Live data from Hacker News

OpenAI is connecting ChatGPT to bank accounts via Plaid

firethering.com

101–110 of 155 posts

Re: OpenAI is connecting ChatGPT to bank accounts via Plaid

#101

Earlier quoted context omitted.

Plaid wants you to enter your bank username-password into their form. If it was just routing+account it would be truly no different than other bank connection methods.

Plaid works a lot like PSD2-based services in the EU then, which also typically consist of a form hosted by the service using Times New Roman and the original padlock.gif from Netscape asking for your IBAN and online banking password and then a TAN/2FA number. Obviously there are no technical controls at that point to what the service can do in your account. I tend to avoid anything PSD2 for much the same reasons as…

At this point, it's often OAuth, but in my view, the exact means of access is a red herring: The only thing that changes between screen scraping and OAuth is that Plaid doesn't get my banking password, which is literally the least of my concern compared to persistent access to my account transactional data.

Re: OpenAI is connecting ChatGPT to bank accounts via Plaid

#102
post #77

Earlier quoted context omitted.

They're a YC company so every other YC company is going to use them, that's how YC companies operate.

This isn't at all how YC companies operate (source: I did YC), but also... Plaid is not YC.

Seems kinda weird then that they're listed in workatastartup.com: https://www.workatastartup.com/jobs/15283

Re: OpenAI is connecting ChatGPT to bank accounts via Plaid

#103

Earlier quoted context omitted.

The same info is also on checks, and there's an established story around fraud there -- if I didn't authorize an ACH withdrawal then my bank is legally required to make me whole. If I hand over my username+password to a third party, I'm on my own. Also, the routing+account numbers just let them deposit/withdraw money, not snoop on all my transactions and harvest my data...

This is a common belief, but the CFPB has stated your bank is still legally required to make you whole in the event of fraud even if you handed over your username and password to a third party, and that any bank TOS stating otherwise are not valid. This is covered on the CFPB Electronic Fund Transfers FAQ, under the Error Resolution: Unauthorized EFTs, Question 8: https://www.consumerfinance.gov/compliance/compliance…

In Germany, there was a similar antitrust-based ruling, but it even went further: They disallowed banks to block screen scraping services, as they considered the existence of screen-scraping-based confirmed instant bank transfers a valuable competitor to the (bank-led) card payment schemes.

In retrospect, they were maybe right on the competitive part, but the data privacy impact was disastrous.

Re: OpenAI is connecting ChatGPT to bank accounts via Plaid

#104
post #54

Man, I remember when the common wisdom was that there would NEVER be enough people willing to put their credit card into a web browser to support a business. I never expected to be nostalgic for those days.

To be fair most frequently people online use debit cards which can be frozen if something goes wrong.

What good is freezing a card (regardless of debit or credit) after something has already gone wrong?

Re: OpenAI is connecting ChatGPT to bank accounts via Plaid

#105
post #75

Earlier quoted context omitted.

To be fair most frequently people online use debit cards which can be frozen if something goes wrong.

Uh, debit cards are the worse as they (technically) don’t allow you to dispute charges like in a credit card. Money comes right out of your account first, and then you have to try to get it back. Don’t use debit cards online.

> debit cards are the worse as they (technically) don’t allow you to dispute charges like in a credit card.

That's a commonly propagated falsehood. Both legally (Regulation E) and practically (all large card networks require issuers to extend a zero-liability policy to debit cards), consumer protections are very similar.

The big difference is that, as you say, with a debit card you're potentially out the money for a few days, which can be unpleasant if it makes the direct debit or check for your rent bounce.

Re: OpenAI is connecting ChatGPT to bank accounts via Plaid

#108

Stupid question, but what if you just open an account at a credit union, then have that one connected to plaid? If it needs to see transactions, just have your salary deposited there, then an automatic transfer the same day to your real account?

You totally could, but the purpose of the OpenAI/Plaid integration is to help you analyze your spending and finances with OpenAI (using it as a budgeting/financial planning app), so if your spending isn't actually in the account you connected, it's not going to give you any value.

Re: OpenAI is connecting ChatGPT to bank accounts via Plaid

#109
post #81
post #72

Earlier quoted context omitted.

Okay, what concrete harms has Meta done with this information? At best you have some creeps using it to stalk their exes, which is bad, but a far cry from the AI takeover scenario implied by OP.

I haven't implied an AI takeover, this data will be repackaged into a product for military/intelligence, political applications, insurance companies that can charge you more because they know you're willing to pay, and many more. These things already exist and happen, it's about the data getting better and not having to build tools to query it and make projections, since you can just type a query into a box even if y…

>I haven't implied an AI takeover, this data will be repackaged into a product for military/intelligence, political applications, insurance companies that can charge you more because they know you're willing to pay, and many more.

Any evidence google or meta actually sells customer data like that?

Re: OpenAI is connecting ChatGPT to bank accounts via Plaid

#110
post #69

Earlier quoted context omitted.

One thousand times this. I am not giving away the keys to my bank accounts.

It’s worse than keys, it’s a persistent read-only view of all account data. At least there is a process for unauthorized ACH debits. For this blatant breach of privacy, there is nothing.

Plaid requires your bank username and password, so they have full read-write access to your account. They can do anything you can do when logged in to the bank's website, and so can anyone else who gains access to Plaid's database.
Post reply on HN