If the banks cared they would provide either token-based API like oAuth or at the very least, a read-only password for users to give these sites that aren't fully credentialed. Customers will always want to extract their data.
It's amazing that we can grant revokable, read-only and audited access to our social accounts, but not our bank accounts. Even though the largest aggregators operate under some level of federal supervision (via FFIEC and the OCC), there is an obviously better way. TxPush ( http://txpush.org ) looks like an initiative in this direction. There will likely be an ongoing need for aggregators to maintain access to laggard…
The UK is moving in this direction. The ODI/Fingleton report into Data Sharing and Open Data for Banks[1] recommended creating a open banking API standard and suggested using OAuth, using Twitter as an example (see p24 of the report). Work has begun on defining the roadmap towards creating an API standard[2].
1: https://www.gov.uk/government/publications/data-sharing-and-...
2: http://theodi.org/news/open-banking-working-group-uk-experts...