Live data from Hacker News

UK's Open Banking to Launch on 13 January

openbanking.org.uk

101–110 of 113 posts

Re: UK's Open Banking to Launch on 13 January

#101
post #71
post #59

Earlier quoted context omitted.

People said the said the same about ATMs. They were wrong.

How is ATMs remotely similar?

You give a 3rd party ATMs permission to withdraw money every time you use them. If they wanted to, they could store the data on the stripe of the card and your pin, and steal all of your money.

Re: UK's Open Banking to Launch on 13 January

#102
post #87

Earlier quoted context omitted.

How many people do you think will be able to secure their access? And what happens if their computer is hacked, the credentials stolen and the accounts emptied? It's not hard for me to imagine developers saying, "hey, we all know computers get hacked, it is the bank's job to know when its really me versus when someone stole my API keys. What a shitty bank. I'm expecting all my money back"

WTF? How is that any different with web interfaces? Or are you saying that people should just generally not be able to use their own computers for banking purposes?

API keys are stored on the computer (even accidentally pushed to github, etc)

Credentials for web interfaces are stored in our heads.

People are still able to use their own computers - via the web interface, which is under the full control of the banks.

Re: UK's Open Banking to Launch on 13 January

#103
post #101
post #71

Earlier quoted context omitted.

How is ATMs remotely similar?

You give a 3rd party ATMs permission to withdraw money every time you use them. If they wanted to, they could store the data on the stripe of the card and your pin, and steal all of your money.

That's not worse than doing any purchase at all.

If anything ATMs are the safest and best option available, well, aside from malicious hardware modifications done to them.

Having access to my bank account with all the history is another thing entirely.

Re: UK's Open Banking to Launch on 13 January

#104
post #103
post #101

Earlier quoted context omitted.

You give a 3rd party ATMs permission to withdraw money every time you use them. If they wanted to, they could store the data on the stripe of the card and your pin, and steal all of your money.

That's not worse than doing any purchase at all. If anything ATMs are the safest and best option available, well, aside from malicious hardware modifications done to them. Having access to my bank account with all the history is another thing entirely.

I guess our threat models are different. I'm not worried about transaction history as much as being able to drain the account.

Re: UK's Open Banking to Launch on 13 January

#105
post #3

> Open Banking is a term that describes a secure set of technologies and standards that allow customers to give companies other than their bank or building society permission to securely access their accounts. Does it have to be another company or will I be able to write my own software that has access to my bank account?

Change to a bank that lets you do it - for example, Mondo/Monzo has an API.

Re: UK's Open Banking to Launch on 13 January

#106

Earlier quoted context omitted.

WTF? How is that any different with web interfaces? Or are you saying that people should just generally not be able to use their own computers for banking purposes?

API keys are stored on the computer (even accidentally pushed to github, etc) Credentials for web interfaces are stored in our heads. People are still able to use their own computers - via the web interface, which is under the full control of the banks.

> API keys are stored on the computer (even accidentally pushed to github, etc)

Then ... create an API without "API keys"?!

> Credentials for web interfaces are stored in our heads.

So ... store the credentials for the API in your head then?!

> People are still able to use their own computers - via the web interface, which is under the full control of the banks.

Erm ... no, it's not? The bank sends me IP packets, what happens with those IP packets is completely under my control (or under the control of anyone who happens to have compromised my computer, for that matter). I select what web browser I use. I could write my own web browser. Or modify an existing one. Or run it under a debugger. Or just not use a browser at all. What my computer does with the IP packets my bank sends me is completely out of the bank's control.

Re: UK's Open Banking to Launch on 13 January

#107
post #78

Earlier quoted context omitted.

Want a better mortgage rate or a bigger loan? Let us look at the data, we may be able to give you one. Repeat for savings, insurance, whatever.

Yeh right you know those comparison sites are all pay to play TANSTAAFL as Bob Heinlein noted.

I said nothing about comparison sites,this could be other banks or financial service companies.

Re: UK's Open Banking to Launch on 13 January

#108
post #104
post #103

Earlier quoted context omitted.

That's not worse than doing any purchase at all. If anything ATMs are the safest and best option available, well, aside from malicious hardware modifications done to them. Having access to my bank account with all the history is another thing entirely.

I guess our threat models are different. I'm not worried about transaction history as much as being able to drain the account.

Even so, ATMs are much safer than trusting the store clerk and whatever device they use to read your card.

I know some magnetic stripe readers actually imitates a keyboard and just "write" the card info. So if you gave focus to notepad.exe instead all the card info would be dumped in cleartext. "Oh, seems it didn't register, could you swipe your card again?"

Re: UK's Open Banking to Launch on 13 January

#109
post #24
post #21

Earlier quoted context omitted.

No it isn't, at least, not yet - it asks for all the user login information including passwords and security numbers required for a normal login. Edit: And unfortunately, it doesn't seem even to have any intention of using it: https://twitter.com/stevegraham/status/951163378424217600

Teller is interesting; I have some reservations (mostly around the attitude they portray, which is a bit unprofessional) but they have a good vision. The downside is they are encouraging you to share passwords, as you say, which isn't driving the right customer behaviour. More critically; in about 18 months the PSD2 Secure Customer Authentication guidance comes into force and this sort of approach (sharing credential…

> a bit unprofessional

That's putting it mildly.

Re: UK's Open Banking to Launch on 13 January

#110

Earlier quoted context omitted.

Yes, every UK bank had to write to their customers updating their terms allowing such activity end of last year.

I have accounts with several banks and other financial services, and I have received various updates to terms in connection with PSD2 over the past few months. However, I don't recall any of them saying it was now OK to share things like passwords or PINs. Are we talking at cross-purposes here? Encouraging non-experts to share security credentials that give unrestricted access to their accounts with third parties is…

Most likely it took the form of 'Section 7.5.2 is deleted', and you or I wouldn't have noticed.

However, I will be hunting down the full version of the T&Cs for my account to see what they say now!

Post reply on HN