Live data from Hacker News

Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

finledger.com

181–190 of 257 posts

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#181

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

Hi! I work at Plaid wanted to share that the Consumer Financial Production Bureau addressed the fact that a financial institution cannot waive liability responsibilities in a recent Compliance Aid. FAQ 4 says that instititutions cannot rely on an agreement with the consumer that waives the liability protections under Regulation E if a consumer has shared their account information with a third party because those are protections provided under the Electronic Funds Transfer Act.

Source: https://www.consumerfinance.gov/compliance/compliance-resour...

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#182

As a developer living in a country that has fully implemented "Open Banking", here's a quick setting of expectations for Canadian developers so they don't get too excited as I did when this was first being introduced. Open Banking is not, in fact, open in almost any sense of the world. It is standardised and the standards are freely available ("open"), but other than that, you still need to have an official "blessing…

If you're based in Europe or UK, Nordigen has a completely free API do exactly what you described (I'm one of the cofounders).

We're connected to 1,500 EU/UK banks and you can connect your bank account to your script/app without any license, certificates or any fees. We don't charge for accessing banking data, we only charge for complimentary data enrichment services like transaction categorisation.

https://nordigen.com/

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#183
post #122

Earlier quoted context omitted.

But sending you an SMS is a lot more security than no 2FA at all, right? I am aware of attacks that state/very sophisticated actors can use to intercept SMS messages but that's a serious edge case for a normal person, right?

It's not secure at all, as some services (PayPal!) Allow password reset via SMS to your regitered mobile number. So if someone even has control of your mobile number via sim swap for 5 minutes they gain full control of your paypal acct. Heard of enough incidents of this earlier this year through one of the Canadian prepaid mobile flanker brands... Paypal makes it hard to remove a mobile number from your account once…

To reiterate what you said, enabling SMS can make your security much worse on some services. It's counterintuitive. Someone taking control of your phone number can make your excellent password irrelevant.

If you must provide a phone number, another tip is to call customer service on your cellular service provider and ask them to put a "port out block" or "port protect" on your account. Before anyone can do a sim swap on your account, they'd have to call the cellular service provider and give a password or PIN. (It's amazing that this isn't the default.)

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#184

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

I work at Plaid, and I responded to this on the parent, but because this is pretty highly upvoted I figured I'd respond here too for visibility: the Consumer Financial Production Bureau addressed the fact that a financial institution cannot waive liability responsibilities in a recent Compliance Aid. FAQ 4 says that institutions cannot rely on an agreement with the consumer that waives the liability protections under Regulation E if a consumer has shared their account information with a third party because those are protections provided under the Electronic Funds Transfer Act.

Source: https://www.consumerfinance.gov/compliance/compliance-resour...

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#186

Earlier quoted context omitted.

It's not shady, its the explicit purpose of these apps, they collect your transaction data and show you more detailed analysis of it. Since there is no API to safely get the data in a read only way, the only option is to screen scrape the banks website.

It is absolutely shady and scary that they store your banking credentials so that they can log in with them. The fact that there isn't a better option doesn't make it any less shady and scary.

They explicitly explain this to the user and apparently even encourage that you instead manually export files and upload them but also provide direct login as a feature.

Yes its not perfect security which you may find scary but I struggle to find what about it is shady when they are very open about what happens.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#187

Earlier quoted context omitted.

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

I haven't used Plaid, but how is this different from Mint or Quicken that have been around for years?

Mint and Quicken are end user applications, Plaid is not. Plaid is an API provider to access financial information from multiple institutions.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#188
post #133

Earlier quoted context omitted.

You already know the answer. Ask forgiveness not permission, move fast and break things.

Our profession is such a joke. We're no better than the stereotypical trades worker of yore... a bunch of plumbers scamming and ripping off the every day person that doesn't know any better. Truly pathetic.

Or perhaps it is our systems that are pathetic? Laws, regulations and enforcement thereof has always been a bureaucratic effort.

As an early career engineer, who works at a highly bureaucratic company, I always asked for permission for access to things I needed for my job. The gate keepers would ignore me. Worst example was when my management asked me to start version controlling a project I created. I had to work with the change management department, it took them six months to create a repo on a server just because no one knew the person who knew how to do that, and they had to be the ones to make it, not me.

Then I moved up in the company and got direct communication with the customer. The gate keepers come to me, not the other way around. Repos get created in a day now.

The problem with every bureaucracy is the incentives are never aligned with the organizations stated mission. When you say “version control” what you really mean is version control for employees who directly bring money to the company, for which we’ll dedicate significant parts of our budget to employ people for a function that can be automated as some sort of make-work scheme. The incentives are messed up.

Bureaucrats only win when they don’t get fired, and they don’t get fired when they follow the policies and procedures. And policies and procedures are there for the well trodden happy path. If you are innovating, there will, by definition, be no happy path, you have to make it, and if you ask a bureaucrat for help, they’ll seize up because there is no procedure to follow. At best they’ll direct you to someone else, who will also seize up and direct you back to the same person who sent you.

I discovered that the best way around that is to make seizing up a more likely way to visibly fail. I need you to help me get this build out to the customer TODAY if failure to do that will result in higher consequences than failing to follow procedures, they will make the build.

So moving fast and breaking things can get you to that high consequence state that bureaucrats seem to budge on. If you have a successful startup that breaks the law, you can please your users, and afford lawyers to defend you in court and afford PR firms that can convince the media to harass your regulators on your behalf.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#189

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

Hi! I work at Plaid wanted to share that the Consumer Financial Production Bureau addressed the fact that a financial institution cannot waive liability responsibilities in a recent Compliance Aid. FAQ 4 says that instititutions cannot rely on an agreement with the consumer that waives the liability protections under Regulation E if a consumer has shared their account information with a third party because those are…

But still. Terrible security model, right?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#190

Earlier quoted context omitted.

> It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. Wise (formerly TransferWise) is another example. You have to move funds into your Wise account before you can do a transfer, payment, or currency exchange. Wise offer various ways to fund your account such as wire transfer, credit card payment, debit card payment, etc., each of which has differe…

Are you sure you're not confusing things? Direct debit usually means just a permission to charge the given account for the specified amount. It's commonly used in Canada and doesn't involve sharing your password.

Wise (formerly TransferWise) has different meanings for "debit" and "direct debit".

Their "debit" option works the way you think. You give only your bank card number, expiry date, and CVV.

However, their "direct debit" option requires you to enter your bank debit card number and bank password into Wise's web form. It is not a redirect to the bank website. The URL says "https://wise.com/..." when you're asked to enter that info. Wise definitely gets your bank credentials.

They have yet another option called "bill payment" in which you log into your bank account yourself and do a bill payment to Wise (and giving your Wise account number).

Both the "debit" and "bill payment" methods look secure and acceptable. But Wise charges a considerably higher fee than with their "direct debit" method. And it always seems to take a day or two for the funds to appear in your Wise account with those other methods. They really want to encourage their "direct debit" method in which they get your bank login info.

Post reply on HN