Live data from Hacker News

The Secret API of Banks

gduverger.com

121–130 of 257 posts

Re: The Secret API of Banks

#121

The actual secret API of banks-and by the way this is the initial strategy Plaid pursed if rumor is to be believed (essentially without the consent of the banks)-is by reverse engineering mobile app APIs. Most of these bank APIs try to use cheesy secret token vending to prevent casual API traffic on their endpoints, but the reality is that a sufficiently instrumented Android kernel (or rooted iOS device) will let you…

Cert pinning. EOL.

Re: The Secret API of Banks

#122
Forgive the shameless self-promotion, but we at Seed offer a customer facing API for read-only transaction data. We would happily build out more API features, but we've seen very little demand, despite the frequent HN threads about bank APIs.

We are a business focused bank, but we support sole proprietors and freelancers as well.

API docs are here: http://docs.seed.co/v1.0.0/docs

https://seed.co

p.s. We are working on Android I promise please don't yell at us (again).

Re: The Secret API of Banks

#124
post #88

Earlier quoted context omitted.

> Since you're so far in the future, can you consider dragging Germany into it as well so I don't have to use cash everywhere I go? I think that stems from an intense dislike of debt, specific to Germany more than anything. Not sure why that's relevant to my comment though, or why being 'so far in the future' means 'credit cards everywhere at all times'. Also the USA is still using cheques. They haven't even got to c…

"Also the USA is still using cheques. They haven't even got to chip and pin yet. We are pretty much past that and onto contactless." I'm not sure what you're talking about. All my cards have chips, and I'm in the US. And for several years, I've been living in an apartment which takes direct bank transfers for rent rather than paper checks. Landlords in my experience have been the last holdouts that don't want to stop…

Most American cards are chip and signature, not chip and pin. And they weren't even chip at all until recently.

Re: The Secret API of Banks

#125
post #122

Forgive the shameless self-promotion, but we at Seed offer a customer facing API for read-only transaction data. We would happily build out more API features, but we've seen very little demand, despite the frequent HN threads about bank APIs. We are a business focused bank, but we support sole proprietors and freelancers as well. API docs are here: http://docs.seed.co/v1.0.0/docs https://seed.co p.s. We are working o…

It's really unclear to me what your product is. I would have given up trying to figure out if you hadn't implied that it's somehow related to what this cool blog post accomplishes.

From the FAQ, my best guess is that you offer businesses bank accounts that come bundled with the reporting you'd get with something like Mint/Quickbooks?

It's OK to basically be two services glued together, but why are you better than just the two existing services, were they to be glued together?

Re: The Secret API of Banks

#126
post #113

Earlier quoted context omitted.

I disagree entirely. The problem is that the US banking industry permits this state of affairs. They should require updated, at-table point-of-sale devices within a reasonable timeframe to be able to continue to take credit cards.

It always seemed odd to me that the card readers are owned by the retailer. On the one hand, that leads to a lot of old or insecure-by-design equipment in circulation as 'not worth the cost to replace", and on the other hand, it tends to lead to a lot of annoying spam calls of "we'll replace your machine if you switch your payment processing to our company." If the upstream providers provded the readers as a leased s…

Not that I have practical experience with this, but I believe that equipment leasing is the norm in Australia.

Re: The Secret API of Banks

#127
post #121

The actual secret API of banks-and by the way this is the initial strategy Plaid pursed if rumor is to be believed (essentially without the consent of the banks)-is by reverse engineering mobile app APIs. Most of these bank APIs try to use cheesy secret token vending to prevent casual API traffic on their endpoints, but the reality is that a sufficiently instrumented Android kernel (or rooted iOS device) will let you…

Cert pinning. EOL.

If it's in the binary Simple ships I can take it or modify it to not need it. It's a huge pain in the ass, but it's not "hard."

And while I know I did a cert pin and you did a cert pin, not everyone does it (or does it bidirectionally). Nor is that the only way folks would get an API spec.

Re: The Secret API of Banks

#128

The actual secret API of banks-and by the way this is the initial strategy Plaid pursed if rumor is to be believed (essentially without the consent of the banks)-is by reverse engineering mobile app APIs. Most of these bank APIs try to use cheesy secret token vending to prevent casual API traffic on their endpoints, but the reality is that a sufficiently instrumented Android kernel (or rooted iOS device) will let you…

That rumor sounds far from plausible though. If they were to attempt to use the reverse-engineered API from their own servers without consent, banks would find out (in a matter of hours) and shut them down when they discover a huge spike in traffic from a relatively small pool of IPs. If they were to access it directly from customers' phone/browser via their (web-)apps, I expect that it would've caused a huge media s…

Hi, I founded Level Money, was one of Intuit's earliest aggcat customers and one of their last customers, and did this for a lot of people until Capital One bought my company and we did it for them.

AMA, I guess.

But to answer the implicit question: shutting that off can be harder than it sounds. And because it's a mobile API and iOS's store has fairly slow update cycles, it can be very hard to simply rotate your API spec fast enough without interrupting customer service: a difficult thing for a bank to get away with (lol, I'm joking they're down all the time).

Re: The Secret API of Banks

#130

The actual secret API of banks-and by the way this is the initial strategy Plaid pursed if rumor is to be believed (essentially without the consent of the banks)-is by reverse engineering mobile app APIs. Most of these bank APIs try to use cheesy secret token vending to prevent casual API traffic on their endpoints, but the reality is that a sufficiently instrumented Android kernel (or rooted iOS device) will let you…

Why don't banks sell API access at a rate s/similar/lower than Google Maps API access? This is starting to feel like music and video piracy all over again.

Because they know they can't compete on a technical level with Amazons and Google's even dumping a billion dollars into tech growth, and disintermediation is a fast road to becoming a utility.
Post reply on HN