Live data from Hacker News

Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

finledger.com

121–130 of 257 posts

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#121
post #111
post #110

Earlier quoted context omitted.

Exactly this, Plaid "kindly requests" you violate the ToS you have with the bank and hand over the keys to your finances. I have never noped out of anything so hard.

It would be interesting if an attorney general went after Plaid for CFAA violation.

I'm conflicted on the issue. Plaid only has to do this insane screen scraping because there's no other way to get my own financial data. The details of how it's done pains me, but I also think I should have freedom of choice with my data.

IMHO, the Canadian proposal seems like the ideal solution. Force the banks to offer a secure and more efficient way for consumers to access their open banking data. (This will also massively lower the barrier to entry for another Plaid competitor)

edit: Plaid's docs mention that banks may detect and block this screen-scraping. They frame it as the bank limiting "your ability to access your financial information", which I think is somewhat valid. They're quite obtuse about the whole scraping thing though: https://plaid.com/trouble-connecting/#:~:text=Your%20financi...

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#122

Earlier quoted context omitted.

> Obviously no 2FA. Don't worry, you really aren't missing out on much security because the 2FA most banks implement just involves sending you an SMS.

But sending you an SMS is a lot more security than no 2FA at all, right? I am aware of attacks that state/very sophisticated actors can use to intercept SMS messages but that's a serious edge case for a normal person, right?

It's not secure at all, as some services (PayPal!) Allow password reset via SMS to your regitered mobile number. So if someone even has control of your mobile number via sim swap for 5 minutes they gain full control of your paypal acct. Heard of enough incidents of this earlier this year through one of the Canadian prepaid mobile flanker brands...

Paypal makes it hard to remove a mobile number from your account once it's on there too...

If a bank "MUST" have a phone number, I lean towards providing my good ol landline number since in theory thats a "little" harder to instantly take over or port out.

Worthwhile to "test" what it takes to reset a password on your various critical services...

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#123
post #24

To everyone in this thread complaining that this is just Canada being Canada and trying to snuff out the upstarts... what the fuck are you going on about? I'm a US citizen and I want this screen scraping / credential sharing / whatever you want to call it to die in a fire already. Forcing banks to implement any sort of API access seems both preferable to the dumpster fire we have today, as well as more inviting to up…

I guess you're talking to me. I'm not arguing for screen scraping. I'm stating my experience as a Canadian that our oligopolies use legislation like this as a way to discourage competition, under the guise of helping users. And they rely on people like you to talk about how great it is that we're all getting a made in Canada open banking solution when what we'll really get is something that makes new entry impossible…

Not a loosing battle; let's keep the discussion; but honestly I see situations where a oligopoly is preferred.

I lived in states. I banked in First bank of Fairmont ... yes, a city of 11,500 people had its own bank. I could not do ANYthing outside of city. This was a while back of course, but even today that the notion that there are over 5000 banks in USA (down from way over 10k), with complicated inter-state financing laws, from everything I can hear and understand from my USA friends and family, is discouraging both competition and functionality/convenience/sanity, and seems like we are constantly 5-10 years ahead in Canada with basics like Interac, PIN, Chip, Contactless, Interac email transfer, etc. Basically, USA banking system is as strange to me as their health / insurance system.

A bit like, I enjoyed it when Netflix was a monopoly and I could get anything I wanted there. I don't like the "competition" we have now with myriad streaming services that don't interoperate and have different systems and oh yes all want my money.

I guess I am curious: what should I be on the lookout, as a Canadian, that I am missing in our banking system compared to USA? What should I be hopeful a new entry would give me?

(and note, I am talking about banking sector for myself as ignorant consumer; telecom is a whole other ballgame for a myriad different reasons and I'll 100% agree is an area where we are lagging).

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#124
post #81

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

It’s worse than that. I assume Plaid doesn’t scrape bank sites and rely on 3rd parties to bypass the EULAs on bank sites.

Hi! I work at Plaid. This is false. We do not do that.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#125
post #4

This sounds so futuristic which is awesome but at the same time banks like Tangerine, which otherwise I have nothing but praise for, don't even allow be to use a password more secure than a 4-6 digit numeric passcode. Obviously no 2FA. Sorry, that has little to do with the submission, I just had to vent about banks.

With Tangerine I have set up the secret question thing where my answers are secure passwords generated with my password manager. Their login asks for the secure question answer before the 4-6 digit useless pin entry, so it has that going for it at least. I refuse to set up SMS based 2FA.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#126
post #81

Earlier quoted context omitted.

It’s worse than that. I assume Plaid doesn’t scrape bank sites and rely on 3rd parties to bypass the EULAs on bank sites.

can you please elaborate? this is quite the accusation

It is something I heard working in fintech, a lot around security, that the aggregators rely on 3rd party scrapers. Not plaid specific.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#127
post #81

Earlier quoted context omitted.

It’s worse than that. I assume Plaid doesn’t scrape bank sites and rely on 3rd parties to bypass the EULAs on bank sites.

Hi! I work at Plaid. This is false. We do not do that.

Ever? That was always the rumor on how aggregators could fix scraping within a day of major changes.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#128

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

This is FUD. Lots of Plaid-based connections only allow reads. This is a regulated industry, and the fallout reputationally might be tough, but consumers are well-protected.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#129
post #128

Earlier quoted context omitted.

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

This is FUD. Lots of Plaid-based connections only allow reads. This is a regulated industry, and the fallout reputationally might be tough, but consumers are well-protected.

How is that enforced? What is the technical basis that enforces read-only access using user/password auth? Especially since that user/password auth is used by an end user to do "write"-type actions?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#130
post #128

Earlier quoted context omitted.

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

This is FUD. Lots of Plaid-based connections only allow reads. This is a regulated industry, and the fallout reputationally might be tough, but consumers are well-protected.

Is it, though? I’ve given Plaid the user name and password to my bank account. The same set of credentials that I use to log in, to pay bills, transfer money, etc. Plaid stores this information for future use in some sort of reversible encryption. So now we trust Plaid to keep both their data set of user names and encrypted passwords secure, and also to keep their decryption keys secure. Forget that noise. Like the previous commenter , they’re one breach away from exposing millions of bank account credentials. It doesn’t matter if the Plaid API is read only for the integration side - somebody has MY credentials, and that’s not read only.
Post reply on HN