Live data from Hacker News

Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

finledger.com

141–150 of 257 posts

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#141

Earlier quoted context omitted.

How is that enforced? What is the technical basis that enforces read-only access using user/password auth? Especially since that user/password auth is used by an end user to do "write"-type actions?

Read-only access is not possible. By handing over the credentials you are handing over write access. You are correct.

A couple of my banking institutions let me generate a read-only set of credentials for this sort of purpose.

Citi and Capital One have OAuth flows that Plaid supports, too, which tends to make me angrier at the banks than Plaid; the need for this stuff has been clear for a decade now, but only a few have added OAuth or similar.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#142
post #127

Earlier quoted context omitted.

Hi! I work at Plaid. This is false. We do not do that.

Ever? That was always the rumor on how aggregators could fix scraping within a day of major changes.

If the supposed third-party scrapers can do it within a day, why wouldn't Plaid/Mint/Yodlee be able to do the same?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#143

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

Dunno how Turbotax does things under the hood in the US, but when it prompts me for the username and password of my broker to import my info, it certainly make me very queasy.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#144
post #128

Earlier quoted context omitted.

This is FUD. Lots of Plaid-based connections only allow reads. This is a regulated industry, and the fallout reputationally might be tough, but consumers are well-protected.

How is that enforced? What is the technical basis that enforces read-only access using user/password auth? Especially since that user/password auth is used by an end user to do "write"-type actions?

It's enforced - sometimes - by the bank. My bank provides read access to everything with a username + password, but to transfer money or update details requires an SMS confirmation.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#145

Earlier quoted context omitted.

Hi! I work at Plaid. We’re strong advocates for API-based connectivity -- our goal is for 75% of our traffic to be committed to APIs by the end of the year. As part of that, we've actually converted our integration with Capital One to be 100% API-based and use OAuth for authentication. You can read more here: https://www.capitalone.com/about/newsroom/data-sharing-agree...

What you did was wrong and you all knew it. It seems to have paid off though, so congratulations. Nobody with half a brain would trust you.

Let's be real, banks wouldn't see government regulation like this if something like Plaid didn't force them to have to implement more secure ways to get your own financial data.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#146

Earlier quoted context omitted.

Sounds like the situation in Australia, which NZ sounds like they’re copying.

Yep, I was excited that I might be able to access my banking data using APIs in NZ, then I found this: https://www.apicentre.paymentsnz.co.nz/join/api-community-co... So it's "free for 12 months", but the idea is that I build or create an "innovation". Not interested, I just want APIs for my data, I'm not interested in building a SaaS, I don't want that kind of responsibility for other people's data. Back to using my…

Hit me up, email in profile.

Working on similar stuff, effectively what you have without the requirement to maintain scrapers.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#147

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

I haven't read the entire report yet, but it seems like a step in the right direction (even given some of the caveats folks have pointed out). I work at Plaid and a big focus area for us is to move as much traffic to APIs as possible, with a target of 75% of traffic to be committed to APIs by EOY, and we’re hopeful that we’ll be close to a fully API based industry in the next few years. IMO anything that makes API-based connectivity and open finance standards more widespread is a win for both fintech developers and anyone with a bank account.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#148
post #145

Earlier quoted context omitted.

What you did was wrong and you all knew it. It seems to have paid off though, so congratulations. Nobody with half a brain would trust you.

Let's be real, banks wouldn't see government regulation like this if something like Plaid didn't force them to have to implement more secure ways to get your own financial data.

I actually do agree - but two wrongs don't make a right here. Taking raw credentials from users without them knowing is completely messed up and a massive danger to the end-user. It's not justifiable in those terms.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#149
post #133

Earlier quoted context omitted.

I'm pretty salty about this. It's totally unethical, they knew it wasn't legal, and yet... they're going to be OK outside the fine? Why do we bother being ethical when nobody besides us gives a shit outside a slap on the wrist? You know how many people thought of Plaid before it was a thing, then rightfully wrote it off as "don't attempt"? What kind of sick precedent does this set? Why do I even bother caring.

You already know the answer. Ask forgiveness not permission, move fast and break things.

Our profession is such a joke. We're no better than the stereotypical trades worker of yore... a bunch of plumbers scamming and ripping off the every day person that doesn't know any better. Truly pathetic.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#150
post #113

Earlier quoted context omitted.

This argument seems strange to me.. how many attacks are by someone literally armed with a customer list from a financial institution? The "casting a wide net" seems directly opposed to the effort involved in a SMS intercept attack which requires significant resources. I don't see a practical circumstance where this is a reasonable risk I guess. I just don't know. I would love an article-length explainer out there so…

A targetted SMS interception attack looks like something something SS7 or SIM swap/social engineering, but a wide net attack looks like pwn the telco and get ssh access to an SMS gateway (or logs, or a database with content), or an aggregator, or a middleman SMS provider between aggregator(s) and carriers, or posing as a legit (or grey route) middleman and getting in routing and then snooping on stuff. Or just a high…

I guess that's the thing I don't get.. you need to pwn a bank and then pwn a telco.. it feels like if it were a probable scenario all these issues with SS7 would be long fixed, so it must be an improbable scenario?

My recollection is that we had that once incident in Germany with 02, but never really heard how much was lost and it was the result of a bad policy at 02 that they fixed and was particular to 02.

Post reply on HN