Live data from Hacker News

Teller – API for your bank account

blog.teller.io

101–110 of 282 posts

Re: Teller – API for your bank account

#101

Earlier quoted context omitted.

I believe this is true for most US banks also. I can't even count how many promising-looking Fintech products I had to pass over because the only auth mechanism they offered was through sharing online banking credentials. Until bank policies regarding credentials-sharing actually change, I think it's really irresponsible for products to even ask for credentials at all, let alone offer it as the default/only auth opti…

Users could be unwittingly putting their entire life savings at risk. Is this a realistic concern? I thought the point of a bank was that situations like that can be reversed 100% of the time.

In this particular case, yes, because banks tend to deny all liability for fraudulent transactions that result from credentials sharing, so the user is entirely liable for whatever loss that occurs.

Re: Teller – API for your bank account

#102

Earlier quoted context omitted.

I believe this is true for most US banks also. I can't even count how many promising-looking Fintech products I had to pass over because the only auth mechanism they offered was through sharing online banking credentials. Until bank policies regarding credentials-sharing actually change, I think it's really irresponsible for products to even ask for credentials at all, let alone offer it as the default/only auth opti…

Users could be unwittingly putting their entire life savings at risk. Is this a realistic concern? I thought the point of a bank was that situations like that can be reversed 100% of the time.

That reversal is not instantaneous, and by no means is it a guarantee that you'll ever get the whole amount back when overdraft fees, third-party bounced check fees, and all of the other non-monetary impacts are taken into account.

Depending on the scope of your accounts with the financial company that you're banking with it's possible that beyond your day-to-day operating funds and your mid-term savings accounts that you may also have access to your investments and other long-term stores of value. They aren't as liquid, and it would be harder for a thief to shift them into something that can be transferred out of your account, but it certainly is possible for it to happen if sales of stocks/bonds/etc. are conducted without your knowledge and then the funds are wired out.

Re: Teller – API for your bank account

#104
There already exists a company called Teller in Europe which is dealing with payment solutions.

> Nets is split up in two divisions: Nets, which manages the Danish market, and Teller, which handles all international markets. This means that Nets processes all Dankort transactions, while Teller processes all transactions by international cards.

http://www.epay.eu/acquirer-internet/nets-teller.asp

https://www.nets.eu/en/payments/

http://netseu.23video.com/secret/12342399/64f0568391b3ebaa58...

https://my.teller.com/login

Re: Teller – API for your bank account

#105

UK banks don't accept any liability if you give your online banking credentials to a third party. If some fraud was to come about as a result of someone using Teller then they would be out of pocket or has Teller got agreements with the compatible banks to overcome this situation (either by Teller reimbursing the customer or the bank)?

Hi, Firstly, we don't always need a credential. Some banks provide other auth mechanisms, e.g. EMV CAP. We use this for Barclays and Nationwide. Using Teller might not violate your bank's terms of service, which is why we advise you to read them in conjunction with ours. Furthermore, it is the view of some senior bank people that I speak to that PSD2 will make such clauses in banking terms illegal. It is also worth m…

It sounds to me like you added a lot of detail around a core message of "yes, you may be violating your bank's ToS by using our service, please verify this by reading through page upon page of legalese in your spare time."

Well... no thanks. I (and likely many others) would only consider using such a service if I had a guarantee, both from you and my bank, up front.

from your ToS:

>"We are not liable for any loss or damage that may result from your use of our services. This includes any direct, indirect, or consequential losses; any loss or damage caused by tort, including negligence, breach of contract or otherwise."

Oh geez.

Re: Teller – API for your bank account

#106
post #63

Earlier quoted context omitted.

Hi, Firstly, we don't always need a credential. Some banks provide other auth mechanisms, e.g. EMV CAP. We use this for Barclays and Nationwide. Using Teller might not violate your bank's terms of service, which is why we advise you to read them in conjunction with ours. Furthermore, it is the view of some senior bank people that I speak to that PSD2 will make such clauses in banking terms illegal. It is also worth m…

Would be prudent and indeed consumer friendly if you where to go thru those TOS the banks have in conjunction with your own and provide a simple at a glance list of liability/impact. Reassure people that way and shows, you care and thought this thru beyond saying we recommend reading this and that as people are wary and equally might not understand it. Sure would take time and some effort, but would certainly return…

They'd likely be opening themselves up to huge liability if they did that though.

Re: Teller – API for your bank account

#107

Earlier quoted context omitted.

I believe this is true for most US banks also. I can't even count how many promising-looking Fintech products I had to pass over because the only auth mechanism they offered was through sharing online banking credentials. Until bank policies regarding credentials-sharing actually change, I think it's really irresponsible for products to even ask for credentials at all, let alone offer it as the default/only auth opti…

Users could be unwittingly putting their entire life savings at risk. Is this a realistic concern? I thought the point of a bank was that situations like that can be reversed 100% of the time.

Unless you hand out your credentials to an unauthorized third party, relieving the bank of any liability.

Re: Teller – API for your bank account

#108
post #94
post #74

When will this be available in the US?

Never? You need legally available reverse engineering without dmca-hammer to be applied plus PSD2 directive coming soon forcing banks to open. Those are EU things.

yodlee, mint, quicken, come on. I've had bank transaction information for last 20 years

Re: Teller – API for your bank account

#109
post #11

Earlier quoted context omitted.

Your terms: "We are not liable for any loss or damage that may result from your use of our services. This includes any direct, indirect, or consequential losses; any loss or damage caused by tort, including negligence, breach of contract or otherwise." You don't get taken seriously in the financial space with terms like that. You need to accept responsibility for errors and carry errors and omissions insurance. Compa…

Bank of America's assets total over 2 trillion dollars. I would imagine it's easier for large financial institutions to create such strong guarantees for its users.

ok, so... I'll take BoA seriously, and not these guys.

Re: Teller – API for your bank account

#110

UK banks don't accept any liability if you give your online banking credentials to a third party. If some fraud was to come about as a result of someone using Teller then they would be out of pocket or has Teller got agreements with the compatible banks to overcome this situation (either by Teller reimbursing the customer or the bank)?

Hi, Firstly, we don't always need a credential. Some banks provide other auth mechanisms, e.g. EMV CAP. We use this for Barclays and Nationwide. Using Teller might not violate your bank's terms of service, which is why we advise you to read them in conjunction with ours. Furthermore, it is the view of some senior bank people that I speak to that PSD2 will make such clauses in banking terms illegal. It is also worth m…

> Furthermore, it is the view of some senior bank people that I speak to that PSD2 will make such clauses in banking terms illegal.

I'm not sure that's the case; I thought the FCA were pretty clear one intent of PSD2 is to stop the need for screen scraping.[1]

Have you had any dialogue with OpenBanking UK etc. about their strategy on API driven interactions?

1. https://www.out-law.com/en/articles/2017/february/screen-scr...

Post reply on HN