Live data from Hacker News

The Secret API of Banks

gduverger.com

221–230 of 257 posts

Re: The Secret API of Banks

#221

Earlier quoted context omitted.

> just not how you want it Which is a big deal in 2018 and the era of open data, data portability (even Facebook offers data exports). Why don't banks offer data exports?

It's mostly because your Facebook account doesn't have a balance :). On the other hand I'm not sure what data you need exported and can't. A bank data export is the monthly bank statement. Most banks allow you to to export every transaction going back some years from the app or website. Going further back you can address the bank and they will provide you with such an export going as far back as the local laws mandat…

Honestly? My Facebook data (back when I had one) contains way more valuable data than my bank statement.

Well let me give you a real example - my personal bank account is Monzo so there is an API and webhooks and all is well.

My business account doesn't yet have an API (it's Starling Bank - a modern bank so they're planning to have one that gives out personal access tokens without needing to be an AISP). I have accounting software (FreeAgent) that has an API. I want to make it so that every time I use the business bank card it creates a new expense (and if it's things I expect - food deliveries, etc - automatically look up the receipt in my inbox and attach it to the expense entry in the accounting software). Same thing for incoming payments - if I receive an incoming payment with a non-blank reference, look through the invoices to see if any of the references match, if so, mark it as paid and send a thank you email to the client.

Am I really asking for too much?

Re: The Secret API of Banks

#222

Earlier quoted context omitted.

I am prevented from accessing my own data. A lot of bank's online banking is absolutely awful and doesn't go back more than 3 months worth of transactions. Thankfully none of this bullshit actually applies to me (I use Monzo Bank which does have an API) but I feel the pain for everyone else. > it doesn't mean they have to open all doors and say "do what you want, I'm not even here" So hold on, does this means we now…

> online banking is absolutely awful and doesn't go back more than 3 months It doesn't mean you can't request it directly with the bank. It is more cumbersome but they have to be able to provide that data as far back as the country's laws require them to keep it. It's just that usually data older than 12-24 months is archived and I can guarantee you no API no matter how open it is will allow you to get the data direc…

My Monzo API allows me to go back to when I opened the account (back then it was just a prepaid card) in 2016. Somehow they are able to get the data directly from this "archive" which frankly shouldn't exist - Facebook is able to lookup stuff from 10 years ago instantly - don't tell me a bank can't do the same.

> But touch someone else's cash or account has always been regulated, yes

My argument here is about my own account. I'm even happy to send a letter stating that I am not an idiot and assume all responsibility just to get a personal access token.

> You're basically advocating for the removal of most regulation anywhere

I'm not advocating for no regulations everywhere - some stuff absolutely does need to be regulated, like massive tracking across the web. However when the user is in control and is knowingly handing over the key to their account, I'm happy for there to be no regulations. Same way nobody is preventing you from handing over your house keys to someone.

Re: The Secret API of Banks

#223
post #214

Earlier quoted context omitted.

> For the same reason we can't have quite a lot of other nice things - scammers and shysters will take advantage. In that case, let's get rid of cash, cards, and frankly everything, because otherwise scammers will take advantage.

Allowing anyone to use any software to access their banking data would allow them unprecedented abilities to automate, and attack. I'm sorry if you don't feel that's adequate. Perhaps you should have a conversation with one of the many people that object to OpenBanking because it's far too permissive and they don't want the possibility of any third party getting their banking data, ever, oversight or not.

> Allowing anyone to use any software to access their banking data would allow them unprecedented abilities to automate, and attack.

In certain countries (Germany, etc) there are actually open protocols (FinTS/HBCI, etc) that banks conform to and allow any software to gain access to the accounts provided the proper credentials are supplied, and it doesn't look like the world has melted down.

Re: The Secret API of Banks

#224
post #215

Earlier quoted context omitted.

> Because at the moment, stupid people can withdraw all their cash and throw it away, and nobody is there to prevent them from doing so. This is not actually a real world problem though. If it were it would likely be addressed. Why do so many people think only in theoretical extremes?

I don’t see account access being abused either. People could already be giving out their credentials, but somehow it’s not happening, so I don’t see the argument against personal access tokens.

> People could already be giving out their credentials, but somehow it’s not happening,

It is, people often get scammed into giving access to their accounts. Having more locked-down APIs is a way to move off from this.

Re: The Secret API of Banks

#225

Earlier quoted context omitted.

^ This. It's often called "Quicken Direct Connect" (NOT "web connect", that's a bastardization trying to push the login flow through the proprietary web interface), and often has to be specifically enabled for your account (Bank of Slum-merica is the only place I've heard charging for the functionality though). Check say https://ofx-prod-filist.intuit.com/qb2600/data/fidir.txt to see if your bank is listed (that cont…

How does web connect actually work? I've never found any description of the method

I don't exactly know. But I'm under the impression that it performs the standard website login flow via headless browsing, then uses the website's "download transactions as OFX" functionality. So similar problems as "screen scraping" but less error prone because if it successfully downloads the data, it is in a well-defined format.

Re: The Secret API of Banks

#226

Earlier quoted context omitted.

It's mostly because your Facebook account doesn't have a balance :). On the other hand I'm not sure what data you need exported and can't. A bank data export is the monthly bank statement. Most banks allow you to to export every transaction going back some years from the app or website. Going further back you can address the bank and they will provide you with such an export going as far back as the local laws mandat…

Honestly? My Facebook data (back when I had one) contains way more valuable data than my bank statement. Well let me give you a real example - my personal bank account is Monzo so there is an API and webhooks and all is well. My business account doesn't yet have an API (it's Starling Bank - a modern bank so they're planning to have one that gives out personal access tokens without needing to be an AISP). I have accou…

Honestly. [1] Make it $500. $1000. Unless you put the next winning lottery numbers in there, your data isn't that valuable. And in case you are wondering some data is heavily regulated anyway.

But you keep moving the goalposts, you complain about something, it turns into a non-issue, then move to something else. First it was that you don't have access to your data, then it turned into web banking only providing 3 years of the data you don't have access to (?), then it was back to no access to data.

For my last reply I'll rehash it:

a) you do have access to all your data just not how you want it: you want access via a generic interface of your choosing so that you may process it somehow. They provide access via their proprietary interface making the processing more cumbersome.

b) smaller banks will offer APIs for individual use because it's cheaper for them and want to attract customers, larger banks don't because it's expensive, riskier, and they already have the customers.

c') your bank offers you the API because you are its customer and they have control. They do not offer that access to a random 3rd party in bulk because that third party is not their customer and they lose control (in the bad way).

d) no bank really wants to offer bulk access to APIs when the regulation sets a low bar because it's very risky and they are taking most of the risk.

Hence the regulation: you get access to the APIs if you meet some criteria.

Real world example? I want to be Bank of close04 but although I have a hand calculator and a pretty good hiding spot for money they still set the bar slightly too high. [2] Now sit on it, think it through and let me know why a bank holding your money would be treated any differently from a 3rd party that can perform close to any operation with that money. And why your earlier statement that "people should be free to [...]" doesn't make sense in the context of current day reality.

People's misery tends to turn into misery for the state. Which is why the state is regulating stuff. The more sensitive the topic, the higher the bar. Money is sensitive.

P.S. The argument that the bar for open banking is set high is to discourage competition and keep power in the hands of the banks is total BS, visible from afar. There will be dozens and dozens of 3rd parties more than able to fill the role. It could be "Amazon Financial Services", it could be one of the banks, it could be a 2 man startup with moderate financing. Literally thousands of startups manage to raise over $10 million.

[1] https://medium.com/wibson/how-much-is-your-data-worth-at-lea...

[2] https://www.offshorecompany.com/banking/start-a-bank/your-ow...

[3] https://techcrunch.com/2016/08/26/co-founders-optional/

Re: The Secret API of Banks

#227

Earlier quoted context omitted.

Honestly? My Facebook data (back when I had one) contains way more valuable data than my bank statement. Well let me give you a real example - my personal bank account is Monzo so there is an API and webhooks and all is well. My business account doesn't yet have an API (it's Starling Bank - a modern bank so they're planning to have one that gives out personal access tokens without needing to be an AISP). I have accou…

Honestly. [1] Make it $500. $1000. Unless you put the next winning lottery numbers in there, your data isn't that valuable. And in case you are wondering some data is heavily regulated anyway. But you keep moving the goalposts, you complain about something, it turns into a non-issue, then move to something else. First it was that you don't have access to your data, then it turned into web banking only providing 3 yea…

> Unless you put the next winning lottery numbers in there, your data isn't that valuable.

My Facebook or other data obtained through web tracking is definitely more valuable than my boring bank balance.

The thing about web banking not providing 3 years was just to refute your argument about how banks apparently provide me all the data I need, which clearly isn't the case.

> you do have access to all your data just not how you want it

I do not. In my previous response I told you that most banks do not provide more than 3 months of data.

> your bank offers you the API because you are its customer and they have control

All I'm asking for is that banks provide personal access tokens to any of their customers. I don't mind the regulations being there for massive-scale access, but I do want any customer who wants to automate their finances to be able to do so.

Re: The Secret API of Banks

#228

Earlier quoted context omitted.

Honestly? My Facebook data (back when I had one) contains way more valuable data than my bank statement. Well let me give you a real example - my personal bank account is Monzo so there is an API and webhooks and all is well. My business account doesn't yet have an API (it's Starling Bank - a modern bank so they're planning to have one that gives out personal access tokens without needing to be an AISP). I have accou…

Honestly. [1] Make it $500. $1000. Unless you put the next winning lottery numbers in there, your data isn't that valuable. And in case you are wondering some data is heavily regulated anyway. But you keep moving the goalposts, you complain about something, it turns into a non-issue, then move to something else. First it was that you don't have access to your data, then it turned into web banking only providing 3 yea…

[deleted]

Re: The Secret API of Banks

#229
post #224

Earlier quoted context omitted.

I don’t see account access being abused either. People could already be giving out their credentials, but somehow it’s not happening, so I don’t see the argument against personal access tokens.

> People could already be giving out their credentials, but somehow it’s not happening, It is, people often get scammed into giving access to their accounts. Having more locked-down APIs is a way to move off from this.

They are not using APIs to begin with. I'm not sure what else is there to lock down.

Maybe we should just let idiots be idiots, and natural selection (or in this case, financial selection?) do its thing and the problem will go away eventually?

Re: The Secret API of Banks

#230
post #214

Earlier quoted context omitted.

Allowing anyone to use any software to access their banking data would allow them unprecedented abilities to automate, and attack. I'm sorry if you don't feel that's adequate. Perhaps you should have a conversation with one of the many people that object to OpenBanking because it's far too permissive and they don't want the possibility of any third party getting their banking data, ever, oversight or not.

> Allowing anyone to use any software to access their banking data would allow them unprecedented abilities to automate, and attack. In certain countries (Germany, etc) there are actually open protocols (FinTS/HBCI, etc) that banks conform to and allow any software to gain access to the accounts provided the proper credentials are supplied, and it doesn't look like the world has melted down.

AFAICT FinTS wasn't ever massively widely supported and has never been fully implemented, there seems to be little information about it at all.

What info I can find appears in discussions related to PSD2, and one presumes there are reasons the EU didn't pick up that model but issued what it did.

One of the projects using these protocols seems to be openbankproject.com, but they have their apps go through approvals as well, using OAuth flows in a similar way to OpenBanking in the UK.

Eh. I don't really see how, even from your perspective, you can be against PSD and Open Banking - it forces all banks in the EU to open up more than the vast majority do now.

Post reply on HN