Live data from Hacker News

Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

finledger.com

221–230 of 257 posts

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#221

Earlier quoted context omitted.

> It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. Wise (formerly TransferWise) is another example. You have to move funds into your Wise account before you can do a transfer, payment, or currency exchange. Wise offer various ways to fund your account such as wire transfer, credit card payment, debit card payment, etc., each of which has differe…

In what country does it have that option? Doesn't seem to be a thing in Australia as far as I can tell. But we do have multiple different ways of doing free (or free for the sender and very low cost for a merchant) payments and transfers, including real-time transfers to/from financial institutions... Given that it seems to be a similar case in Europe, UK etc. I assume this might just be a US thing?

Australia does have other examples of these systems though, like poli (https://www.polipayments.com/) which is commonly used by airlines to accept and prove direct deposit payments

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#222

Earlier quoted context omitted.

Are you in the US? I think Wise’s ways of adding funds vary depending on what’s available in terms of payment infrastructure in each country. In the UK where Wise is based, direct debits are very common for routine payments but do not require a card number. But for receiving money Wise UK’s closest equivalent right now is to authorise payment via open banking and your bank ( the newish UK specs for doing this are rea…

I'm speaking about Canada. I should have mentioned that. You're right that the payment options are probably quite different in each country where Wise operates.

Out of curiosity, in Canada (and the USA, where I assume it will be similar), how do you call the system to authorise a business, for example a utility company, to charge your bank account directly every given period, with a more-or-less flexible amount, and with no need for you to take any action?

The reason I ask is that that is what is called a "Direct Debit" in the UK and the European SEPA area, and it does not involve providing any credentials to the bank account. Rather, you only need to provide your International Bank Account Number (IBAN) and maybe your name. However, the ability for a company to be able to take Direct Debit payments is heavily regulated, you can easily cancel them via your bank, and even reverse charges if they were illegitimate.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#223
post #121
post #111

Earlier quoted context omitted.

It would be interesting if an attorney general went after Plaid for CFAA violation.

I'm conflicted on the issue. Plaid only has to do this insane screen scraping because there's no other way to get my own financial data. The details of how it's done pains me, but I also think I should have freedom of choice with my data. IMHO, the Canadian proposal seems like the ideal solution. Force the banks to offer a secure and more efficient way for consumers to access their open banking data. (This will also…

You're basically saying that if a law makes something impossible, then it's OK to ignore the law?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#224
post #207

Earlier quoted context omitted.

Hi! I work at Plaid. We’re strong advocates for API-based connectivity -- our goal is for 75% of our traffic to be committed to APIs by the end of the year. As part of that, we've actually converted our integration with Capital One to be 100% API-based and use OAuth for authentication. You can read more here: https://www.capitalone.com/about/newsroom/data-sharing-agree...

Is there a list of which institutions you support using APIs versus screen scrapers? I'm a happy user of YNAB and would like to have automated imports for any bank that can be read from securely.

Unfortunately, there isn't a comprehensive list that I'm allowed to share, and even if there were we're often rolling out API access gradually because it can require implementation changes on the developer's side (for example, to support an OAuth redirect flow), so it's possible that right now a particular institution may be accessed via API in one Plaid integration but via screen-scraping in another. I think the only thing I can say here about specific institutions is that of the major US banks, Capital One, Chase, Wells Fargo, and US Bank have all issued press releases indicating that they have signed agreements with us to provide API based access.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#225

Earlier quoted context omitted.

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

> It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. Wise (formerly TransferWise) is another example. You have to move funds into your Wise account before you can do a transfer, payment, or currency exchange. Wise offer various ways to fund your account such as wire transfer, credit card payment, debit card payment, etc., each of which has differe…

I've never seen this in either the UK or Finland when using Wise. Direct Debit is a legit thing that's more common in the UK - but that takes several days to clear and the protection is quite strong, Wise would have lost a lot of money to fraud if they offered it as an option...

They use Trustly in the Nordics to do something similar to what you mention, which does seem to use propper bank APIs - as I have to authenticate it on the bank app or website separately.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#226

Earlier quoted context omitted.

Are you in the US? I think Wise’s ways of adding funds vary depending on what’s available in terms of payment infrastructure in each country. In the UK where Wise is based, direct debits are very common for routine payments but do not require a card number. But for receiving money Wise UK’s closest equivalent right now is to authorise payment via open banking and your bank ( the newish UK specs for doing this are rea…

I'm speaking about Canada. I should have mentioned that. You're right that the payment options are probably quite different in each country where Wise operates.

Yeah, direct debit is a very specific, well-standardised thing in the UK and comes with a fair amount of consumer protection. It’s also a bit Oauth-ish in that you can unilaterally cancel it from your bank’s side of things instead of going through the provider.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#227

The EU has been moving in this direction with PSD2 and it’s been pretty good. Downside is there’s no defacto standard for APIs and each bank's development skills vary widely.

PSD2 is really bad. It doesn't actually allow you, the customer, to sign in to your banking account using your own application and an API.

It only mandates that regulated thirdparty companies can access your banking account using some API.

Here in Germany PSD2 was a big step back. Previously we had FinTS (https://en.wikipedia.org/wiki/FinTS), an open banking protocol used since the last 90s, and many programs supporting it. Then PSD2 came and broke some use cases of FinTS. Many banks didn't want to both fix FinTS and support new PSD2 APIs, so they just switched off FinTS. Now German bank customers are basically forced to use the banking website because PSD2 doesn't allow them to use an API and the API they had was taken from them by PSD2.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#228

Earlier quoted context omitted.

Wise (formerly TransferWise) has different meanings for "debit" and "direct debit". Their "debit" option works the way you think. You give only your bank card number, expiry date, and CVV. However, their "direct debit" option requires you to enter your bank debit card number and bank password into Wise's web form. It is not a redirect to the bank website. The URL says " https://wise.com/ ..." when you're asked to ent…

Are you in the US? I think Wise’s ways of adding funds vary depending on what’s available in terms of payment infrastructure in each country. In the UK where Wise is based, direct debits are very common for routine payments but do not require a card number. But for receiving money Wise UK’s closest equivalent right now is to authorise payment via open banking and your bank ( the newish UK specs for doing this are rea…

Can confirm that Wise use Open Banking API to send money in the UK, if your bank supports it. If your bank doesn't support it, it's either debit / credit card or bank transfer.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#229
post #136

Earlier quoted context omitted.

Eh, it’s herd security. Hackers with credentials may pick off a few people’s accounts, but the odds of you being hit are low since it’s a hard problem to scale and there’s so many targets.

For the 0.3 seconds until they automate emptying accounts...

If all Plaid's customers accounts were emptied in one go, I suspect banks would reverse those transactions and tell any counterparties that lost money to pound sand.

I believe the cool kids call it a "hard fork", as in, if you are the bank that received the stolen funds and let someone withdraw them, you get forked, hard.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#230

As a developer living in a country that has fully implemented "Open Banking", here's a quick setting of expectations for Canadian developers so they don't get too excited as I did when this was first being introduced. Open Banking is not, in fact, open in almost any sense of the world. It is standardised and the standards are freely available ("open"), but other than that, you still need to have an official "blessing…

If you're based in Europe or UK, Nordigen has a completely free API do exactly what you described (I'm one of the cofounders). We're connected to 1,500 EU/UK banks and you can connect your bank account to your script/app without any license, certificates or any fees. We don't charge for accessing banking data, we only charge for complimentary data enrichment services like transaction categorisation. https://nordigen.…

We were considering using Nordingen but our main concern is that it seems that Nordingen is essentially able to MITM all calls on PSD2 endpoints, right? How do you establish trust, and how can you keep the service free?
Post reply on HN