Live data from Hacker News

Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

justice.gov

251–260 of 295 posts

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#251

Earlier quoted context omitted.

I understand the situation. Another of Plaid's investors is Goldman Sachs. I naively assumed that Plaid's ability to build their product was likely based on access to private APIs available to them based on their relationships and backing. If someone came to me and asked me to build what Plaid has built, I would decline the work. I would assume that impersonating a bank would be illegal. I would assume that the banks…

Plaid does have real integrations with some institutions, using OAuth and the works. The list is relatively miniscule compared to the vast majority of institutions that still consider customer data their asset and not their customers'.

On the other hand, Plaid’s behaviour means that your data is not yours either, but is up for grabs by a 3rd party for which you may not have given consent to. Plaid is no Robin Hood (the story not the app) here.

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#252
post #75

I’ve some friends that works there, so I’m hesitant to say this, because I’m sorry for them, but Plaid is a terrible company. Their main product scrapes financial data from unsuspecting users that simply think they’re making a bank transfer and not signing away the privacy and security of their banking, 401k and trading information. https://twitter.com/seanieb/status/1298871471645761537?s=20

I once went to use plaid to apply for a mortgage on one of the new fancy broker platforms. It asked me to type my login credentials.. sketchy , but alright banks and mortgage companies seem to trust them? Then they asked me to disable 2FA on my account and at that point it was indistinguishable from a phishing attack to me. I noped out and changed my bank password immediately.

This is why a standard API is needed, like Open Banking in the UK. When I use a third party app, the access request is redirected to my bank app and authorisation is granted there. At this point it is explicit what data the third party will require. Once authorised, I’m redirected back to the third party’s app. At no point have I given my credentials. This must be renewed every 90 days. Furthermore I can view what apps have access to my account and can revoke this access at any time.

PS Yes I know people like Ben Thompson [1] and even the US Treasury (mentioned in the same link) advocated for a private solution like Plaid (and nearly by extension Visa), but seriously this seems like something that needs to be government regulated to prevent incentives for selling user data.

[1] https://stratechery.com/2020/visa-plaid-networks-and-jobs/

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#253

Earlier quoted context omitted.

They are getting sued by TD Bank for this very reason: > The bank said in the court filings that the interface "dupes" consumers into believing they are entering personal information into TD Bank's trusted platform. > "In reality, however, consumers are unwittingly giving their login credentials to the defendant, who takes the information, stores it on its servers, and uses it to mine consumers' bank records for valu…

I am sure I will be called naive, but this is shocking to me. I assumed that Plaid was integrating with the banks and not doing this sort of thing because of the people associated with Plaid. Their seed round included Spark Capital and Google Ventures. Their most recent round included Mary Meeker and Andreessen Horowitz. [1] These investors have reputations to protect. This type of thing would certainly come out in d…

It’s clear as day in the privacy policy. You did click on the privacy policy link and read through it right?

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#254

Earlier quoted context omitted.

You're right, they aren't the first. That said, when I use accounting software, it's pretty obvious to me that I am going to be sharing my transaction history with the accounting software. When I connect my bank account to Venmo, it is absolutely not obvious to me that I'm sharing my entire transaction history with Plaid. Replicating the appearance of my bank's login screens is critical to the illusion. Even if I did…

Fortunately, Plaid doesn’t sell your transaction history, so this isn’t a concern.

READ: https://plaid.com/legal/#consumers

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#255
post #162
post #159

Earlier quoted context omitted.

Web scraping is not illegal per se. Though it may be against the specific terms of service of the site you are scraping.

that was before the 2018 ruling this was back in 2012, I remember Craigslist sued someone for scraping under CFAA. Thanks to EFF, this scummy tactic used to kill Aaron Swartz is no more.

You are misremembering. CFAA defines criminal acts not civil, so Craigslist could not sue someone under the CFAA. The DA would have to bring charges first and then the civil suit by Craigslist would reference the criminal suit.

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#256
post #250

Earlier quoted context omitted.

> There are organizations and companies that are trying to do this legitimately, through open standards and real incentives to both FIs and customers to share information in exchanges: That is never going to work. The reason the world works the way it works is because banks dont want to give easy access, so market opportunity for companies like Plaid exists.

It works in the UK where open banking is regulated by the FCA: https://www.openbanking.org.uk/customers/what-is-open-bankin...

Open Banking is the result of the EU PSD2, so unfortunately is no longer guaranteed in the UK. UK firms have already lost passporting rights, and it's yet unclear whether the UK will align with EU regulation going forward.

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#257
post #250

Earlier quoted context omitted.

It works in the UK where open banking is regulated by the FCA: https://www.openbanking.org.uk/customers/what-is-open-bankin...

Open Banking is the result of the EU PSD2, so unfortunately is no longer guaranteed in the UK. UK firms have already lost passporting rights, and it's yet unclear whether the UK will align with EU regulation going forward.

I think it would be highly unlikely the UK would regress on open banking. It's been a cornerstone of a lot of govt policy for banking.

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#258
post #75

I’ve some friends that works there, so I’m hesitant to say this, because I’m sorry for them, but Plaid is a terrible company. Their main product scrapes financial data from unsuspecting users that simply think they’re making a bank transfer and not signing away the privacy and security of their banking, 401k and trading information. https://twitter.com/seanieb/status/1298871471645761537?s=20

I can confirm this as I currently use Plaid in a few projects. People have no idea what they are signing up for when they authorize this. It's possible to get near real time transaction data from somoene's bank account as well as monitor their account balances for any linked account essentially in perpetuity. With this data it's possible to back in to a lot of behaviors about someone's life. All of that is handed to any firm you authorize to link your bank account.

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#259
post #250

Earlier quoted context omitted.

> There are organizations and companies that are trying to do this legitimately, through open standards and real incentives to both FIs and customers to share information in exchanges: That is never going to work. The reason the world works the way it works is because banks dont want to give easy access, so market opportunity for companies like Plaid exists.

It works in the UK where open banking is regulated by the FCA: https://www.openbanking.org.uk/customers/what-is-open-bankin...

It doesn't really work. Open Banking doesn't seem to enforce a consistent API which means you either need to implement a client for each bank (and their data model) individually or use something like Plaid (in the UK our equivalent is TrueLayer) to aggregate all the different banks into a single API.

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#260
post #251

Earlier quoted context omitted.

Plaid does have real integrations with some institutions, using OAuth and the works. The list is relatively miniscule compared to the vast majority of institutions that still consider customer data their asset and not their customers'.

On the other hand, Plaid’s behaviour means that your data is not yours either, but is up for grabs by a 3rd party for which you may not have given consent to. Plaid is no Robin Hood (the story not the app) here.

Plaid is equivalent to a carrier, right? They merely provide the data to their client (whatever service/app you're signing into) and it's up to that client to decide how to use it.
Post reply on HN