Live data from Hacker News

Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

finledger.com

61–70 of 257 posts

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#61
post #49

Earlier quoted context omitted.

Thunder Bay have its very own mobile carrier, which is quite a feat for a town of 100k people. https://www.tbaytel.net

I was born in Thunder Bay. :) Maybe Fort Frances would have been a better example, basically the cell and internet in Fort Frances was non-existent/didn't work 90% of the time till the province forced Tbay Tel & Shaw to service the region correctly, and we paid the same prices as folks in Tbay, and I'm sure it made little to no economic sense to be servicing that far up north at that time, but I'm sure glad they did.

[deleted]

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#62
post #24

To everyone in this thread complaining that this is just Canada being Canada and trying to snuff out the upstarts... what the fuck are you going on about? I'm a US citizen and I want this screen scraping / credential sharing / whatever you want to call it to die in a fire already. Forcing banks to implement any sort of API access seems both preferable to the dumpster fire we have today, as well as more inviting to up…

We have a system like this in Australia already. The benefit of it is its a read only system so if criminals get access to your api key, they can list your details out but they can't take your money or do much useful. So much better than giving a 3rd party your login details.

Doesn't Intuit use some read-only mechanism, allowing TurboTax to import your 1099 data? I hope it's read-only. Curious how it works.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#63
post #24

To everyone in this thread complaining that this is just Canada being Canada and trying to snuff out the upstarts... what the fuck are you going on about? I'm a US citizen and I want this screen scraping / credential sharing / whatever you want to call it to die in a fire already. Forcing banks to implement any sort of API access seems both preferable to the dumpster fire we have today, as well as more inviting to up…

I guess you're talking to me. I'm not arguing for screen scraping. I'm stating my experience as a Canadian that our oligopolies use legislation like this as a way to discourage competition, under the guise of helping users. And they rely on people like you to talk about how great it is that we're all getting a made in Canada open banking solution when what we'll really get is something that makes new entry impossible…

As another canadian, here's something that occurred to me recently: we like to sling around the oligopoly argument when talking about telecoms, but when I bothered to look a bit into it, rather than finding some tightly knit mafia-like boys club, what I found is that the landscape is quite fragmented and messy (e.g. look at the scope of Telus' operations in Ontario vs Quebec, or look at how Sasktel operates, or look at companies like Fibrestream)

The big telecom lobbying argument vs CRTC about how urban markets need to subsidize rural infrastructure costs is not something 95% of canadians like to hear, but it kinda makes sense (They say rural infra simply isn't cost effective because Canada is so expansive, but you expect high speed Internet access in your Muskoka cottage, right?)

Banking is kind of in a similar boat in the sense that it's an industry with economies of scale effect, so naturally there are going to be big players. Even smaller players like Tangerine need to make "big boy" investments like call centers. ICBC is another example of a bank that isn't the big 5 and yet has brick and mortar branches to serve a highly specific niche.

OpenBanking doesn't mean that TD et al somehow get to tighten the noose on smaller banks to their own advantage; it's actually on them to implement the APIs. If Tangerine can't keep up with other banks improving their technology, that's their own fault. What the whole thing means is that Plaid doesn't get to have root access to your banking.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#64
post #4

This sounds so futuristic which is awesome but at the same time banks like Tangerine, which otherwise I have nothing but praise for, don't even allow be to use a password more secure than a 4-6 digit numeric passcode. Obviously no 2FA. Sorry, that has little to do with the submission, I just had to vent about banks.

> Obviously no 2FA. Don't worry, you really aren't missing out on much security because the 2FA most banks implement just involves sending you an SMS.

The Canadian Revenue Agency started forcing SMS 2FA on online accounts recently

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#65

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

FWIW I use Schwab for banking and I was able to connect YNAB to Schwab without entering my password. It looks like Schwab supports read-only API access, and Plaid takes advantage of that to avoid needing your credentials.

As an added plus, you can keep 2FA enabled. Schwab does 2FA through an app so it's a touch above SMS-based 2FA (although only a single app is supported, Symantic VIP Access, rather than generic support for apps like Google Authenticator).

I also hate Plaid's model where you provide Plaid your credentials, and I've never entered my credentials into Plaid.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#66

Earlier quoted context omitted.

> Obviously no 2FA. Don't worry, you really aren't missing out on much security because the 2FA most banks implement just involves sending you an SMS.

But sending you an SMS is a lot more security than no 2FA at all, right? I am aware of attacks that state/very sophisticated actors can use to intercept SMS messages but that's a serious edge case for a normal person, right?

No, it’s a fairly simple social engineering attack and the telco customer service will do it for you at the cost of a SIM card.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#67
post #24

To everyone in this thread complaining that this is just Canada being Canada and trying to snuff out the upstarts... what the fuck are you going on about? I'm a US citizen and I want this screen scraping / credential sharing / whatever you want to call it to die in a fire already. Forcing banks to implement any sort of API access seems both preferable to the dumpster fire we have today, as well as more inviting to up…

We have a system like this in Australia already. The benefit of it is its a read only system so if criminals get access to your api key, they can list your details out but they can't take your money or do much useful. So much better than giving a 3rd party your login details.

Unfortunately, Australia's APIs (for anything useful), also have a high barrier to entry for just anyone looking to build an app on top of them:

> To access consumer APIs, you'll need to be accredited by the ACCC and get the customer's consent.

Accreditation [0] has a lot of requirements - my paying child support was considered disqualifying. Parts of accreditation make sense, and should keep things more secure, other parts... Make less.

Mandatory AFCA membership, for example, only makes sense at first glance. The ombudsman can still field complaints without it. Consumer Rights still exist without it. However, the mandatory membership is being used by the ACCC as a replacement for yearly auditing.

[0] https://www.accc.gov.au/focus-areas/consumer-data-right-cdr-...

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#68

Earlier quoted context omitted.

> Obviously no 2FA. Don't worry, you really aren't missing out on much security because the 2FA most banks implement just involves sending you an SMS.

But sending you an SMS is a lot more security than no 2FA at all, right? I am aware of attacks that state/very sophisticated actors can use to intercept SMS messages but that's a serious edge case for a normal person, right?

It's better than nothing, I just wish it wasn't conflated with effective 2FA.

It isn't just state-level or sophisticated actors, it's anyone who is dumb enough to commit fraud with computers or via unauthorized access to telecom networks, which includes a lot of fraud rings.

According to The Verge[1], such services are even advertised on illicit marketplaces, so anyone with some Bitcoin and the Tor Browser can potentially be your adversary in such an attack.

[1] https://www.theverge.com/2017/6/13/15794292/ss7-hack-dark-we...

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#69

Earlier quoted context omitted.

We have a system like this in Australia already. The benefit of it is its a read only system so if criminals get access to your api key, they can list your details out but they can't take your money or do much useful. So much better than giving a 3rd party your login details.

Can you share the systems that provide read only API access please? I've tried to find services like them numerous times over the years but have failed at piercing the cloud of opaqueness that seems to surround banking.

OpenBanking at some of the big banks:

+ CommonWealth Bank - https://www.commbank.com.au/developer

+ NAB - https://developer.nab.com.au/docs/open-banking

+ Westpac - https://www.westpac.com.au/about-westpac/innovation/open-ban...

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#70
As a developer living in a country that has fully implemented "Open Banking", here's a quick setting of expectations for Canadian developers so they don't get too excited as I did when this was first being introduced.

Open Banking is not, in fact, open in almost any sense of the world. It is standardised and the standards are freely available ("open"), but other than that, you still need to have an official "blessing" to actually access a production API endpoint (even for your own account), you need a legal entity that has some highly specific and entirely meaningless certificates that are hard (and potentially expensive) to get and even after all of that, you'll still need to negotiate access with each bank individually.

What I imagined when I first heard of "Open Banking" was a public OAuth2 endpoint where I can grant my custom script access to just my bank balance and transaction history (possibly with a change webhook) and have it update my finance tracking database.

The "open" part is only relevant to the banks, since they don't have to pay royalties for the standard implementing the APIs. For the rest of us, it might as well be SS7.

Post reply on HN