Live data from Hacker News

Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

finledger.com

241–250 of 257 posts

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#241

Earlier quoted context omitted.

Out of curiosity, in Canada (and the USA, where I assume it will be similar), how do you call the system to authorise a business, for example a utility company, to charge your bank account directly every given period, with a more-or-less flexible amount, and with no need for you to take any action? The reason I ask is that that is what is called a "Direct Debit" in the UK and the European SEPA area, and it does not i…

This is as common as bread and butter in Australia. You provide your bank account (or credit/debit card) details to the company or even govt (gas, electricity, water, car registration, insurance, internet, mobile etc.) and a so called direct debit authority and the company will just debit from your account on the due date.

Yes, Direct Debits or similar are something that I would normally assume is commonplace in every developed country. However, I'm so aware of the American TV trope of receiving "bills" in the mail and having to remember to pay them that I wonder if it's just something that has stuck as a cliché even if it's no longer the case, or whether it is still the ordinary way of handling these payments in North America.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#242

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

As someone who attempts to import all my own banking transactions into open-source personal financial software, I certainly don't like the situation, but banks often give someone looking to download their own financial transaction data no other choice. This is basically what Intuit/Quicken do for 'Quicken Web Connect', too...

Additionally, though I think the advent of new APIs which will allow you to authenticate directly with your bank (FDX) are a great improvement for overall security, I think they're going to be a step backwards for free access to your own personal financial information. Because banks are limiting access to FDX to large players like Plaid/Quicken, I fear you will be forced to pay a third-party to get your own personal financial data in the future!

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#243
post #232

As a developer living in a country that has fully implemented "Open Banking", here's a quick setting of expectations for Canadian developers so they don't get too excited as I did when this was first being introduced. Open Banking is not, in fact, open in almost any sense of the world. It is standardised and the standards are freely available ("open"), but other than that, you still need to have an official "blessing…

Well, your expectations were clearly wrong. “Open” in this case means open standards and access for accredited entities. Because if you grant access to just anyone, then you’ve created an instant fraudster’s paradise. The legal requirements in the UK (which you may be talking about, unsure) are not meaningless, they are there to ensure that known parties and known good practice are in use. Open Banking the company is…

> if you grant access to just anyone, then you’ve created an instant fraudster’s paradise.

I believe that everyone might get access to their own data and to performing actions on their own account.

Could you clarify how is that supposed to create a fraudsters' paradise?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#244

Earlier quoted context omitted.

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

> It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. Wise (formerly TransferWise) is another example. You have to move funds into your Wise account before you can do a transfer, payment, or currency exchange. Wise offer various ways to fund your account such as wire transfer, credit card payment, debit card payment, etc., each of which has differe…

> Wise (formerly TransferWise) is another example

It is not. The direct debit feature you describe is provided by Plaid.

Wise itself says so in this TrustPilot answer https://ca.trustpilot.com/reviews/60e668daf9f48702a893a5e6

> It sounds like you might be trying to make a ACH direct debit payment, in which case Plaid is indeed one of the payment handlers that help us process these types of payments. However, we also offer other payment options for USD, if your account isn't able to support ACH direct debit.

There are other sources mentioning TransferWise is a customer of Plaid like https://www.digfingroup.com/plaid-visa/ and https://politechs.ca/2020/09/09/visas-acquisition-of-plaid-c...

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#245
post #232

Earlier quoted context omitted.

Well, your expectations were clearly wrong. “Open” in this case means open standards and access for accredited entities. Because if you grant access to just anyone, then you’ve created an instant fraudster’s paradise. The legal requirements in the UK (which you may be talking about, unsure) are not meaningless, they are there to ensure that known parties and known good practice are in use. Open Banking the company is…

> if you grant access to just anyone, then you’ve created an instant fraudster’s paradise. I believe that everyone might get access to their own data and to performing actions on their own account. Could you clarify how is that supposed to create a fraudsters' paradise?

Yep, the moment you allow that sort of access people will let the arseholes in one way or another, because people in general don't have a clue about what permissions should be given to people who call up claiming to be, for instance, from the tax office.

Even read only, fraudsters will find ways to exfiltrate private data that's useful for identity theft, blackmail or any number of criminal acts.

People are not security-savvy enough to be given this access safely. You might be, my parents and millions like them aren't.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#246

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

I've worked for a heavy customer of Plaid, and I've experienced the good and bad side of said entities and architectures, and the propaganda used by both sides. Banks say "impersonate", Plaid says something else. I think a reasonable viewpoint could say that you are authorizing Plaid to act on your behalf. Would a bank punish a rich person for having their accountant/finance manager know their credentials and use them in their duties? Would a bank publicly punish someone for storing their bank password in a password manager? How about an online password manager?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#247

Earlier quoted context omitted.

In the UK, which has implemented open banking already, you can use services like https://syncforynab.com/ (no affiliation, just a happy customer) to link your accounts to YNAB. Some challenger banks like Monzo and Starling allow you to set up webhooks for transactions so they're immediately available in YNAB through Sync for YNAB rather than having to use x-hourly syncs via open banking companies that are officially…

I recently moved back to the US after 5 years in the UK. It’s hard to overstate how awesome Monzo is, and how much of a steaming pile of 3rd world shit banking in the US is.

Addendum: I still use Monzo in the US. Call the cops. I don’t care.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#248

Earlier quoted context omitted.

I'm pretty salty about this. It's totally unethical, they knew it wasn't legal, and yet... they're going to be OK outside the fine? Why do we bother being ethical when nobody besides us gives a shit outside a slap on the wrist? You know how many people thought of Plaid before it was a thing, then rightfully wrote it off as "don't attempt"? What kind of sick precedent does this set? Why do I even bother caring.

> they knew it wasn't legal Who knew what wasn't legal? I don't think anyone is doing anything illegal here?

Coercing credentials out of a user is phishing. I was wrong in that it may not be technically illegal, but are we really going to dispute if phishing is acceptable behaviour for a company to participate in?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#249
post #136

Earlier quoted context omitted.

Eh, it’s herd security. Hackers with credentials may pick off a few people’s accounts, but the odds of you being hit are low since it’s a hard problem to scale and there’s so many targets.

For the 0.3 seconds until they automate emptying accounts...

You wouldn’t drain all accounts all at once. Pick a couple accounts to satisfy your needs and drain them. Harder to get caught.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#250
post #238
post #155

Earlier quoted context omitted.

Yes I agree it can be scary, but it seems like this is the way a lot of companies have to do things if they want regulation to change at any reasonable pace. Just look at Uber and AirBnB as examples. Most cities they started in they were operating in kinda grey areas or even breaking laws. But they could afford to eat any fines and continue on anyway. It forced governments to put regulations in place to support these…

But is it a good thing for companies that are rich enough to be able to force changes in regulations by overwhelming the government's ability to punish them?

No, it definitely is not. Governments notoriously move slow and they do not often keep up with the fast moving pace of technology.

Governments for the most part worldwide have still done barely anything to address things like "loot boxes" in gaming despite them being almost identical to gambling. They aren't even getting fined or anything for this and are raking in billions of dollars. So whether or not big companies are doing things to break regulations they can still be doing things that should be regulated or are not ethical anyway.

The taxi industry was pretty bad and often filled with scams and corruption. One of the cities I live near only allowed one cab company to be licensed in the city and they sucked especially when people needed rides home at night. So when Uber came in people loved it because they could finally get home safety after a night of drinking and it discouraged people from having to try and drive home drunk. For whatever reason the city always only allowed this one cab company. It would be reasonable to think a city official had some affiliation with that company to not allow other cab companies to come in.

Uber forced that to happen and it forced them to make regulation for it. There seemed to be no progress in that happening before Uber came to town.

So while Uber has some pretty shitty practices and I wouldn't consider it a good company, it is definitely a good example of what often needs to be done to force regulation.

And I mean a city always had the option to increase their fines to something massive and hit Uber hard, but instead they realized that their population wanted that and they would likely lose a lot of votes if they did something against the people like that.

Post reply on HN