Banks are well aware that this is a thing and they're not that bothered.
If you want to see this improve, maybe push on US regulators to formalise it?
11–20 of 47 posts
Banks are well aware that this is a thing and they're not that bothered.
If you want to see this improve, maybe push on US regulators to formalise it?
Hard delete of an issue over closing it or closing comments... for such a security sensitive issue... under the rug sweeping.
Well, thanks to the fact that you can't delete anything off the internet it will still be presented as evidence in court some day. This confirms to me that staying as far away as possible from plaid is the right move.
The scariest thing is whether they keep downloading transactions or just verify i own the account like they make you think they're doing.
@skierpage and @briangordon we appreciate your concerns, which is why our compliance team vets anybody who uses Link. As to malicious knock offs, this is a matter that most successful companies lookout for and deal with -- as we and our security team do.
This person should not be allowed to provide services that use bank APIs. Who should do the preventing? Banks.
Compare that to something like "Sign-in with Google" or "Sign in with Github". They put it in plain english exactly what the website you are signing into is asking permission for and you explicitly say I'm ok with that.
Plaid needs to be exposed as one of the most unethical companies in SV. If people are worried about online privacy then they should really be worried about a company that is so deceiving and makes it basically impossible to revoke permissions on something as sensitive as access to your bank account and transaction history once granted.
can you revoke by changing your password?
I take issue with a product that markets to consumers as an easy way to authenticate for the purpose of pulling or pushing funds, but is actually authorizing developers to scrape years of transaction history in 20 minutes, my real time balance, my phone/email/address etc. without another level of permission. It’s disgusting.
I just wanted an alternative to microdeposits to prove to an app that I own a bank account, not give the app free range to steal all my bank data in the process of doing so.
Plaid needs to be exposed as one of the most unethical companies in SV. If people are worried about online privacy then they should really be worried about a company that is so deceiving and makes it basically impossible to revoke permissions on something as sensitive as access to your bank account and transaction history once granted.
[1] https://www.quora.com/Why-doesnt-Betterment-or-Wealthfront-u...
[2] https://www.investmentnews.com/article/20190108/FREE/1901099...
Earlier quoted context omitted.
Well, thanks to the fact that you can't delete anything off the internet it will still be presented as evidence in court some day. This confirms to me that staying as far away as possible from plaid is the right move.
What would you recommend for ACH bank account verification?
I don't believe access to all of my most personal data should be ‘frictionless’.
They also quite cheerfully asked me ‘Hey! Next time you’re in the area we’d love to look at working together?’ Classy.