Live data from Hacker News

The Secret API of Banks

gduverger.com

161–170 of 257 posts

Re: The Secret API of Banks

#161
post #71
post #65

Earlier quoted context omitted.

So you need to be vetted and approved before being allowed access to some of people's most private and secure data. Why is this a problem exactly?

My problem is that it does not even allow access to your own account. Nobody has a problem with access to others ' accounts being regulated. I just want to do whatever I want with my own account.

> My problem is that it does not even allow access to your own account.

Here, use our application to aggregate data about your financial history, just give it access to your data and it'll give you all sorts of useful stats.

Do not look behind the curtain, we're definitely not snaffling your data and giving it to anyone we feel like...

--edit-- The number of people who would be competent to write their own API-using software is pretty tiny as a proportion of the population. If you allow people access to their own account data via an API then they will seek out software to help them access it. The regulations are about who can produce and distribute such software.

Re: The Secret API of Banks

#162
post #157

Earlier quoted context omitted.

You'd submit it manually. >lawsuit You really think an aggregator who's blatantly violating bank TOS is going to sue?

Yes! There's only upside.

Well you then become worth it for the bank to counter-sue and get discovery on exactly how you broke their ToS.

Re: The Secret API of Banks

#163
post #38

Earlier quoted context omitted.

*in America Banks provide an API in Europe. In fact it's a legal requirement that's coming into force in 2019, and there are a lot of 'mobile-first' banks like Monzo and Revolut which make this entirely un-needed in the first place (providing spending exports, decent analytics, push notifications, etc etc). Welcome to the future. Contact your local politician if you want to join us. Maybe also ask about chip and pin…

Are you sure? Looking here[0], it seems the future is fake, and the EU is no better than the US in this regard. Even after 2019, I'll still have to scrape bank's website and manual exports to get my own data out in usable format. -- [0] - https://news.ycombinator.com/item?id=17718782

Germany is better unless you use a crappy bank. HBCI is a 20 years old API supported by most major banks.

Re: The Secret API of Banks

#164
post #71

Earlier quoted context omitted.

My problem is that it does not even allow access to your own account. Nobody has a problem with access to others ' accounts being regulated. I just want to do whatever I want with my own account.

If you are allowed to access your data, then you can grant that access to third parties (pass along the API token). I happen to think that is great, but we live in a time where the idea of my sharing my Facebook account with an app is considered a problem, because it has a list of my friends. My financial history contains a lot of metadata about third parties. This is exactly the intersection between this overlay str…

At the moment you can already grant third parties access to your data - you can pass along your online banking credentials and they will scrape the web UI (there is an entire industry built on that - companies like TrueLayer will take any bank’s credentials and some cash and give you JSON in exchange, scraping the online banking UI behind the scenes).

Stupid people will be stupid and will find a way to shoot themselves in the foot; doesn’t mean I should be prevented from accessing my own data.

Re: The Secret API of Banks

#165
post #42

Earlier quoted context omitted.

PSD2 and “open” banking is bullshit. I wish this myth would die - it is anything but “open”. If you want to gain access to API s , you need to become an “AISP” (as they are called in the UK), this requires a certification and a load of other nonsense akin to PCI-DSS. This is for read-only access - for “write” access including the ability to edit payees or make payments you need to become a “PISP” which I assume requi…

> If you want to gain access to APIs, you need to become an “AISP” It's more complicated than that. Banks can give unregulated entities access to their APIs, but they don't because IMO providing API access is directly opposed to their interests. If you want to be statutorily entitled to API access you need to be a registered AISP or PISP. Unfortunately what an AIS is is very specific, i.e. showing the account owner a…

From what I've heard the main problem is banks are afraid popular API access would overload their mainframe-era systems that don't scale and can't scale.

Re: The Secret API of Banks

#166
post #161
post #71

Earlier quoted context omitted.

My problem is that it does not even allow access to your own account. Nobody has a problem with access to others ' accounts being regulated. I just want to do whatever I want with my own account.

> My problem is that it does not even allow access to your own account. Here, use our application to aggregate data about your financial history, just give it access to your data and it'll give you all sorts of useful stats. Do not look behind the curtain, we're definitely not snaffling your data and giving it to anyone we feel like... --edit-- The number of people who would be competent to write their own API-using…

> If you allow people access to their own account data via an API then they will seek out software to help them access it

Is that a bad thing? How about we let people do whatever they want with their data?

Not to mention the lack of APIs doesn’t stop this - there is an entire industry built on top of scraping bank’s web UIs. Companies like TrueLayer will happily take online banking credentials and provide you with an API, scraping the bank’s UI behind the scenes. A lot of financial aggregator apps use it for ages now.

Re: The Secret API of Banks

#167
post #132
post #42

Earlier quoted context omitted.

PSD2 and “open” banking is bullshit. I wish this myth would die - it is anything but “open”. If you want to gain access to API s , you need to become an “AISP” (as they are called in the UK), this requires a certification and a load of other nonsense akin to PCI-DSS. This is for read-only access - for “write” access including the ability to edit payees or make payments you need to become a “PISP” which I assume requi…

So you are saying Cambridge Analytica wouldn't be able to get access to people's banking data by marketing some sort of convenience app to them?

Cambridge Analytica didn't make or market such an app to them. It was some academic who made the app and then turned around and sold the data. This academic has now been largely erased from the story, presumably because journalists tend to like academics and anyway "one guy screwed up" is not a story whereas "clash of the corporate titans" is.

Re: The Secret API of Banks

#168
post #82
post #35

Earlier quoted context omitted.

This is, on one hand, great. I made the switch to a similar bank myself a few years back. What I failed to realise at the time was how exposed I became to the vulnerabilities associated with being cashless. Cash is not just an ancient relic. Cash is an ancient relic and a fundamental component of a free society. My country has, in practise, become nearly cashless and I used to be proud to be one of the very early ado…

Could you elaborate on the risks of not using cash for you?

Transaction fees, tracking, reliance on third-party controlled network that could go down or decide to exclude you.

Re: The Secret API of Banks

#169
post #28

I hate sounding like a VC jerk, but the banking industry needs some serious disruption.

The american banking industry, maybe. One of the ills of VC-mania is the ongoing assumption that a) problems that exist in the US exist everywhere and b) that there are no other problems. (see also: Uber busting the "taxi monopoly")

Uber is popular everywhere, including throughout Europe.

And as for banking, well, it's somewhat worse in the USA than elsewhere but it's not like Europe is overflowing with awesome hi-tech banks. Yes there are a few "startup banks" in the UK and one in Germany that I know of, and that's about it for the entire continent. Moreover the vast majority of people don't use them and bank with the existing set of firms, many of which have legacy and decaying IT estates. Look at what happened with TSB recently. Total meltdown. Major IT outages in the UK banking sector have become commonplace; you don't hear about that happening in the US.

Re: The Secret API of Banks

#170

In the UK the fintech (Financial Tech) scene is becoming more prevalent, for the better. Recently I switched to a new online-only bank called Monzo. It's fully licensed and all accounts are insured up to a certain amount by the UK government. It's great. They're in the top charts for apps in the UK now on the iOS App Store. There's a few other alternatives like Starling Bank and Revolut too. They're very good. They'r…

Revolut are a nightmare. After using it for several months and fully verified I apparently entered a CVV incorrectly on one transaction. Revolut blocked the card but with no notification, and no inapp indicators, all showed normal in app, all toggled enabled for maximum flexibility. It took ages to figure out, but swiping the card or using online was now returning to the merchant 'FRAUD/STOLEN' marker rather than jus…

I've done this with Monzo and you get a push notification saying "Declined at XYZ".

They seem to know what they're doing at least

Post reply on HN