Live data from Hacker News

The Secret API of Banks

gduverger.com

131–140 of 257 posts

Re: The Secret API of Banks

#131
post #42

Earlier quoted context omitted.

PSD2 and “open” banking is bullshit. I wish this myth would die - it is anything but “open”. If you want to gain access to API s , you need to become an “AISP” (as they are called in the UK), this requires a certification and a load of other nonsense akin to PCI-DSS. This is for read-only access - for “write” access including the ability to edit payees or make payments you need to become a “PISP” which I assume requi…

> If you want to gain access to APIs, you need to become an “AISP” It's more complicated than that. Banks can give unregulated entities access to their APIs, but they don't because IMO providing API access is directly opposed to their interests. If you want to be statutorily entitled to API access you need to be a registered AISP or PISP. Unfortunately what an AIS is is very specific, i.e. showing the account owner a…

To be honest those requirements sound perfect for a scrappy startup. Just enough of a moat to deter 99% of drive by hackers, but within the reach of any reasonably serious startup.

- £1,500 application fee

- €50,000 own capital requirements

If you're aiming to play in this league you really should be able to scrape together this kind of money.

- 3 months wait

Can also be seen as a 3 month delay imposed on your competitors.

Of course if you're aiming to use the API for your own personal needs only- then yeah, these requirements suck.

Re: The Secret API of Banks

#132
post #42
post #8

For those in the EU there's something interesting coming next year, banks need to provide open API to interact with each other: https://thenextweb.com/worldofbanking/2018/06/27/openbanking... Already right now in Germany there are a lot of banks that share a common API format which is why there are a lot of banking apps where you can just log into your bank and don't need bank specific apps. It's called HBCI / FinTS…

PSD2 and “open” banking is bullshit. I wish this myth would die - it is anything but “open”. If you want to gain access to API s , you need to become an “AISP” (as they are called in the UK), this requires a certification and a load of other nonsense akin to PCI-DSS. This is for read-only access - for “write” access including the ability to edit payees or make payments you need to become a “PISP” which I assume requi…

So you are saying Cambridge Analytica wouldn't be able to get access to people's banking data by marketing some sort of convenience app to them?

Re: The Secret API of Banks

#133
post #121

The actual secret API of banks-and by the way this is the initial strategy Plaid pursed if rumor is to be believed (essentially without the consent of the banks)-is by reverse engineering mobile app APIs. Most of these bank APIs try to use cheesy secret token vending to prevent casual API traffic on their endpoints, but the reality is that a sufficiently instrumented Android kernel (or rooted iOS device) will let you…

Cert pinning. EOL.

There are ways to work around cert pinning

Re: The Secret API of Banks

#134

I hate sounding like a VC jerk, but the banking industry needs some serious disruption.

I had a similar idea, so I looked up the process for starting a bank. There's a good reason fresh-faced startup VCs can't get into it. - Extremely high starting capital requirements (10-100 million USD) - Knowledge on security, finance, and law, means you will be needing an expert team of lawyers, accountants, cryptographers, etc. - An actual location and strictly controlled building to keep the physical money. There…

Sales pitch:

- Extremely high ($10 billion plus) market opportunity, with a ~0.1% to ~1% capital requirement.

- Recruit a team with the highly diverse skills needed to operate a modern bank.

- Have a secure location? Let us pay you to leverage assets from another startup.

Re: The Secret API of Banks

#135
post #88

Earlier quoted context omitted.

> Since you're so far in the future, can you consider dragging Germany into it as well so I don't have to use cash everywhere I go? I think that stems from an intense dislike of debt, specific to Germany more than anything. Not sure why that's relevant to my comment though, or why being 'so far in the future' means 'credit cards everywhere at all times'. Also the USA is still using cheques. They haven't even got to c…

"Also the USA is still using cheques. They haven't even got to chip and pin yet. We are pretty much past that and onto contactless." I'm not sure what you're talking about. All my cards have chips, and I'm in the US. And for several years, I've been living in an apartment which takes direct bank transfers for rent rather than paper checks. Landlords in my experience have been the last holdouts that don't want to stop…

My parents still use personal checks everywhere they can. They are why many stores still post "no checks accepted" signs in 2018.

Re: The Secret API of Banks

#136

Earlier quoted context omitted.

That rumor sounds far from plausible though. If they were to attempt to use the reverse-engineered API from their own servers without consent, banks would find out (in a matter of hours) and shut them down when they discover a huge spike in traffic from a relatively small pool of IPs. If they were to access it directly from customers' phone/browser via their (web-)apps, I expect that it would've caused a huge media s…

Hi, I founded Level Money, was one of Intuit's earliest aggcat customers and one of their last customers, and did this for a lot of people until Capital One bought my company and we did it for them. AMA, I guess. But to answer the implicit question: shutting that off can be harder than it sounds. And because it's a mobile API and iOS's store has fairly slow update cycles, it can be very hard to simply rotate your API…

Why is shutting it difficult? Any IP that logs into more than 5 accounts within a day gets a ban. They can use proxies but eventually will run out.

You can also use your own canary accounts, provide them to the service you want to block, and ban any IP that tries to log in

Re: The Secret API of Banks

#138

Earlier quoted context omitted.

I had a similar idea, so I looked up the process for starting a bank. There's a good reason fresh-faced startup VCs can't get into it. - Extremely high starting capital requirements (10-100 million USD) - Knowledge on security, finance, and law, means you will be needing an expert team of lawyers, accountants, cryptographers, etc. - An actual location and strictly controlled building to keep the physical money. There…

TBF in Europe (or specifically the UK) the new regulations seem to have come up with a plethora of new banks -Starling, Monzo, Revolut, Tide, etc. Both my personal and business accounts are with these, and it's awesome. Starling for my personal account and Tide for the business one. I get notifications of payments usually before the in-store machine has finished sorting itself out. Also get nice things like being abl…

Not from those EU regulations - PSD2 is more recent than most of those challengers. They've popped up because the FCA (the UK regulator) deliberately tried to make it easier to start banks in order to get more competition in the space.

Re: The Secret API of Banks

#139
post #91

I talk to (about) a person a week who wants to create a new US bank. Some are pursuing a de novo charter, some are buying a bank, and some are a quasi bank on top of another bank. The real blocker here is the Fed won't grant new charters and often won't transfer charters. I'm hoping this will change in the next few years and we can get some real competition. (Disclosure: my job is making APIs for US Banks.)

What's your take on new entrants at the processor level?

When I worked for a debit card startup (stripe's new feature, but worse, and years earlier), it seemed like the "bank account" parts were mostly boring money buckets, and all the interesting features existed at the processor level.

FIS was tragicomic to interface with, and they control something like 50% of card swipes in the US if i understand correctly?

Seems like if you want to make a really major play, you do to FIS what stripe did to paypal, right?

Re: The Secret API of Banks

#140
post #111

I hate sounding like a VC jerk, but the banking industry needs some serious disruption.

No, the financial services industry needs some serious disruption. Banks need to be MORE conservative. Not less. "Disruption" in banking is whats caused previous financial crisis. Managing user interfaces to sell financial products is not the same as running a bank. This is why API's are so important. They allow innovation in the sale of financial products while keeping the actual risk calculations on deposits and lo…

I want my bank to offer me the ability to generate Access Control Lists, with generated accounts. I want to make an account with read-only access to all of my financial information. I want to monitor all of my assets in real time, with alerts going to my phone for suspicious activity.

That's MORE conservative. But it's only enabled through intelligent APIs, which banks in the US don't have. With Mint, you passed over your full banking credentials, which was absurd.

I'd also like to remove the ability to PULL money from my credit / debit cards. I want only to PUSH money from my bank. Allowing companies to pull is what allows the vast majority of identity theft.

That's the kind of disruption I want.

Give ME the control to organize, monitor, and control access to my funds.

Post reply on HN