Live data from Hacker News

UK's Open Banking to Launch on 13 January

openbanking.org.uk

61–70 of 113 posts

Re: UK's Open Banking to Launch on 13 January

#61
post #57

Why would anyone ever want to let a 3rd party company manage their bank account? I barely trust my bank yo do that... I'm afraid that some companies will try to force it upon customers as well. Starting with: "If you allow us to manage your purchase it will get even faster (oh and we get access to all of your financial info), and you also get a useless gadget!"

[deleted]

Re: UK's Open Banking to Launch on 13 January

#62

Sorry, but I can't see the benefit of it. Can anyone show a useful scenario... for the bank account owner?

It would let you see the balance of all your accounts in one place, share data with your accountant or IFA, or apply for a mortgage without those tedious forms as well as photocopies of bank statements, offer proof of income easily, use apps that offer a marketplace for mortgages, savings or other financial services, use apps like xero, mint or Emma with any bank account easily, etc.

It’s an API for your bank, and like stripe being an API for payments, I think it’ll shake up the market a bit. It should make a lot of things easier than before, and force large banks to allow customers to control their data more via authorised apps. It’ll take a while to have any impact though.

Re: UK's Open Banking to Launch on 13 January

#63
post #10
post #3

> Open Banking is a term that describes a secure set of technologies and standards that allow customers to give companies other than their bank or building society permission to securely access their accounts. Does it have to be another company or will I be able to write my own software that has access to my bank account?

My understanding is companies, who meet stringent requirements and can afford to take out insurance policies should they be liable for any loss/misuse of data.

I don't get why they can't give individuals and API key for access to only their own accounts.

Re: UK's Open Banking to Launch on 13 January

#64
post #46
post #22

Earlier quoted context omitted.

I think that will come. It will take a bit of time for comfort to set in (both with the consumer and the banks) but I definitely see this as the first step. (edit; in addition the psd2 legislatiob, and specifically the technical guidance, does touch on concepts like 4th party, relaying parties and technical partners - so the exoectation of the regulator is that this will emerge)

I'm struggling with the enterprise-y terminology. It sounds like: * your bank is an "ASPSP" * the second party is you * the company (third party) is the AISP So each individual company that needs to access your information is an AISP (or PISP for initiating payments)? Your accountant might be an AISP and your water company a PISP? And FCA requirements are ( https://www.fca.org.uk/firms/new-regulated-payment-services-…

Yes that is an accurate summary.

Re: UK's Open Banking to Launch on 13 January

#65
post #42
post #33

Earlier quoted context omitted.

Are you sure you can't? Besides the paper statements, I can download my transaction data in a variety of formats including CSV from every bank I've use in the Netherlands.

Does the history go back more than a year or two?

I would expect they are, if only for legal reasons.

According to my bank's website, I can get account statements up to 10 years back, except for closed accounts.

Re: UK's Open Banking to Launch on 13 January

#66
post #58

I've read through their website a few times. Whilst it's easy to find the specs and a list of banks participating - you can even find some example code on GitHub - it's incredibly hard to find out what you actually have to do to be able to access the APIs. I appreciate that banking data is sensitive, but I think the on boarding process could be made a lot clearer.

First you need to be accredited by the FCA, either as a third party provider or as a banking institute. Not 100% sure what comes next.

Profit.

Re: UK's Open Banking to Launch on 13 January

#67
post #17

I'm really excited by this (and PSD-2), as a banking API is the last piece of the puzzle to create fully automated businesses.

If you use a modern SaaS account app like Xero you can already access banking records no? What does this give us that you don't already have to fully automate your business?

Re: UK's Open Banking to Launch on 13 January

#68
post #32

Earlier quoted context omitted.

It's already against the typical bank's terms of service for a user to provide them. Not to mention a silly thing to do. But the average user seems just blindly trusts these things - tools like 'You Need a Budget' ask for the same.

Founder here. This is incorrect. It is no longer against the terms of service of any European bank as of today thanks to PSD2.

Really? So that suggests enrolment in an 'Open Banking' app requires the same?

That's extremely disappointing...

Re: UK's Open Banking to Launch on 13 January

#69

Earlier quoted context omitted.

Yes, every UK bank had to write to their customers updating their terms allowing such activity end of last year.

I have accounts with several banks and other financial services, and I have received various updates to terms in connection with PSD2 over the past few months. However, I don't recall any of them saying it was now OK to share things like passwords or PINs. Are we talking at cross-purposes here? Encouraging non-experts to share security credentials that give unrestricted access to their accounts with third parties is…

What the existing screen scraper companies have done, is to make sure the psd2 directive will allow screen scraping as a fallback method if they are not satisfied with the bank API:s.

That's because the directive is actually a competitive disadvantage for them since they've invested a lot in the screen scraping.

The interpretation is not trivial though. The authentication details in particular are not very clear right now.

Re: UK's Open Banking to Launch on 13 January

#70
post #10

Earlier quoted context omitted.

My understanding is companies, who meet stringent requirements and can afford to take out insurance policies should they be liable for any loss/misuse of data.

I don't get why they can't give individuals and API key for access to only their own accounts.

presumably as dubious third parties would use it a way round the control framework

"get your API key, paste here", etc

Post reply on HN