Live data from Hacker News

Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

finledger.com

71–80 of 257 posts

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#71
post #31
post #24

To everyone in this thread complaining that this is just Canada being Canada and trying to snuff out the upstarts... what the fuck are you going on about? I'm a US citizen and I want this screen scraping / credential sharing / whatever you want to call it to die in a fire already. Forcing banks to implement any sort of API access seems both preferable to the dumpster fire we have today, as well as more inviting to up…

This. As others mentioned, the whole point of an effort towards OpenBanking is that services like Plaid literally store your username/password in their system and impersonate you to do whatever they do. Any software dev worth their salt would instinctively know this is a big security no-no, so to have this happen with your banking credentials of all things and on such a large scale seems insane to me. An effort to im…

It's actually kind of crazy how a company was able to build a business out of this and get acquired while doing it, too. If someone would've pitched me the idea, I would've been like "it's doable, but it'll never be a viable business."

Goes to show what I know.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#72

Earlier quoted context omitted.

> Obviously no 2FA. Don't worry, you really aren't missing out on much security because the 2FA most banks implement just involves sending you an SMS.

The Canadian Revenue Agency started forcing SMS 2FA on online accounts recently

PayPal in Europe is doing SMS now too. They claim it's for "PSD2" compliance or something. But I already had TOTP 2FA ("Google Authenticator") enabled and I'd prefer to use that instead as it's much safer than SMS. That was never intended to carry secure information. Also, TOTP works even when I have my phone in airplane mode.

Strange thing is it seems to randomly ask for SMS or TOTP now, whichever it feels like at the time.

Still it's weird that an official standard mandates SMS 2FA when more secure methods are available.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#73

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

In the UK, which has implemented open banking already, you can use services like https://syncforynab.com/ (no affiliation, just a happy customer) to link your accounts to YNAB. Some challenger banks like Monzo and Starling allow you to set up webhooks for transactions so they're immediately available in YNAB through Sync for YNAB rather than having to use x-hourly syncs via open banking companies that are officially blessed by the big banks.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#74
post #31
post #24

To everyone in this thread complaining that this is just Canada being Canada and trying to snuff out the upstarts... what the fuck are you going on about? I'm a US citizen and I want this screen scraping / credential sharing / whatever you want to call it to die in a fire already. Forcing banks to implement any sort of API access seems both preferable to the dumpster fire we have today, as well as more inviting to up…

This. As others mentioned, the whole point of an effort towards OpenBanking is that services like Plaid literally store your username/password in their system and impersonate you to do whatever they do. Any software dev worth their salt would instinctively know this is a big security no-no, so to have this happen with your banking credentials of all things and on such a large scale seems insane to me. An effort to im…

It is not just the problem is password stored in 3rd party system. Occasionally an engineer has to look at the raw intercepted html data if the bank changes their login or data pages.

Intuit (via Quicken) and Microsoft Money were in a position to influence this - they required banks to give access to quicken servers.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#76

Earlier quoted context omitted.

> Obviously no 2FA. Don't worry, you really aren't missing out on much security because the 2FA most banks implement just involves sending you an SMS.

But sending you an SMS is a lot more security than no 2FA at all, right? I am aware of attacks that state/very sophisticated actors can use to intercept SMS messages but that's a serious edge case for a normal person, right?

Depends on where you are - a SIM swap attack is surprisingly easy to do in many places.

But more generally, a sophisticated actor doesn't have to be targeting you specifically. Many people assume that "nobody would put in so much effort to steal from me", but they don't have to be. A sophisticated attacker with the capability to intercept SMS would likely be casting a very wide net. Once people start noticing, they'll be locked out very soon, so they'll be aiming to "hack" as many people as possible.

You might just happen to be one of the N random people that happened to log into their bank on the day of the hack and the spreadsheet happened to be sorted by last login time. Hackers don't discriminate, so as long as you fit "SELECT from account WHERE balance > 0", you'll be on the target list.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#77
post #71
post #31

Earlier quoted context omitted.

This. As others mentioned, the whole point of an effort towards OpenBanking is that services like Plaid literally store your username/password in their system and impersonate you to do whatever they do. Any software dev worth their salt would instinctively know this is a big security no-no, so to have this happen with your banking credentials of all things and on such a large scale seems insane to me. An effort to im…

It's actually kind of crazy how a company was able to build a business out of this and get acquired while doing it, too. If someone would've pitched me the idea, I would've been like "it's doable, but it'll never be a viable business." Goes to show what I know.

I'm not personally surprised that you could find users to buy into this kind of product - I'm amazed that none of the US regulators came down on them hard and killed them dead five+ years ago.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#78
post #31
post #24

To everyone in this thread complaining that this is just Canada being Canada and trying to snuff out the upstarts... what the fuck are you going on about? I'm a US citizen and I want this screen scraping / credential sharing / whatever you want to call it to die in a fire already. Forcing banks to implement any sort of API access seems both preferable to the dumpster fire we have today, as well as more inviting to up…

This. As others mentioned, the whole point of an effort towards OpenBanking is that services like Plaid literally store your username/password in their system and impersonate you to do whatever they do. Any software dev worth their salt would instinctively know this is a big security no-no, so to have this happen with your banking credentials of all things and on such a large scale seems insane to me. An effort to im…

Worse than that plaid places the liability on you so that when their systems get hacked and you lose money it's your fault at your expense for giving them access.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#79
post #24

To everyone in this thread complaining that this is just Canada being Canada and trying to snuff out the upstarts... what the fuck are you going on about? I'm a US citizen and I want this screen scraping / credential sharing / whatever you want to call it to die in a fire already. Forcing banks to implement any sort of API access seems both preferable to the dumpster fire we have today, as well as more inviting to up…

I guess you're talking to me. I'm not arguing for screen scraping. I'm stating my experience as a Canadian that our oligopolies use legislation like this as a way to discourage competition, under the guise of helping users. And they rely on people like you to talk about how great it is that we're all getting a made in Canada open banking solution when what we'll really get is something that makes new entry impossible…

That's not happening in the UK, I don't think it's that difficult to conform to - especially not compared to the financial compliance stuff you're already dealing with as a bank! At the end of the day it's just 'use this API instead of rolling your own', really.

The reason I've soured on it is that it's not that bloody open at all. It should be called 'InteroperableBanking' or something.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#80
post #24

To everyone in this thread complaining that this is just Canada being Canada and trying to snuff out the upstarts... what the fuck are you going on about? I'm a US citizen and I want this screen scraping / credential sharing / whatever you want to call it to die in a fire already. Forcing banks to implement any sort of API access seems both preferable to the dumpster fire we have today, as well as more inviting to up…

18 years ago when working for a shipping company a lot of customers complained about the pain of setting up an address book again, so to help our salespeople entice them to give us their business I wrote some code so if you entered the username and password for one of the other companies it navigated inside that account and pulled all the addresses out. No one I spoke to had ever seen such magical wizardry before and I felt pretty thrilled. We never stored the username and password but I still wondered if we could somehow get into trouble. It amazes me so many people were so happy to use it. Many years later, I’ve faced multiple websites offering Plaid’s help to retrieve data (even Google Pay offers to log into your bank account) but I always refuse.
Post reply on HN