Live data from Hacker News

The Secret API of Banks

gduverger.com

101–110 of 257 posts

Re: The Secret API of Banks

#102

The actual secret API of banks-and by the way this is the initial strategy Plaid pursed if rumor is to be believed (essentially without the consent of the banks)-is by reverse engineering mobile app APIs. Most of these bank APIs try to use cheesy secret token vending to prevent casual API traffic on their endpoints, but the reality is that a sufficiently instrumented Android kernel (or rooted iOS device) will let you…

That rumor sounds far from plausible though. If they were to attempt to use the reverse-engineered API from their own servers without consent, banks would find out (in a matter of hours) and shut them down when they discover a huge spike in traffic from a relatively small pool of IPs. If they were to access it directly from customers' phone/browser via their (web-)apps, I expect that it would've caused a huge media storm by now when someone finds out they are storing/transmitting the password in plaintext (or its equivalent) to be used for authentication.

As for this instance specifically, I believe Chase grants Mint (and few other whitelisted companies) account access via OAuth. It's a step in the right direction, although it's not clear to me what their long term goal is.

Re: The Secret API of Banks

#105
post #91

I talk to (about) a person a week who wants to create a new US bank. Some are pursuing a de novo charter, some are buying a bank, and some are a quasi bank on top of another bank. The real blocker here is the Fed won't grant new charters and often won't transfer charters. I'm hoping this will change in the next few years and we can get some real competition. (Disclosure: my job is making APIs for US Banks.)

Any idea why this is the situation? What about doing a state-by-state charter?

The fed is still living with the fear of the 2008 crash. And you still need FDIC insurance even if you have a state charter.

Re: The Secret API of Banks

#106
post #78

Earlier quoted context omitted.

I guess that's the target for anonymous cryptocurrencies like Monero and ZCash?

I'm skeptical of any tender that is rendered worthless by something as simple and common as an electrical outage.

fine. bottle caps it is.

Re: The Secret API of Banks

#107
post #79

Earlier quoted context omitted.

Apologies, I misread it as him complaining that small, one man startups will not be able to compete due to the necessary regulatory burden.

More importantly, the original post, the one you responded to somewhat arrogantly, stated: > This is very clever but makes me sad. It’s 2018 and the best, cleanest way of monitoring and storing my own transactions programmatically is by scraping an email. It would seem that, outside of Germany, which has FinTS, the cleanest way to monitor my own transactions programmatically may well remain email scraping.

> somewhat

that's generous.

Re: The Secret API of Banks

#108

The actual secret API of banks-and by the way this is the initial strategy Plaid pursed if rumor is to be believed (essentially without the consent of the banks)-is by reverse engineering mobile app APIs. Most of these bank APIs try to use cheesy secret token vending to prevent casual API traffic on their endpoints, but the reality is that a sufficiently instrumented Android kernel (or rooted iOS device) will let you…

Why don't banks sell API access at a rate s/similar/lower than Google Maps API access? This is starting to feel like music and video piracy all over again.

Re: The Secret API of Banks

#109

Earlier quoted context omitted.

Particularly in user-facing aspects

What user facing aspects bug you the most?

If I want to make my financial life difficult in the sake of security, that should be my choice. I'm sick of banks saying, either implicitly or outright, "we don't want to ratchet up security measures because people will find it inconvenient. You can say that because it's not your money on the line.

Why can't I ask for chip-and-pin or nothing? No chip-and-signature, no swipe-and-pin, no swipe-and-signature,no it's-less-than-$50-so-nobody-cares-and-we-don't-even-ask-that.

Why can't I have a card inactive by default-- if not used in a week, you have to press a button in the app to re-activate it before it works again? Then you could potentially add "the next charge will be $120 +/- 10. Those would make for a smaller target for spray-and-pray fraud.

Conversely, when they do try to protect you, they do a terrible job of it. My bank (one of the largest in the county) has a particular hard-on for the website of a large regional electronics retailer. In person, fine, but if you order from their site, odds are 50:50 it will fail and your card will get fraud locked. I am significantly less likely to order from them because I know it's going to be a hassle, even when I see an offer I want. If I could white-list the merchant, problem solved. If many customers whitelist them, it might provide better information for their automated anti-fraud systems.

Re: The Secret API of Banks

#110
post #88

Earlier quoted context omitted.

Pretty condescending attitude you've got there. Since you're so far in the future, can you consider dragging Germany into it as well so I don't have to use cash everywhere I go?

> Since you're so far in the future, can you consider dragging Germany into it as well so I don't have to use cash everywhere I go? I think that stems from an intense dislike of debt, specific to Germany more than anything. Not sure why that's relevant to my comment though, or why being 'so far in the future' means 'credit cards everywhere at all times'. Also the USA is still using cheques. They haven't even got to c…

"Also the USA is still using cheques. They haven't even got to chip and pin yet. We are pretty much past that and onto contactless."

I'm not sure what you're talking about. All my cards have chips, and I'm in the US. And for several years, I've been living in an apartment which takes direct bank transfers for rent rather than paper checks. Landlords in my experience have been the last holdouts that don't want to stop using checks. Contactless payment I don't use, but I know it exists in the US because I see signs when I check out.

Post reply on HN