Live data from Hacker News

Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

justice.gov

261–270 of 295 posts

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#261
post #126

Earlier quoted context omitted.

Yeah, banks could have done oauth2 years ago but it never happened.

Open Banking in the UK does that now.

Not really, considering it doesn't enforce a single, consistent API, so most companies will still use something like TrueLayer (our local equivalent of Plaid) to aggregate all these separate APIs into a single consistent one.

Furthermore, "open" banking is very misleading because it's only open to corporations with deep pockets to obtain an AISP license/certification*, but doesn't even allow the account holder to gain API access to their own account. Unless you're lucky enough to be with a modern bank that provides that as a feature (which is legally separate from Open Banking, though often it's the same API), your only workaround is to sign up for TrueLayer yourself just to access your own account through them.

* given the "deep pockets" requirement, it almost forces all the account aggregator apps/services (Emma, Yolt, etc) to have a somewhat scummy business model and monetize the captured data. Wouldn't it have been nicer that you didn't need deep pockets to gain read-only access, so that an indie developer could make such an account aggregator and not have to resort to a scummy business model to fund the certification/compliance expenses?

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#262

Earlier quoted context omitted.

Open Banking is the result of the EU PSD2, so unfortunately is no longer guaranteed in the UK. UK firms have already lost passporting rights, and it's yet unclear whether the UK will align with EU regulation going forward.

I think it would be highly unlikely the UK would regress on open banking. It's been a cornerstone of a lot of govt policy for banking.

I guess the question is what you mean by "open banking". Initially, in the UK, that phrase referred to the FCA's implementation of the PSD2 requirement for banks to allow a secure mechanism of access to third parties. I think that this definition of open banking has already regressed post-Brexit, from the absence of passporting. UK firms and banks are no longer able to interoperate with EU firms and banks, and PSD2 no longer applies to them.

Another definition may be domestic API access to bank accounts, which I agree will continue to be policy in the UK. It won't be PSD2 open banking, though.

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#263
post #250

Earlier quoted context omitted.

It works in the UK where open banking is regulated by the FCA: https://www.openbanking.org.uk/customers/what-is-open-bankin...

It doesn't really work. Open Banking doesn't seem to enforce a consistent API which means you either need to implement a client for each bank (and their data model) individually or use something like Plaid (in the UK our equivalent is TrueLayer) to aggregate all the different banks into a single API.

PSD2 doesn't even mandate APIs as the mechanism of access!

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#264
post #126

Earlier quoted context omitted.

Open Banking in the UK does that now.

Not really, considering it doesn't enforce a single, consistent API, so most companies will still use something like TrueLayer (our local equivalent of Plaid) to aggregate all these separate APIs into a single consistent one. Furthermore, "open" banking is very misleading because it's only open to corporations with deep pockets to obtain an AISP license/certification*, but doesn't even allow the account holder to gai…

> Not really, considering it doesn't enforce a single, consistent API, so most companies will still use something like TrueLayer (our local equivalent of Plaid) to aggregate all these separate APIs into a single consistent one.

That's not quite true. The CMA9 have to follow the Open Banking spec, and some other non-cma9 banks have decided to follow the same spec. In practise, there's some deviation from the spec between the banks (in part, due to ambiguity in the spec), but it's not like they're all pulling their own spec out of the air.

> Furthermore, "open" banking is very misleading because it's only open to corporations with deep pockets to obtain an AISP license/certification*, but doesn't even allow the account holder to gain API access to their own account. Unless you're lucky enough to be with a modern bank that provides that as a feature (which is legally separate from Open Banking, though often it's the same API), your only workaround is to sign up for TrueLayer yourself just to access your own account through them.

The 'deep pockets' don't need to be as deep as implied. I think it's <~£3k. It's not something that only big companies can afford, but I agree, it's not something that an individual would use to test out an idea, which would push them towards something like TrueLayer.

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#265

Earlier quoted context omitted.

I think it would be highly unlikely the UK would regress on open banking. It's been a cornerstone of a lot of govt policy for banking.

I guess the question is what you mean by "open banking". Initially, in the UK, that phrase referred to the FCA's implementation of the PSD2 requirement for banks to allow a secure mechanism of access to third parties. I think that this definition of open banking has already regressed post-Brexit, from the absence of passporting. UK firms and banks are no longer able to interoperate with EU firms and banks, and PSD2 n…

PSD2 still applies. That was integrated into U.K. law long before Brexit. It would take an act of parliament to unwind.

Additionally the U.K. has generally been on the leading edge of open banking, which is why our standards weren’t identical to the EUs for a while. It’s going nowhere, and pass-porting will make no difference.

The only real impact of Brexit is the open banking entities will need to register separately in the U.K. and the EU, and be subject to two different regulators. But that’s just paperwork for the most part.

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#266

Earlier quoted context omitted.

I don't even think it's a data issue. He literally says they bought Plaid because they're a threat. That's textbook anti-competitive behavior and a big smoking gun when it comes to anti-trust cases.

I'm not informed when it comes to anti-competitive legislation, but don't companies like Google do this sort of thing all the time?

Yes, and they didn't invent the practice. Standard Oil brought competitors into its fold in order to maintain its pricing power and dominate the petroleum market.

As with most questionable business practices, they're not wise to be transparent about their true reasons for doing it, and inevitably they admit to their true reasons anyway.

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#267

Earlier quoted context omitted.

I guess the question is what you mean by "open banking". Initially, in the UK, that phrase referred to the FCA's implementation of the PSD2 requirement for banks to allow a secure mechanism of access to third parties. I think that this definition of open banking has already regressed post-Brexit, from the absence of passporting. UK firms and banks are no longer able to interoperate with EU firms and banks, and PSD2 n…

PSD2 still applies. That was integrated into U.K. law long before Brexit. It would take an act of parliament to unwind. Additionally the U.K. has generally been on the leading edge of open banking, which is why our standards weren’t identical to the EUs for a while. It’s going nowhere, and pass-porting will make no difference. The only real impact of Brexit is the open banking entities will need to register separatel…

> PSD2 still applies. That was integrated into U.K. law long before Brexit. It would take an act of parliament to unwind.

It's not that simple. The FCA is no longer an EEA National Competent Authority and UK Third Party Providers must register with an EEA NCA to continue to operate in the EEA. Domestic legislation which put PSD2 in force is of course still UK law, and domestic TPPs and Account Servicing Payment Service Providers can continue to operate together (even using the same eiDAS certs), but they cannot engage in open banking with the rest of the EU/EEA.

PSD2 and its supporting institutions (EBA, EPC, ECJ) no longer apply to the UK.

> Additionally the U.K. has generally been on the leading edge of open banking, which is why our standards weren’t identical to the EUs for a while. It’s going nowhere, and pass-porting will make no difference.

Internally, maybe, but UK TPPs and ASPSPs can no longer interoperate with EU/EEA TPPs and ASPSPs unless they register with an EU/EEA NCA, and thus become subject to EU Directives. Again it comes back to your definition of "open banking". If you mean only UK banks and firms being able to operate an open banking scheme, then you are correct that this will continue. If you mean open banking as defined by PSD2, it has already come to an end in the UK.

> The only real impact of Brexit is the open banking entities will need to register separately in the U.K. and the EU, and be subject to two different regulators. But that’s just paperwork for the most part.

So either UK TPPs and ASPSPs have to abide by EU Directives (if possible - the UK legislature may diverge from the EU in unreconcilable ways), or the UK has to maintain alignment with the EU indefinitely. Doesn't seem like just paperwork to me.

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#268
post #75

I’ve some friends that works there, so I’m hesitant to say this, because I’m sorry for them, but Plaid is a terrible company. Their main product scrapes financial data from unsuspecting users that simply think they’re making a bank transfer and not signing away the privacy and security of their banking, 401k and trading information. https://twitter.com/seanieb/status/1298871471645761537?s=20

Blame the banks for dragging their feet and not making proper APIs for these companies to use instead of screen scraping.

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#269

Earlier quoted context omitted.

I don't even think it's a data issue. He literally says they bought Plaid because they're a threat. That's textbook anti-competitive behavior and a big smoking gun when it comes to anti-trust cases.

I'm not informed when it comes to anti-competitive legislation, but don't companies like Google do this sort of thing all the time?

I'm a layman, so take this with a grain of salt, but here's the basic legal theory...

In antitrust law, intent matters. If your primary motivating intent is to make the market less competitive, that's what gets the book thrown at you. That's why it can be so hard to prosecute antitrust, because it's pretty easy to lie your way out as long as there's no direct proof of intent.

Let's take Facebook's acquisition of Instagram. Did they buy Instagram because they saw Instagram as a threat, or did they buy Instagram because they wanted to acquire their talent and improve their product? For a long time, you could argue it was the latter case, which warded off antitrust suits. Recently, some emails came to light where they explicitly talked about taking out Instagram because they were beginning to pose a threat. Now there's a smoking gun and a strong case to be made, which may well be prosecuted in the near future.

Re: Visa and Plaid Abandon Merger After Antitrust Division’s Suit to Block

#270
post #126

Earlier quoted context omitted.

Open Banking in the UK does that now.

Not really, considering it doesn't enforce a single, consistent API, so most companies will still use something like TrueLayer (our local equivalent of Plaid) to aggregate all these separate APIs into a single consistent one. Furthermore, "open" banking is very misleading because it's only open to corporations with deep pockets to obtain an AISP license/certification*, but doesn't even allow the account holder to gai…

Yes, it's only 'open' to FCA registered entities, which is an entirely reasonable requirement given how easy it is for scammers to get people to give away the keys to the kingdom.

So no, it wouldn't have been nicer, it would have been a scammers delight.

And yes, it does require a consistent API, thought it's perhaps open to a bit too much interpretation.

Post reply on HN