Live data from Hacker News

Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

finledger.com

131–140 of 257 posts

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#131

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

I'm pretty salty about this. It's totally unethical, they knew it wasn't legal, and yet... they're going to be OK outside the fine?

Why do we bother being ethical when nobody besides us gives a shit outside a slap on the wrist?

You know how many people thought of Plaid before it was a thing, then rightfully wrote it off as "don't attempt"? What kind of sick precedent does this set?

Why do I even bother caring.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#132
post #121
post #111

Earlier quoted context omitted.

It would be interesting if an attorney general went after Plaid for CFAA violation.

I'm conflicted on the issue. Plaid only has to do this insane screen scraping because there's no other way to get my own financial data. The details of how it's done pains me, but I also think I should have freedom of choice with my data. IMHO, the Canadian proposal seems like the ideal solution. Force the banks to offer a secure and more efficient way for consumers to access their open banking data. (This will also…

I'm not conflicted on it at all. Plaid might need to do this for them to work, but there's nothing that makes Plaid required for anything you do with your banking. People keep mistaking convenience for necessity, and that's how we keep ending up with hacked-together services that leak everyone's info and worse.

I'd rather have no convenience than a convenience that hands off the keys to my life behind my back. And so should the rest of us.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#133

Earlier quoted context omitted.

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

I'm pretty salty about this. It's totally unethical, they knew it wasn't legal, and yet... they're going to be OK outside the fine? Why do we bother being ethical when nobody besides us gives a shit outside a slap on the wrist? You know how many people thought of Plaid before it was a thing, then rightfully wrote it off as "don't attempt"? What kind of sick precedent does this set? Why do I even bother caring.

You already know the answer. Ask forgiveness not permission, move fast and break things.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#134
post #128

Earlier quoted context omitted.

This is FUD. Lots of Plaid-based connections only allow reads. This is a regulated industry, and the fallout reputationally might be tough, but consumers are well-protected.

How is that enforced? What is the technical basis that enforces read-only access using user/password auth? Especially since that user/password auth is used by an end user to do "write"-type actions?

Read-only access is not possible. By handing over the credentials you are handing over write access. You are correct.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#135
post #92

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

> YNAB (You Need A Budget) use services like Plaid to...take my username and password and impersonate me to get my banking data WHAT. THE. F. I'm a longtime, happy YNAB user. I had no idea this was going on until just now. I always just assumed there were secure APIs used to import my data. YNAB's Capital One "integration" stopped working a few years ago (possibly because they cracked down on screen scraping?) and I…

Hi! I work at Plaid. We’re strong advocates for API-based connectivity -- our goal is for 75% of our traffic to be committed to APIs by the end of the year. As part of that, we've actually converted our integration with Capital One to be 100% API-based and use OAuth for authentication. You can read more here: https://www.capitalone.com/about/newsroom/data-sharing-agree...

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#136
post #128

Earlier quoted context omitted.

This is FUD. Lots of Plaid-based connections only allow reads. This is a regulated industry, and the fallout reputationally might be tough, but consumers are well-protected.

Is it, though? I’ve given Plaid the user name and password to my bank account. The same set of credentials that I use to log in, to pay bills, transfer money, etc. Plaid stores this information for future use in some sort of reversible encryption. So now we trust Plaid to keep both their data set of user names and encrypted passwords secure, and also to keep their decryption keys secure. Forget that noise. Like the p…

Eh, it’s herd security. Hackers with credentials may pick off a few people’s accounts, but the odds of you being hit are low since it’s a hard problem to scale and there’s so many targets.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#137
post #92

Earlier quoted context omitted.

> YNAB (You Need A Budget) use services like Plaid to...take my username and password and impersonate me to get my banking data WHAT. THE. F. I'm a longtime, happy YNAB user. I had no idea this was going on until just now. I always just assumed there were secure APIs used to import my data. YNAB's Capital One "integration" stopped working a few years ago (possibly because they cracked down on screen scraping?) and I…

Hi! I work at Plaid. We’re strong advocates for API-based connectivity -- our goal is for 75% of our traffic to be committed to APIs by the end of the year. As part of that, we've actually converted our integration with Capital One to be 100% API-based and use OAuth for authentication. You can read more here: https://www.capitalone.com/about/newsroom/data-sharing-agree...

What you did was wrong and you all knew it.

It seems to have paid off though, so congratulations. Nobody with half a brain would trust you.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#138

Earlier quoted context omitted.

2FA is so seriously lacking here it's not funny. TD Bank has 2FA which has been SMS-based for a very long time, and they just introduced a 2FA app. FYI. But yes on Tangerine (and other banks) being so, so behind. Sending a wire online here is pretty much impossible..!

As a TD customer, this is mildly infuriating. Is there any legitimate security rationale for forcing me to install their authenticator app instead of simply allowing me to use any industry-standard TOTP app (Authy, Google Authenticator, etc). Not to mention the fact that they still don't allow hardware tokens / U2F eg. Yubikey.

I'd like to know as well. There could very well be some auditing requirement that forces them to explicitly generate the tokens sent to users, and the people enforcing the requirement have sticks up their asses. It wouldn't be the first time that the auditors foul up something because despite working as well or better than what they want, it's not what they know.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#139
post #136

Earlier quoted context omitted.

Is it, though? I’ve given Plaid the user name and password to my bank account. The same set of credentials that I use to log in, to pay bills, transfer money, etc. Plaid stores this information for future use in some sort of reversible encryption. So now we trust Plaid to keep both their data set of user names and encrypted passwords secure, and also to keep their decryption keys secure. Forget that noise. Like the p…

Eh, it’s herd security. Hackers with credentials may pick off a few people’s accounts, but the odds of you being hit are low since it’s a hard problem to scale and there’s so many targets.

For the 0.3 seconds until they automate emptying accounts...
Post reply on HN