Live data from Hacker News

Visa Buys Plaid

wsj.com

181–190 of 333 posts

Re: Visa Buys Plaid

#181

Earlier quoted context omitted.

pretty sure this is false, all my accounts are 2FA, and connected to a few different account aggregators (mint, personalcapital, etc) which i am prettty sure all use Plaid. Handles it fine.

So, you call me a liar? I have personal, my own business, and several accounts of a nonprofit I am an officer at. All have 2FA and none work. Intuit is a different story and I'm able to sync in bank transactions into it - not with Plaid-based services though!

I feel sorry you had to go through those replies telling you your statements were false or wrong. I think it comes from people who think that if it works for them, it must work for everyone else.

Re: Visa Buys Plaid

#182
post #141

Slightly off topic, but worth highlighting. Privacy virtual card use Plaid (well at least the last time I looked at it a few months back). The integration was extremely questionable. They were faking the bank’s login page. So when you enter your credentials, it wasn’t the actual banks page. There was a github issue opened, and after several followed up complaints they blocked further commenting and the removed then t…

Collecting actual banking credentials is how plaid works, quite literally. One needs to be clinically insane to give your bank login creds to a third party voluntarily! I refuse to do business with any business that uses plaid and has no sane alternative to get bank account numbers (deposit two small amounts, three days later I tell you what they are) First time i saw it, i assumed the website had been hacked. I was…

> I refuse to do business with any business that uses plaid and has no sane alternative to get bank account numbers (deposit two small amounts, three days later I tell you what they are)

I'm a bit horrified this is still a thing, too. Doing this just confirms you have the correct account and routing number, so you can deposit and withdrawal. It won't allow you to see transactions--will it?

FWIW, a minority of banks have "linked apps" that allow you to revoke access from the bank's website (some are clear they're restricting it to read-only access). But I'm not sure how consistent or widespread this kind of thing is. I doubt if you're offering a service like Plaid you could rely on only supporting these institutions.

Re: Visa Buys Plaid

#183
post #48

Plaid is terrible! Both Wells Fargo and Bank of America support API integration, but Plaid chooses to screen-scrape and does not work if you have 2FA enabled. Also, you can't even manually enter your bank information. In other words, even if you pay dearly to Plaid, you may block many users who use some of the top banks in the States! There is a bunch of services I cannot use because they rely solely on Plaid, and I'…

This is why I never wanted to use Mint, although maybe Mint is better about this now. I've also seen online mortgage applications ask for banking and retirement account passwords for the purpose of automated form-filling. It seems very shortsighted to give away your password to save 5 minutes filling out a form. The nightmare scenario is that you give your bank account password to one of these screen scraping service…

The cynical part of me is convinced that banks would want to secretly run and popularize this kind of service as honeypots for collecting passwords sharing violations as a future liability defense.

Re: Visa Buys Plaid

#184
post #141

Slightly off topic, but worth highlighting. Privacy virtual card use Plaid (well at least the last time I looked at it a few months back). The integration was extremely questionable. They were faking the bank’s login page. So when you enter your credentials, it wasn’t the actual banks page. There was a github issue opened, and after several followed up complaints they blocked further commenting and the removed then t…

Collecting actual banking credentials is how plaid works, quite literally. One needs to be clinically insane to give your bank login creds to a third party voluntarily! I refuse to do business with any business that uses plaid and has no sane alternative to get bank account numbers (deposit two small amounts, three days later I tell you what they are) First time i saw it, i assumed the website had been hacked. I was…

> First time i saw it, i assumed the website had been hacked. I was actually more horrified when I found out that this was working as intended and some website wanted my bank password!

This was my exact same impression. Even after some Googling and asking friends where I learned this was a thing, I was still very wary that it was legit.

Re: Visa Buys Plaid

#185
post #170

Heard they were offering .1 percent for senior software engineers 6 months ago. Congrats guys! (source: https://www.teamblind.com/post/Plaid-acquired-by-Visa-for-5B... )

[deleted]

Re: Visa Buys Plaid

#186
post #48

Plaid is terrible! Both Wells Fargo and Bank of America support API integration, but Plaid chooses to screen-scrape and does not work if you have 2FA enabled. Also, you can't even manually enter your bank information. In other words, even if you pay dearly to Plaid, you may block many users who use some of the top banks in the States! There is a bunch of services I cannot use because they rely solely on Plaid, and I'…

This is why I never wanted to use Mint, although maybe Mint is better about this now. I've also seen online mortgage applications ask for banking and retirement account passwords for the purpose of automated form-filling. It seems very shortsighted to give away your password to save 5 minutes filling out a form. The nightmare scenario is that you give your bank account password to one of these screen scraping service…

Mint used to sync with Chase and Wells Fargo through sketchy scraping, but those banks have since then integrated with Mint over APIs. Mint then disabled syncing until customers reestablished the connection with the new, more secure, method (which I thought was a good move)

Re: Visa Buys Plaid

#187
post #48

Plaid is terrible! Both Wells Fargo and Bank of America support API integration, but Plaid chooses to screen-scrape and does not work if you have 2FA enabled. Also, you can't even manually enter your bank information. In other words, even if you pay dearly to Plaid, you may block many users who use some of the top banks in the States! There is a bunch of services I cannot use because they rely solely on Plaid, and I'…

> and does not work if you have 2FA enabled

Certainly false, at least for Bank Of America. Just yesterday I connected BofA to privacy.com using Plaid and it asked me to enter the SMS 2fa code.

Re: Visa Buys Plaid

#188

Earlier quoted context omitted.

Not even close to true. We’re one of the larger clients with Plaid and that’s not on Plaid but the service provider to not provide a manual entry. Plaid works great and we’ve ran into next to no issues with customers linking Plaid

So, I'm imagining their errors and suggestions to turn off 2FA?

I need to go back and check, we might be in one of their test groups as I haven’t heard any issues with 2FA. We do a catch-all and based on the error, we prompt the user to manually provide their banking info to proceed.

Worth noting I don’t work for a financial services company so the use case is likely very different than the services you’re discussing.

Apologies if I came off strong, it appears I may be a one-off consumer as opposed to mainstream.

Re: Visa Buys Plaid

#189
Open Banking Standards in Commonwealth Countries will make the need for these scrapers redundant and limit the tools use to the US only.

Never been a fan of scrapers. Very unreliable and a big security hole especially when MFA is used.

I wonder if the tightening data privacy regulations (CCPA et al) forced them to sell or whether it was just a good sale opportunity.

Re: Visa Buys Plaid

#190
post #183

Earlier quoted context omitted.

This is why I never wanted to use Mint, although maybe Mint is better about this now. I've also seen online mortgage applications ask for banking and retirement account passwords for the purpose of automated form-filling. It seems very shortsighted to give away your password to save 5 minutes filling out a form. The nightmare scenario is that you give your bank account password to one of these screen scraping service…

The cynical part of me is convinced that banks would want to secretly run and popularize this kind of service as honeypots for collecting passwords sharing violations as a future liability defense.

That’d probably risk a counter-suit for willful negligence.
Post reply on HN