Live data from Hacker News

Bank of America Cut Off Finance Sites from Its Data

nasdaq.com

31–40 of 61 posts

Re: Bank of America Cut Off Finance Sites from Its Data

#31
post #4

I don't use the aggregators because I want to, and they don't use my passwords and screen scrape because they want to. I just can't have being aware of my finances take all fucking day. I wish there was a standard and secure format and protocol for collecting balances and transactions built into the FDIC or NCUA rules or something.

Yeah, I know which one I'd give up first.

Re: Bank of America Cut Off Finance Sites from Its Data

#32
Banks have been purposefully limiting customers' view of electronic data for years, first by eliminating running balances about 10 years ago and then by limiting online data to 90 days. They do this because confused customers are more likely to pay fees such as overdraft fees, which is where retail banks make most of their money.

Mint complied with the banks' demand to not display running balances but they do display data going back indefinitely in time.

What Mint has shown the banks is how valuable the data is to advertisers. The data is so valuable that Intuit is shutting down their popular $50/year semi-subscription Quicken software in favor of advertising to people via Mint.

In an ideal world a government regulator would step in and ensure data access and privacy. But we do not live in a very ideal world.

Re: Bank of America Cut Off Finance Sites from Its Data

#36

We're on Wells Fargo who are also doing this. Does anyone have an alternative banking solution? We aren't eligible for USAA. I'd love to keep local free ATM withdrawals, and I have no idea how depositing cash works for online only financial services.

In the case of my online only bank, you just can't deposit cash. This is only a small nuisance for me, though, as the only instance I receive cash anymore is when selling things on Craigslist.

Re: Bank of America Cut Off Finance Sites from Its Data

#37
post #14
post #10

Earlier quoted context omitted.

That's what these "finance sites" already do. That's why you have to enter your bank username and password to use them - they just scrape the website. Incidentally, I have never used one, because that requirement is completely insane.

I think the point was so that the banks couldn't block access via ip address. Each person would be able to aggregate their bank info on their home computer or they could secure their own server to do it for them constantly.

Not my area of expertise, but isn't it fairly trivial to circumvent an IP address block, (given a willingness to devote some resources to it)?

Re: Bank of America Cut Off Finance Sites from Its Data

#38

We're on Wells Fargo who are also doing this. Does anyone have an alternative banking solution? We aren't eligible for USAA. I'd love to keep local free ATM withdrawals, and I have no idea how depositing cash works for online only financial services.

EDIT: This is all wrong: I think USAA checking and other financial services are open to most people now, not just military and relatives of current members. Insurance and perhaps retirement accounts, I think, are all that are still restricted.

This either used to be true and its switched back, or they were discussing it and decided not to implement it. Sorry for the mistake.

Also, yeah, as my sibling reply says, you can't deposit cash easily. I think you can technically mail it, but I would never do that. I used to get paid rent by a roommate in cash, it was a few hundred a month. I'd just pay for my meals and groceries with it instead of depositing it.

Re: Bank of America Cut Off Finance Sites from Its Data

#39
post #25
post #10

Earlier quoted context omitted.

That's what these "finance sites" already do. That's why you have to enter your bank username and password to use them - they just scrape the website. Incidentally, I have never used one, because that requirement is completely insane.

Why is that insane? It's inelegant, but it's not functionally different than having an API and a system for registering API keys. Either you trust the aggregator or you don't; if you don't you shouldn't give them access to your data either way. If they do something they shouldn't with your data, they'll be ruined if it becomes public. (Of course there's a huge gray area of things they could do that you wouldn't like,…

> Why is that insane? It's inelegant, but it's not functionally different than having an API and a system for registering API keys.

Because there is such thing as a read-only API. But logging into the banking site as a customer permits the aggregator to take actions as the customer, like wire transfers--which are not reversible, and not typically covered by fraud protection.

Sure, I might trust Mint not to do that, but what if Mint gets hacked? By definition, Mint can access my bank creds in plain text, since it must paste them into my bank's website. That is worse security than even my own bank's website, which undoubtedly stores only the hash of my password.

My bank is not going to indemnify me for fraud caused by Mint's security problems. Bank agreements usually say "don't share your account creds," so if you do, and then lose your money, the bank is not likely to make you whole.

Post reply on HN