But this tidbit struck me as hilariously out of touch:
> Let's imagine your bank let you sign in to 3rd party services in a similar manner. How many people would click through on "Let ACME corp act on your behalf on your Citibank Account". I think most people would be super scared of permissions like that. Instead they'd want very specific permission like, only permission to deposit money, or only permission to read the balance, or only permission to read transactions, etc...
It is so, so much worse than that. Most banks don’t even provide OAuth APIs, so to hack around this third parties just straight up ask for your bank username and bank password so that they can turn around and log into that site and scrape the HTML UIs that come back from logging in.
“I think most people would be super scared of that.” No doubt these people exist (hello!) but like, there’s a whole industry built around this.[1] Possibly the banking example is not the best piece of supporting evidence for the article’s claim.