The actual secret API of banks-and by the way this is the initial strategy Plaid pursed if rumor is to be believed (essentially without the consent of the banks)-is by reverse engineering mobile app APIs. Most of these bank APIs try to use cheesy secret token vending to prevent casual API traffic on their endpoints, but the reality is that a sufficiently instrumented Android kernel (or rooted iOS device) will let you…
The Secret API of Banks
121–130 of 257 posts
Re: The Secret API of Banks
#122We are a business focused bank, but we support sole proprietors and freelancers as well.
API docs are here: http://docs.seed.co/v1.0.0/docs
p.s. We are working on Android I promise please don't yell at us (again).
Re: The Secret API of Banks
#123Re: The Secret API of Banks
#124Earlier quoted context omitted.
> Since you're so far in the future, can you consider dragging Germany into it as well so I don't have to use cash everywhere I go? I think that stems from an intense dislike of debt, specific to Germany more than anything. Not sure why that's relevant to my comment though, or why being 'so far in the future' means 'credit cards everywhere at all times'. Also the USA is still using cheques. They haven't even got to c…
"Also the USA is still using cheques. They haven't even got to chip and pin yet. We are pretty much past that and onto contactless." I'm not sure what you're talking about. All my cards have chips, and I'm in the US. And for several years, I've been living in an apartment which takes direct bank transfers for rent rather than paper checks. Landlords in my experience have been the last holdouts that don't want to stop…
Re: The Secret API of Banks
#125Forgive the shameless self-promotion, but we at Seed offer a customer facing API for read-only transaction data. We would happily build out more API features, but we've seen very little demand, despite the frequent HN threads about bank APIs. We are a business focused bank, but we support sole proprietors and freelancers as well. API docs are here: http://docs.seed.co/v1.0.0/docs https://seed.co p.s. We are working o…
From the FAQ, my best guess is that you offer businesses bank accounts that come bundled with the reporting you'd get with something like Mint/Quickbooks?
It's OK to basically be two services glued together, but why are you better than just the two existing services, were they to be glued together?
Re: The Secret API of Banks
#126Earlier quoted context omitted.
I disagree entirely. The problem is that the US banking industry permits this state of affairs. They should require updated, at-table point-of-sale devices within a reasonable timeframe to be able to continue to take credit cards.
It always seemed odd to me that the card readers are owned by the retailer. On the one hand, that leads to a lot of old or insecure-by-design equipment in circulation as 'not worth the cost to replace", and on the other hand, it tends to lead to a lot of annoying spam calls of "we'll replace your machine if you switch your payment processing to our company." If the upstream providers provded the readers as a leased s…
Re: The Secret API of Banks
#127The actual secret API of banks-and by the way this is the initial strategy Plaid pursed if rumor is to be believed (essentially without the consent of the banks)-is by reverse engineering mobile app APIs. Most of these bank APIs try to use cheesy secret token vending to prevent casual API traffic on their endpoints, but the reality is that a sufficiently instrumented Android kernel (or rooted iOS device) will let you…
Cert pinning. EOL.
And while I know I did a cert pin and you did a cert pin, not everyone does it (or does it bidirectionally). Nor is that the only way folks would get an API spec.
Re: The Secret API of Banks
#128The actual secret API of banks-and by the way this is the initial strategy Plaid pursed if rumor is to be believed (essentially without the consent of the banks)-is by reverse engineering mobile app APIs. Most of these bank APIs try to use cheesy secret token vending to prevent casual API traffic on their endpoints, but the reality is that a sufficiently instrumented Android kernel (or rooted iOS device) will let you…
That rumor sounds far from plausible though. If they were to attempt to use the reverse-engineered API from their own servers without consent, banks would find out (in a matter of hours) and shut them down when they discover a huge spike in traffic from a relatively small pool of IPs. If they were to access it directly from customers' phone/browser via their (web-)apps, I expect that it would've caused a huge media s…
AMA, I guess.
But to answer the implicit question: shutting that off can be harder than it sounds. And because it's a mobile API and iOS's store has fairly slow update cycles, it can be very hard to simply rotate your API spec fast enough without interrupting customer service: a difficult thing for a bank to get away with (lol, I'm joking they're down all the time).
Re: The Secret API of Banks
#129Anyone use Firefly III? It uses the Spectre API to allow you to have a self-hosted Mint. https://firefly-iii.org/
Re: The Secret API of Banks
#130The actual secret API of banks-and by the way this is the initial strategy Plaid pursed if rumor is to be believed (essentially without the consent of the banks)-is by reverse engineering mobile app APIs. Most of these bank APIs try to use cheesy secret token vending to prevent casual API traffic on their endpoints, but the reality is that a sufficiently instrumented Android kernel (or rooted iOS device) will let you…
Why don't banks sell API access at a rate s/similar/lower than Google Maps API access? This is starting to feel like music and video piracy all over again.