Live data from Hacker News

Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

finledger.com

161–170 of 257 posts

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#161

Earlier quoted context omitted.

You gave them your bank account login credentials and you didn't think it was strange?

Plaid has designed the screens to resemble each bank's login screen. They essentially phish people. I, as a tech-savvy person, noticed something was up when I saw the URL didn't match my bank's. But most people would put in their password, thinking they are logging into their bank's website, and would be none the wiser.

OK, I work at Plaid and I feel like I have to jump in here -- while it's true that we've iterated on the Plaid Link UI over time and it hasn't always looked like it does now, you can see what the login screen currently looks like here: https://plaid.com/plaid-link/ and here: https://plaid.com/demo/

IMO it does clearly tell end users that they are connecting to Plaid.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#162
post #113

Earlier quoted context omitted.

A targetted SMS interception attack looks like something something SS7 or SIM swap/social engineering, but a wide net attack looks like pwn the telco and get ssh access to an SMS gateway (or logs, or a database with content), or an aggregator, or a middleman SMS provider between aggregator(s) and carriers, or posing as a legit (or grey route) middleman and getting in routing and then snooping on stuff. Or just a high…

I guess that's the thing I don't get.. you need to pwn a bank and then pwn a telco.. it feels like if it were a probable scenario all these issues with SS7 would be long fixed, so it must be an improbable scenario? My recollection is that we had that once incident in Germany with 02, but never really heard how much was lost and it was the result of a bad policy at 02 that they fixed and was particular to 02.

If you pwn the telco, and the bank has poor password recovery policiss, you might be able to just recover the password. Or maybe password reuse, etc.

I assume if you pwn a bank, you don't really need 2fa codes, but I dunno

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#163

I have some issues with the wording in this article (I work at Plaid and I don't think everything it says about us is accurate) but the report is a good thing. Right now we really are dependent on screen scraping at many banks and we'd much rather use API-based connections to power our services, but so many banks just don't provide APIs. I'm optimistic for an open banking future in Canada and who knows, maybe even th…

not only screen scraping. Plaid also gets around 2FA by asking to forward the bank sms code to them. It happened when i tried using Expensify recently.

That is unacceptable and goes against everything I know.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#164

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

I don't know what Plaid is. But the user/password thing sounds insane. How can that be even an idea for a solution?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#165

As a developer living in a country that has fully implemented "Open Banking", here's a quick setting of expectations for Canadian developers so they don't get too excited as I did when this was first being introduced. Open Banking is not, in fact, open in almost any sense of the world. It is standardised and the standards are freely available ("open"), but other than that, you still need to have an official "blessing…

[deleted]

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#166

As a developer living in a country that has fully implemented "Open Banking", here's a quick setting of expectations for Canadian developers so they don't get too excited as I did when this was first being introduced. Open Banking is not, in fact, open in almost any sense of the world. It is standardised and the standards are freely available ("open"), but other than that, you still need to have an official "blessing…

As a Canadian who has been waiting for the hypothetical ideal situation you describe since Mint and YNAB launched in Canada, that is disappointing to hear. Perhaps there will be a startup that can jump through the hoops and then provide some sort of programmability / webhook access to end users.

Where I am in Europe there are quite a few services that act as gateways, but still the sales process is "talk to us" not just sign up and have instance access.

I guess it makes sense in a way, as it would be easy for scammers to use this ("Oh I need to give access to my bank account to view this Facebook post? Oh sure, why not, moar cats plz").

There are also quite a few budgeting apps here that use open banking, so yes I expect those services will migrate to this when it's available in NA. My only complaint is it takes a few days for them to update the data. I have an accounting program (for my business) which uses open banking and also takes a while to update, so maybe it's a "feature" of open banking?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#167

Earlier quoted context omitted.

Holy smokes, that is shady and scary.

It's not shady, its the explicit purpose of these apps, they collect your transaction data and show you more detailed analysis of it. Since there is no API to safely get the data in a read only way, the only option is to screen scrape the banks website.

It is absolutely shady and scary that they store your banking credentials so that they can log in with them. The fact that there isn't a better option doesn't make it any less shady and scary.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#168

I have some issues with the wording in this article (I work at Plaid and I don't think everything it says about us is accurate) but the report is a good thing. Right now we really are dependent on screen scraping at many banks and we'd much rather use API-based connections to power our services, but so many banks just don't provide APIs. I'm optimistic for an open banking future in Canada and who knows, maybe even th…

not only screen scraping. Plaid also gets around 2FA by asking to forward the bank sms code to them. It happened when i tried using Expensify recently. That is unacceptable and goes against everything I know.

By "forward" you mean that we ask people to submit a 2FA code during login? YMMV, but I would characterize that as "supporting users who have 2FA enabled" rather than "getting around 2FA". Like I said, I'm looking forward to a world where we don't have to ask for credentials at all, but in the current world, we either support 2FA or we don't, and if we didn't, many people would probably turn off 2FA altogether. At a number of institutions, we actually add a layer of 2FA protection and require a SMS-based code if the institution doesn't prompt the user with its own 2FA.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#169
post #128

Earlier quoted context omitted.

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

This is FUD. Lots of Plaid-based connections only allow reads. This is a regulated industry, and the fallout reputationally might be tough, but consumers are well-protected.

Regulated by settlements over this specific allegation lmao

Consumers are only protected by people pointing this out over and over again

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#170
post #92

Earlier quoted context omitted.

> YNAB (You Need A Budget) use services like Plaid to...take my username and password and impersonate me to get my banking data WHAT. THE. F. I'm a longtime, happy YNAB user. I had no idea this was going on until just now. I always just assumed there were secure APIs used to import my data. YNAB's Capital One "integration" stopped working a few years ago (possibly because they cracked down on screen scraping?) and I…

Hi! I work at Plaid. We’re strong advocates for API-based connectivity -- our goal is for 75% of our traffic to be committed to APIs by the end of the year. As part of that, we've actually converted our integration with Capital One to be 100% API-based and use OAuth for authentication. You can read more here: https://www.capitalone.com/about/newsroom/data-sharing-agree...

I'm sure you guys started at that point and realized it was not possible because the banks didn't offer it, didn't understand why, and didn't care about you

And now after you made your solution and gained traction with many fintech apps, the timeline was accelerated by FTC settlements

But don't get the order twisted, you're trying to plai us.

Post reply on HN