Live data from Hacker News

Visa Buys Plaid

wsj.com

291–300 of 333 posts

Re: Visa Buys Plaid

#291

Earlier quoted context omitted.

I work for a popular european competitor of Plaid, Tink ( https://tink.com ). We don't do screen scraping, but use the banks' own APIs. These days we also ride on the european bank directive "PSD2" which gives us the right to aggregate financial data from financial providers such as banks. That means we aren't breaking an Terms of Services with banks! ...and yes, we support 2FA. ;)

Note that a SSL_ERROR_BAD_CERT_DOMAIN is shown when trying to access tink.com at the moment. Says the certificate is only valid for cloudfront.net. Edit: the website itself also returns a 403.

Weird. Works for me now. ¯\_(ツ)_/¯

Re: Visa Buys Plaid

#292
post #102

Earlier quoted context omitted.

The way Plaid works, I'm surprised that they hadn't already been shut down for breaking banks' TOS. It exposes the banks to so much liability for a product that's not even theirs.

I dislike Plaid & similar systems but I disagree. Enforcing stupid & unreasonable ToS in court is a slippery slope that can be used against users. You want to use an alternative client to export your data because the official client doesn't allow it? ToS violation and the developer of the alternative client gets sued. Want to screen-scrape some website to automate some tedious manual behaviour? ToS violation and you…

To me that depends on where the fraud risk lies.

In the UK banks (in an attempt to encourage online banking) have a fraud guarantee related to losses from unauthorised access to online banking systems as long as you haven't given your credentials to a 3rd party

Screen scraping, like plaid, obviously breaks that concept.

In that case it seems reasonable for the banks to have a ToS that says "no giving your credentials to third parties".

If there's no such guarantee and the user is on their own from a fraud loss perspective then I don't see a reason for enforcing that kind of ToS.

All that said, the idea of a transactional banking system being online with purely static credentials in 2020 is scary one. Decent 2FA should be used for any system that has a financial impact.

Re: Visa Buys Plaid

#293

Plaid's product is absolutely absurd. Yes, please train your users to type their username and passwords into third party sites because they're given a legitimate looking sign-in box. US Banking infrastructure is so hopelessly bad that this is hack of a business is considered legitimate fin-tech. My wallet was stolen and before I realized it was gone and could cancel my CCs some dude made like six obviously fraudulent…

I have a wallet attached to the back of my phone and it's the only thing I carry. Makes it tough to forget / not realize it missing since I need it so frequently.

So a single point of failure then?

It also means you are holding your cards on your time all the time you use your phone on the street, which is prime time for somebody to come and snag it out of your hand

Re: Visa Buys Plaid

#294

Earlier quoted context omitted.

Note that a SSL_ERROR_BAD_CERT_DOMAIN is shown when trying to access tink.com at the moment. Says the certificate is only valid for cloudfront.net. Edit: the website itself also returns a 403.

Weird. Works for me now. ¯\_(ツ)_/¯

Lancaster, England, Windows 10, Firefox, working perfectly for me as well.

Re: Visa Buys Plaid

#295
post #48

Plaid is terrible! Both Wells Fargo and Bank of America support API integration, but Plaid chooses to screen-scrape and does not work if you have 2FA enabled. Also, you can't even manually enter your bank information. In other words, even if you pay dearly to Plaid, you may block many users who use some of the top banks in the States! There is a bunch of services I cannot use because they rely solely on Plaid, and I'…

I work for a popular european competitor of Plaid, Tink ( https://tink.com ). We don't do screen scraping, but use the banks' own APIs. These days we also ride on the european bank directive "PSD2" which gives us the right to aggregate financial data from financial providers such as banks. That means we aren't breaking an Terms of Services with banks! ...and yes, we support 2FA. ;)

Works for me Chicago, IL, USA Chrome 79.0.3945.117 Useragent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36 Running on Debian Linux 10

Re: Visa Buys Plaid

#297
post #48

Plaid is terrible! Both Wells Fargo and Bank of America support API integration, but Plaid chooses to screen-scrape and does not work if you have 2FA enabled. Also, you can't even manually enter your bank information. In other words, even if you pay dearly to Plaid, you may block many users who use some of the top banks in the States! There is a bunch of services I cannot use because they rely solely on Plaid, and I'…

I'm surprised they still scrape Bank of America. A few months back (maybe a year), when they really pushed their API integration over scraping, a bunch of services (QuickBooks, Mint, Privacy) required me to reauth on my BofA accounts.

I assumed this was because they were switching over to their API, and that was the only way to pull data now. I could be wrong, it just seems weird that 3 different sites made me reauthenticate within a month or so.

Re: Visa Buys Plaid

#298
post #48

Plaid is terrible! Both Wells Fargo and Bank of America support API integration, but Plaid chooses to screen-scrape and does not work if you have 2FA enabled. Also, you can't even manually enter your bank information. In other words, even if you pay dearly to Plaid, you may block many users who use some of the top banks in the States! There is a bunch of services I cannot use because they rely solely on Plaid, and I'…

In many cases, if the APIs are available _and support all the necessary features_, Plaid will work with the bank to use the APIs. Banks have chosen to withhold some info from the APIs that are available on the site, which prevents a full switchover. The other problem, of course, is the payment model: should Plaid pay banks for access to the data? Should banks have to make the APIs as fully featured as their site for external consumption?

Also worth noting that the largest of US banks do offer APIs, but a large swath of the rest do not, either due to proprietary systems, choosing not to use their processor-offered solutions, or simply avoiding risk.

So, Plaid will have to scrape for another few years, I suspect, until the banks catch up in the US to what we are seeing in UK and other places.

Re: Visa Buys Plaid

#299
post #48

Plaid is terrible! Both Wells Fargo and Bank of America support API integration, but Plaid chooses to screen-scrape and does not work if you have 2FA enabled. Also, you can't even manually enter your bank information. In other words, even if you pay dearly to Plaid, you may block many users who use some of the top banks in the States! There is a bunch of services I cannot use because they rely solely on Plaid, and I'…

Plaid's better than using Finicity, which is even worse.

Finicity is actually the old Intuit screen scraping tech. It's been around almost as long as Yodlee. Not to impugn legacy tech or anything, but I suspect there's some cleanup to do there.

Re: Visa Buys Plaid

#300
post #276

Earlier quoted context omitted.

That's default, but you can buy an RSA hardware token.

Like this one [1]? Seems that it is not necessarily better than SMS. [1] https://news.ycombinator.com/item?id=4156897

There is an actual, material difference between having no 2FA (guess passwords until you get in), SMS 2FA (have a human person call a phone provider and have the number switched), and token 2FA (given the physical device and a few hundred attempts, you're able to make another device that also authenticates). Saying you might as well not enable 2FA because a token cloning attack exists is ridiculous.
Post reply on HN