Earlier quoted context omitted.
> It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. Wise (formerly TransferWise) is another example. You have to move funds into your Wise account before you can do a transfer, payment, or currency exchange. Wise offer various ways to fund your account such as wire transfer, credit card payment, debit card payment, etc., each of which has differe…
In what country does it have that option? Doesn't seem to be a thing in Australia as far as I can tell. But we do have multiple different ways of doing free (or free for the sender and very low cost for a merchant) payments and transfers, including real-time transfers to/from financial institutions... Given that it seems to be a similar case in Europe, UK etc. I assume this might just be a US thing?
Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
221–230 of 257 posts
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#222Earlier quoted context omitted.
Are you in the US? I think Wise’s ways of adding funds vary depending on what’s available in terms of payment infrastructure in each country. In the UK where Wise is based, direct debits are very common for routine payments but do not require a card number. But for receiving money Wise UK’s closest equivalent right now is to authorise payment via open banking and your bank ( the newish UK specs for doing this are rea…
I'm speaking about Canada. I should have mentioned that. You're right that the payment options are probably quite different in each country where Wise operates.
The reason I ask is that that is what is called a "Direct Debit" in the UK and the European SEPA area, and it does not involve providing any credentials to the bank account. Rather, you only need to provide your International Bank Account Number (IBAN) and maybe your name. However, the ability for a company to be able to take Direct Debit payments is heavily regulated, you can easily cancel them via your bank, and even reverse charges if they were illegitimate.
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#223Earlier quoted context omitted.
It would be interesting if an attorney general went after Plaid for CFAA violation.
I'm conflicted on the issue. Plaid only has to do this insane screen scraping because there's no other way to get my own financial data. The details of how it's done pains me, but I also think I should have freedom of choice with my data. IMHO, the Canadian proposal seems like the ideal solution. Force the banks to offer a secure and more efficient way for consumers to access their open banking data. (This will also…
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#224Earlier quoted context omitted.
Hi! I work at Plaid. We’re strong advocates for API-based connectivity -- our goal is for 75% of our traffic to be committed to APIs by the end of the year. As part of that, we've actually converted our integration with Capital One to be 100% API-based and use OAuth for authentication. You can read more here: https://www.capitalone.com/about/newsroom/data-sharing-agree...
Is there a list of which institutions you support using APIs versus screen scrapers? I'm a happy user of YNAB and would like to have automated imports for any bank that can be read from securely.
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#225Earlier quoted context omitted.
Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.
> It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. Wise (formerly TransferWise) is another example. You have to move funds into your Wise account before you can do a transfer, payment, or currency exchange. Wise offer various ways to fund your account such as wire transfer, credit card payment, debit card payment, etc., each of which has differe…
They use Trustly in the Nordics to do something similar to what you mention, which does seem to use propper bank APIs - as I have to authenticate it on the bank app or website separately.
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#226Earlier quoted context omitted.
Are you in the US? I think Wise’s ways of adding funds vary depending on what’s available in terms of payment infrastructure in each country. In the UK where Wise is based, direct debits are very common for routine payments but do not require a card number. But for receiving money Wise UK’s closest equivalent right now is to authorise payment via open banking and your bank ( the newish UK specs for doing this are rea…
I'm speaking about Canada. I should have mentioned that. You're right that the payment options are probably quite different in each country where Wise operates.
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#227The EU has been moving in this direction with PSD2 and it’s been pretty good. Downside is there’s no defacto standard for APIs and each bank's development skills vary widely.
It only mandates that regulated thirdparty companies can access your banking account using some API.
Here in Germany PSD2 was a big step back. Previously we had FinTS (https://en.wikipedia.org/wiki/FinTS), an open banking protocol used since the last 90s, and many programs supporting it. Then PSD2 came and broke some use cases of FinTS. Many banks didn't want to both fix FinTS and support new PSD2 APIs, so they just switched off FinTS. Now German bank customers are basically forced to use the banking website because PSD2 doesn't allow them to use an API and the API they had was taken from them by PSD2.
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#228Earlier quoted context omitted.
Wise (formerly TransferWise) has different meanings for "debit" and "direct debit". Their "debit" option works the way you think. You give only your bank card number, expiry date, and CVV. However, their "direct debit" option requires you to enter your bank debit card number and bank password into Wise's web form. It is not a redirect to the bank website. The URL says " https://wise.com/ ..." when you're asked to ent…
Are you in the US? I think Wise’s ways of adding funds vary depending on what’s available in terms of payment infrastructure in each country. In the UK where Wise is based, direct debits are very common for routine payments but do not require a card number. But for receiving money Wise UK’s closest equivalent right now is to authorise payment via open banking and your bank ( the newish UK specs for doing this are rea…
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#229Earlier quoted context omitted.
Eh, it’s herd security. Hackers with credentials may pick off a few people’s accounts, but the odds of you being hit are low since it’s a hard problem to scale and there’s so many targets.
For the 0.3 seconds until they automate emptying accounts...
I believe the cool kids call it a "hard fork", as in, if you are the bank that received the stolen funds and let someone withdraw them, you get forked, hard.
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#230As a developer living in a country that has fully implemented "Open Banking", here's a quick setting of expectations for Canadian developers so they don't get too excited as I did when this was first being introduced. Open Banking is not, in fact, open in almost any sense of the world. It is standardised and the standards are freely available ("open"), but other than that, you still need to have an official "blessing…
If you're based in Europe or UK, Nordigen has a completely free API do exactly what you described (I'm one of the cofounders). We're connected to 1,500 EU/UK banks and you can connect your bank account to your script/app without any license, certificates or any fees. We don't charge for accessing banking data, we only charge for complimentary data enrichment services like transaction categorisation. https://nordigen.…