Live data from Hacker News

Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

finledger.com

111–120 of 257 posts

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#111
post #110
post #100

Earlier quoted context omitted.

For future reference the tip off is that YNAB/Plaid asks for your bank account's username and password directly. If they were using some proper API, you'd be redirected to an Authorization page on your bank's domain where you could review the requested permissions and the app requesting, and then choose to grant it.

Exactly this, Plaid "kindly requests" you violate the ToS you have with the bank and hand over the keys to your finances. I have never noped out of anything so hard.

It would be interesting if an attorney general went after Plaid for CFAA violation.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#112

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

In the UK, which has implemented open banking already, you can use services like https://syncforynab.com/ (no affiliation, just a happy customer) to link your accounts to YNAB. Some challenger banks like Monzo and Starling allow you to set up webhooks for transactions so they're immediately available in YNAB through Sync for YNAB rather than having to use x-hourly syncs via open banking companies that are officially…

I recently moved back to the US after 5 years in the UK. It’s hard to overstate how awesome Monzo is, and how much of a steaming pile of 3rd world shit banking in the US is.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#113

Earlier quoted context omitted.

Depends on where you are - a SIM swap attack is surprisingly easy to do in many places. But more generally, a sophisticated actor doesn't have to be targeting you specifically. Many people assume that "nobody would put in so much effort to steal from me ", but they don't have to be. A sophisticated attacker with the capability to intercept SMS would likely be casting a very wide net. Once people start noticing, they'…

This argument seems strange to me.. how many attacks are by someone literally armed with a customer list from a financial institution? The "casting a wide net" seems directly opposed to the effort involved in a SMS intercept attack which requires significant resources. I don't see a practical circumstance where this is a reasonable risk I guess. I just don't know. I would love an article-length explainer out there so…

A targetted SMS interception attack looks like something something SS7 or SIM swap/social engineering, but a wide net attack looks like pwn the telco and get ssh access to an SMS gateway (or logs, or a database with content), or an aggregator, or a middleman SMS provider between aggregator(s) and carriers, or posing as a legit (or grey route) middleman and getting in routing and then snooping on stuff. Or just a highly priviledge position at a carrier or sms aggregator.

If your wide net lets you see 2FA codes, sometimes you can do stuff.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#114
post #107

Earlier quoted context omitted.

> The big telecom lobbying argument vs CRTC about how urban markets need to subsidize rural infrastructure costs is not something 95% of canadians like to hear, but it kinda makes sense (They say rural infra simply isn't cost effective because Canada is so expansive, but you expect high speed Internet access in your Muskoka cottage, right?) That still doesn't explain why internet service is way more expensive in Cana…

I don't mean this to be crass, I presume you've never driven across Canada then? I suspect if you had, you'd very soon realize why it's so expensive. 11 people per square mile, the same as Botswana, except at least in Botswana you can just drive in a straight line for hours, and you don't have snow salt and freezing temperatures to contend with. If a team from Rogers in Toronto had to go to Kenora Ontario to service…

Except what matters is the density distribution. 85% of Canadians live within 100 miles of the US border, for instance.

https://www.vox.com/2016/5/5/11584064/canada-population-map

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#115

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them.

It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#116
post #92

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

> YNAB (You Need A Budget) use services like Plaid to...take my username and password and impersonate me to get my banking data WHAT. THE. F. I'm a longtime, happy YNAB user. I had no idea this was going on until just now. I always just assumed there were secure APIs used to import my data. YNAB's Capital One "integration" stopped working a few years ago (possibly because they cracked down on screen scraping?) and I…

You gave them your bank account login credentials and you didn't think it was strange?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#117
post #107

Earlier quoted context omitted.

I don't mean this to be crass, I presume you've never driven across Canada then? I suspect if you had, you'd very soon realize why it's so expensive. 11 people per square mile, the same as Botswana, except at least in Botswana you can just drive in a straight line for hours, and you don't have snow salt and freezing temperatures to contend with. If a team from Rogers in Toronto had to go to Kenora Ontario to service…

Except what matters is the density distribution. 85% of Canadians live within 100 miles of the US border, for instance. https://www.vox.com/2016/5/5/11584064/canada-population-map

Take the population distribution map and throw it on top of the telecommunications coverage map and put it on a 20 year timeline, I suspect you'll have the answer to your question, as I explained, Kenora is not near Toronto, it's many many many many many many many hours of driving away, places that are literally physically difficult to get to.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#118

As a developer living in a country that has fully implemented "Open Banking", here's a quick setting of expectations for Canadian developers so they don't get too excited as I did when this was first being introduced. Open Banking is not, in fact, open in almost any sense of the world. It is standardised and the standards are freely available ("open"), but other than that, you still need to have an official "blessing…

Sounds like the situation in Australia, which NZ sounds like they’re copying.

Yep, I was excited that I might be able to access my banking data using APIs in NZ, then I found this:

https://www.apicentre.paymentsnz.co.nz/join/api-community-co...

So it's "free for 12 months", but the idea is that I build or create an "innovation".

Not interested, I just want APIs for my data, I'm not interested in building a SaaS, I don't want that kind of responsibility for other people's data.

Back to using my personally developed scraper, driven by puppeteer.

Side-benefits, I can and have adapted my scraper to also pull my data from other institutions, like investments and retirement accounts, and dump it into a database as JSON and normalized form.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#119

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

Edit: Never mind, I was confusing the use of Plaid for linking accounts (like Robinhood does) with its use to actually monitor accounts (like YNAB).

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#120

Earlier quoted context omitted.

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

Edit: Never mind, I was confusing the use of Plaid for linking accounts (like Robinhood does) with its use to actually monitor accounts (like YNAB).

How would they know about that transaction I made today without my password?
Post reply on HN