Live data from Hacker News

Visa Buys Plaid

wsj.com

301–310 of 333 posts

Re: Visa Buys Plaid

#301

Earlier quoted context omitted.

Wells Fargo's 2FA uses SMS. Hardly worth enabling.

I don’t know why you’re being downvoted. Sms 2FA is not safe, full stop.

For the average Joe it's good enough, no one is SIM swapping Bob who works at Walmart

Re: Visa Buys Plaid

#302

Earlier quoted context omitted.

I have a wallet attached to the back of my phone and it's the only thing I carry. Makes it tough to forget / not realize it missing since I need it so frequently.

So a single point of failure then? It also means you are holding your cards on your time all the time you use your phone on the street, which is prime time for somebody to come and snag it out of your hand

it looks like a normal case, you can't see the cards.

not a single point at all, it's just a couple cards in the slot.

Re: Visa Buys Plaid

#303
post #48

Plaid is terrible! Both Wells Fargo and Bank of America support API integration, but Plaid chooses to screen-scrape and does not work if you have 2FA enabled. Also, you can't even manually enter your bank information. In other words, even if you pay dearly to Plaid, you may block many users who use some of the top banks in the States! There is a bunch of services I cannot use because they rely solely on Plaid, and I'…

I work for a popular european competitor of Plaid, Tink ( https://tink.com ). We don't do screen scraping, but use the banks' own APIs. These days we also ride on the european bank directive "PSD2" which gives us the right to aggregate financial data from financial providers such as banks. That means we aren't breaking an Terms of Services with banks! ...and yes, we support 2FA. ;)

This is a lot easier because European banks all use similar APIs (as far as I've been informed). The US has no such bank API standardization in place. Most banks don't have APIs at all.

Re: Visa Buys Plaid

#304
post #48

Plaid is terrible! Both Wells Fargo and Bank of America support API integration, but Plaid chooses to screen-scrape and does not work if you have 2FA enabled. Also, you can't even manually enter your bank information. In other words, even if you pay dearly to Plaid, you may block many users who use some of the top banks in the States! There is a bunch of services I cannot use because they rely solely on Plaid, and I'…

You can now enter manual account and routing numbers with Plaid and they will handle micro-deposit verification. They also now support 2FA for many banks. Plaid is definitely not great in some areas, but there really isn't a good alternative if you want to aggregate your banking and transaction data. Not in the U.S.

Very few banks have publicly-accessible APIs, and when they do, they likely won't return consistent data. There simply isn't a standard in the U.S. There are literally thousands of banking systems in this country. As someone who helps run a fintech app, I can assure you there are significant numbers of people who are simply members of their local credit union with very limited technology.

Re: Visa Buys Plaid

#305

Plaid is an incredible company and provides a valuable service to their tech partners. That said, their data collection practices are scary. They allow any developer using their software to swallow all of a users banking data - I would love to know how they police bad actors. (Source: https://plaid.com/legal/#privacy-statement )

I'm confused. Isn't that the POINT of Plaid? Do they more than replace Yodlee nowadays where it's a SDK for people to scrap bank accounts? Like say if your an accounting app and need to import bank statements.

For some of Plaid's partners it is the point. Others are only using Plaid for a simple bank account verification.

Here is the list Fintech companies which use Plaid as published in the Visa Acquisition presentation. Many of these (like non-lenders) have no legitimate use for all that info.

Stash Dave N26 Monzo Acorns Chime MoneyLion Rainist Transferwise Robinhood Circle SoFi Revolut Etoro Clearscore Toss NuBank Square Cash Mint Coinbase Venmo Credit Karma

Re: Visa Buys Plaid

#306

Earlier quoted context omitted.

So a single point of failure then? It also means you are holding your cards on your time all the time you use your phone on the street, which is prime time for somebody to come and snag it out of your hand

it looks like a normal case, you can't see the cards. not a single point at all, it's just a couple cards in the slot.

It's still a single point of failure.

Re: Visa Buys Plaid

#307
post #276

Earlier quoted context omitted.

Like this one [1]? Seems that it is not necessarily better than SMS. [1] https://news.ycombinator.com/item?id=4156897

There is an actual, material difference between having no 2FA (guess passwords until you get in), SMS 2FA (have a human person call a phone provider and have the number switched), and token 2FA (given the physical device and a few hundred attempts, you're able to make another device that also authenticates). Saying you might as well not enable 2FA because a token cloning attack exists is ridiculous.

And it's not even an attack on the OTP token.

Re: Visa Buys Plaid

#308

Earlier quoted context omitted.

Same.

Are you trying to use a business account or something? Otherwise I have no clue.

I have both a personal and a business account, but the login is the same, and they fail at the login level, not after I'm authenticated. One cannot tell what sort of accounts are behind the account before you successfully log in.

Re: Visa Buys Plaid

#309
post #141

Slightly off topic, but worth highlighting. Privacy virtual card use Plaid (well at least the last time I looked at it a few months back). The integration was extremely questionable. They were faking the bank’s login page. So when you enter your credentials, it wasn’t the actual banks page. There was a github issue opened, and after several followed up complaints they blocked further commenting and the removed then t…

Yeah, isn't Plaid basically teaching users to fall for phishing attacks? As with any account, the only sane advice is to only enter your password for account X into the website or app for X. Which is the exact opposite of the expectation Plaid creates.

Also, it's one thing for me to let a third party withdraw money from my checking account (if I provide my account number), but that doesn't mean I want to give them the ability to do things like change my password, disable 2FA, read my transaction history, transfer money out of my other accounts, cancel my cards, and so on — which they can if they have my password. That's just insane.

Re: Visa Buys Plaid

#310

Earlier quoted context omitted.

I don't hear this type of criticism for Personal Capital or Mint, both of which collect credentials to catalog transactions.

HNers have been launching this criticism at Mint at least since I signed up for this website. https://hn.algolia.com/?q=mint+password

This is just a bunch of questions asking how Mint stores the credentials; in the majority of these posts, nobody seems to be passing judgment.
Post reply on HN