Live data from Hacker News

Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

finledger.com

171–180 of 257 posts

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#171

Earlier quoted context omitted.

Plaid has designed the screens to resemble each bank's login screen. They essentially phish people. I, as a tech-savvy person, noticed something was up when I saw the URL didn't match my bank's. But most people would put in their password, thinking they are logging into their bank's website, and would be none the wiser.

OK, I work at Plaid and I feel like I have to jump in here -- while it's true that we've iterated on the Plaid Link UI over time and it hasn't always looked like it does now, you can see what the login screen currently looks like here: https://plaid.com/plaid-link/ and here: https://plaid.com/demo/ IMO it does clearly tell end users that they are connecting to Plaid.

So some good finally came from that TD lawsuit. The last time I saw a Plaid login in a service I use, it was a definite phishing screen. It's good that you have moved away from phishing people, but it doesn't change the fact that a) you phished them for years, and b) you still do not in any way warn them that if they use your service it 'voids the warranty', so if their account gets hacked (not necessarily through Plaid), they will be SOL.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#172

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

>if something goes wrong and Plaid loses my money somehow, is there any recourse

Wait, you mean you don't read and understand every word of every legal agreement you accede to??

Ok, well, as a responsible consumer, have you considered keeping a lawyer on retainer?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#173

Earlier quoted context omitted.

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

I'm pretty salty about this. It's totally unethical, they knew it wasn't legal, and yet... they're going to be OK outside the fine? Why do we bother being ethical when nobody besides us gives a shit outside a slap on the wrist? You know how many people thought of Plaid before it was a thing, then rightfully wrote it off as "don't attempt"? What kind of sick precedent does this set? Why do I even bother caring.

> they knew it wasn't legal

Who knew what wasn't legal? I don't think anyone is doing anything illegal here?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#174

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

I haven't used Plaid, but how is this different from Mint or Quicken that have been around for years?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#175

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

I don't know what Plaid is. But the user/password thing sounds insane. How can that be even an idea for a solution?

What else is there, when the bank doesn't provide an API & the ability to do something proper, like OAuth2?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#176

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

> It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached.

Wise (formerly TransferWise) is another example. You have to move funds into your Wise account before you can do a transfer, payment, or currency exchange. Wise offer various ways to fund your account such as wire transfer, credit card payment, debit card payment, etc., each of which has different fees, but by far the lowest fee is "direct debit" which involves giving Wise your bank card number and password. I imagine that the overwhelming majority of Wise customers have no idea that this is terrible for security and privacy.

Everything about this practice is hard to believe:

1) I doubt that any bank has given Wise permission to do this.

2) Which raises the question about why the banks aren't blocking IP addresses that Wise uses to log into bank accounts, or at least making a complaint to Wise.

3) It's obviously against the banks' terms of service, but Wise may be breaking some law regarding unauthorized access (in the same vein that you can't authorize a third party to use your passport, for example).

4) What else is Wise doing after they log into your bank account? Are they collecting other information about your transactions and balance?

5) Does Wise store your bank card number and password? If they do, they'd have to store it as cleartext (not as a one-way hash) if they expect to use it again. They could encrypt it of course, but it would have to be reversible so they could get the cleartext back.

6) Why hasn't any bank regulator forced them to stop doing this?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#177

Earlier quoted context omitted.

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

> It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. Wise (formerly TransferWise) is another example. You have to move funds into your Wise account before you can do a transfer, payment, or currency exchange. Wise offer various ways to fund your account such as wire transfer, credit card payment, debit card payment, etc., each of which has differe…

Are you sure you're not confusing things? Direct debit usually means just a permission to charge the given account for the specified amount. It's commonly used in Canada and doesn't involve sharing your password.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#178
The Spectre Salt Edge API does the same. I thought I could use this in Firefly III to automcatically pull my banking data, until I found out they are screen scraping. This is a no go. Unfortunately, the official FinTS APIs available by most banks are incredibly flawed, too. Firstly, a lot of information is not available. Secondly, there is no way to have a "read-only" API key/connection. Why is that? I have no idea. There is an Open Banking project in Europe, but it it is far from being ready.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#179

Earlier quoted context omitted.

The Canadian Revenue Agency started forcing SMS 2FA on online accounts recently

PayPal in Europe is doing SMS now too. They claim it's for "PSD2" compliance or something. But I already had TOTP 2FA ("Google Authenticator") enabled and I'd prefer to use that instead as it's much safer than SMS. That was never intended to carry secure information. Also, TOTP works even when I have my phone in airplane mode. Strange thing is it seems to randomly ask for SMS or TOTP now, whichever it feels like at t…

It's not weird at all in the context of metadata (phone #).

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#180
post #107

Earlier quoted context omitted.

> The big telecom lobbying argument vs CRTC about how urban markets need to subsidize rural infrastructure costs is not something 95% of canadians like to hear, but it kinda makes sense (They say rural infra simply isn't cost effective because Canada is so expansive, but you expect high speed Internet access in your Muskoka cottage, right?) That still doesn't explain why internet service is way more expensive in Cana…

I don't mean this to be crass, I presume you've never driven across Canada then? I suspect if you had, you'd very soon realize why it's so expensive. 11 people per square mile, the same as Botswana, except at least in Botswana you can just drive in a straight line for hours, and you don't have snow salt and freezing temperatures to contend with. If a team from Rogers in Toronto had to go to Kenora Ontario to service…

Kenora is a two hours drive from Winnipeg, it's not nearly as inaccessible as you're making it out to be.

However, with that said, I saw numbers saying that laying one mile of fiber costs to the tune of $30k, so just connecting Winnipeg to Kenora would cost some $4M. Kenora itself has an area of 80 sq mi and a population of 15k people (though mostly concentrated near Lake of Woods). It's not nothing, but also not exactly a gold mine for telecoms, to be sure.

Timmins might be a better example. It's more than 400 miles north of Toronto, and has some 40k people. Sudbury is half way there and has some 160k people, but still some 250 miles away from Toronto. To give a sense of scale, the distance from Timmins to Toronto is bigger than the distance from Amsterdam (Netherlands) to Berlin (Germany). 200k potential customers is a pretty decent size market (that's a quarter of San Francisco's population, for example), but covering 400 miles w/ fiber at $30k/mile just to reach it comes out to a cool $12M upfront investment. Don't forget this is just to connect two points, there's still last mile coverage and ongoing maintenance which is going to add quite a bit of cost on top. If a single competitor is there, that can cut into the profits pretty deeply.

That's the sort of math that telecoms need to deal with when doing ROI analyses on these markets.

Post reply on HN