whine that they feel they have to provision more capacity for both their user base + the load put on by the aggregators their user base is using. Th…

> I appreciate that some of the larger banks might actually consider the impact of a data breach at an aggregator but reading this a couple of times it really sounds like a whine that they feel they have to provision more capacity for both their user base + the load put on by the aggregators their user base is using. They don't have a way to charge the aggregator for their use like they do the customer.

They absolutely charge their aggregators. Most of the aggregators can't screenscrape without permission of the aggregators. Why on earth would you think they can't? Why do you think Mint doesn't need to do MFA for so many banks and can just get away with a user-pass challenge?

This is about holding control of their customer base, plain and simple. They know everyone else, even other banks, are eager to dis-intermediate their customer base. They're spending too much money maintaining branches and offering inferior savings products to compete digitally, so they would rather delay that as long as possible.

Re: Big Banks Lock Horns with Personal-Finance Web Portals

#54
post #6

This is the major difference between the US and EU. In the EU this isn't the "bank's customer data" this is the "customer's data." The customer actually has a legal right to see what data is held about them by the bank, and the bank has a legal obligation to make sure that data is accurate and up to date.

In the US they also have a fiduciary requirement to protect your money to the best of their ability. I appreciate that some of the larger banks might actually consider the impact of a data breach at an aggregator but reading this a couple of times it really sounds like a whine that they feel they have to provision more capacity for both their user base + the load put on by the aggregators their user base is using. Th…

[deleted]

Re: Big Banks Lock Horns with Personal-Finance Web Portals

#55

I must be a bit odd. I prefer to manually enter all my transactions in my journal. I don't want it automated. Any time I've automated it, I have become complacent. I feel, in order to properly manage my finances, there must be some pain. Don't get me wrong, I use SW. I just don't use SW that is automated.

I think you're right and that there should be some pain. My version of this is taking a full list of transactions and tagging them individually from electronic exports. This way any expense isn't reconciled until it's tagged. This can be done mostly automatically but some are unrecognized/unique expenses. The unrecognized are the ones that probably matter the most in terms of managing my finances, dinning out, random items from amazon, etc. I have to review and recognize everything which makes me monitor the most important aspects where I might have spent my money poorly.

Re: Big Banks Lock Horns with Personal-Finance Web Portals

#56

I used Mint for a long time, but eventually decided I didn't like them having all my bank login information, including security questions. So I switched to a setup where I download OFX data directly from my banks using a Python script [1], and use Ledger [2] to track spending, balances, etc. A big bonus of this approach is that I have complete control over the data, so if an import get screwed up somehow I can fix it…

The advantage I see Mint has is they don't require OFX as they appear willing to scrape sites for content.

Re: Big Banks Lock Horns with Personal-Finance Web Portals

#57

I agree with the banks in part. Giving your online account credentials to access your banking information is complete madness. It's a giant security risk that neither company would likely cover if someone got a hold of your login details. This is the reason I purposely never signed up for Mint. On the second half of the argument. Banks need address the fact that users needs are changing and they want access to their…

> On the second half of the argument. Banks need address the fact that users needs are changing and they want access to their own data, that they own, not the bank. A bank could create an API service with API keys specifically for these types of aggregate services to use. This could be done at first for just read only access, whereby the API does not allow you to transfer funds, etc. It would be a secure interface to access your data from third trusted third parties or your own apps.

My capital one 360 account does this. I can generate an api key that I give to mint.

Re: Big Banks Lock Horns with Personal-Finance Web Portals

#58

I used Mint for a long time, but eventually decided I didn't like them having all my bank login information, including security questions. So I switched to a setup where I download OFX data directly from my banks using a Python script [1], and use Ledger [2] to track spending, balances, etc. A big bonus of this approach is that I have complete control over the data, so if an import get screwed up somehow I can fix it…

I have a very similar setup, except using YNAB[0]. I never felt like I really used Mint, besides just going and looking at my balances and (infrequently) thinking, "huh, looks like I'm over-budget again". With this setup, I feel like I'm taking matters into my own hands, which has had a noticeable impact on my spending and planning discipline.

Thanks for the link to your project, looks really useful!

[0]: https://www.youneedabudget.com/

Re: Big Banks Lock Horns with Personal-Finance Web Portals

#59
post #35
post #3

If the banks cared they would provide either token-based API like oAuth or at the very least, a read-only password for users to give these sites that aren't fully credentialed. Customers will always want to extract their data.

Mine (US) bank does just that.

Which bank?

Re: Big Banks Lock Horns with Personal-Finance Web Portals

#60
post #44
post #11

Earlier quoted context omitted.

The dumb part is banks are more than willing to support Quicken's Express Web Connect, which literally stores your username/password on Intuit's servers, logs into your online banking portal and downloads the .qfx files you would get if you did it by hand. This is the same company that owns Mint, and it's literally doing the same thing! Oh well, until banks decide to stop allowing users to manually save .qfx files th…

As a (reluctant) Quicken user, I was not aware that Express Web Connect credentials are stored on Quicken servers. Do you have anything to back that assertion up?

This is (probably) not global. Some financial institutions will offer aggregators safer ways of keeping a negotiated connection around. Like most big aggregators, Intuit negotiates with all the major banks individually for both batch and realtime refreshes.

The entire world of aggregation is simultaneously really interesting and rock-boring stupid. I'm surprised we don't see more fintech startups using it more aggressively, even as I am happy this made my former endeavor more acquirable.

Post reply on HN