Live data from Hacker News

The Secret API of Banks

gduverger.com

111–120 of 257 posts

Re: The Secret API of Banks

#111

I hate sounding like a VC jerk, but the banking industry needs some serious disruption.

No, the financial services industry needs some serious disruption. Banks need to be MORE conservative. Not less. "Disruption" in banking is whats caused previous financial crisis.

Managing user interfaces to sell financial products is not the same as running a bank. This is why API's are so important. They allow innovation in the sale of financial products while keeping the actual risk calculations on deposits and loans heavily regulated.

Of course, banks don't like them. In the same way internet providers don't like net neutrality. Nobody wants to be commoditised. But this segregating of responsibility is the only way you can ensure positive change for consumers/businesses without introducing a bunch of risk into a critical piece of the economy.

Re: The Secret API of Banks

#112
post #109

Earlier quoted context omitted.

What user facing aspects bug you the most?

If I want to make my financial life difficult in the sake of security, that should be my choice. I'm sick of banks saying, either implicitly or outright, "we don't want to ratchet up security measures because people will find it inconvenient. You can say that because it's not your money on the line. Why can't I ask for chip-and-pin or nothing? No chip-and-signature, no swipe-and-pin, no swipe-and-signature,no it's-le…

"I'm sick of banks saying, either implicitly or outright, "we don't want to ratchet up security measures because people will find it inconvenient. You can say that because it's not your money on the line."

But my money is not on the line. That's what a credit card is - I'm using the bank's money, and I am not charged for fraud. If the bank was seeing excessive amounts of fraud, they would ratchet up security measures.

However, any security measures should be treated with skepticism - do they measurably increase security, or do they serve merely to transfer responsibility away from the banks?

"Why can't I have a card inactive by default-"

You can get single use numbers on many cards, which I think would solve your use case.

Re: The Secret API of Banks

#113

Earlier quoted context omitted.

> - On-restaurant-table credit card swipe rather than taking the card away and entering tip later. Many places overseas do this almost universally. This isn't a problem you can solve by changing the banking industry. This is a point-of-sale problem.

I disagree entirely. The problem is that the US banking industry permits this state of affairs. They should require updated, at-table point-of-sale devices within a reasonable timeframe to be able to continue to take credit cards.

It always seemed odd to me that the card readers are owned by the retailer. On the one hand, that leads to a lot of old or insecure-by-design equipment in circulation as 'not worth the cost to replace", and on the other hand, it tends to lead to a lot of annoying spam calls of "we'll replace your machine if you switch your payment processing to our company."

If the upstream providers provded the readers as a leased service instead-- maybe for a few dollars a month-- they could push out insecure gear in a timely manner more aggressively. Just reject connections from old devices because everyone renting the old model has been sent a new one already. It would also eliminate the price of equipment upgrades as a leverage for competitors to peel off customers.

From what I can tell, the machines are fairly locked to the service providers, and require fairly intensive setup, so it's not necessarily like an unlocked phone where you'd save money by buying a device independently of the service.

Re: The Secret API of Banks

#114
post #41

Earlier quoted context omitted.

> On-restaurant-table credit card swipe rather than taking the card away and entering tip later. Many places overseas do this almost universally. If they took the card away, how would you enter the card's PIN? That's why places outside the USA do the swipe on the table.

In the US, almost universally, they take the card away. Swipe it somewhere in the back -- without a PIN. Then bring back a receipt for an inked signature, which is supposed to the be the alternative to a PIN. Oh, and you put the tip in on that receipt, and they go back and do a second entry of the tip (sometimes incorrectly, almost always higher when incorrect.) Worse - the transaction alert -- if you get one -- is t…

FYI if they enter the final amount incorrectly you can dispute the charge with your credit card provider. It's probably a stronger case if you kept your own copy with the final amount that you wrote down.

Re: The Secret API of Banks

#115

In the UK the fintech (Financial Tech) scene is becoming more prevalent, for the better. Recently I switched to a new online-only bank called Monzo. It's fully licensed and all accounts are insured up to a certain amount by the UK government. It's great. They're in the top charts for apps in the UK now on the iOS App Store. There's a few other alternatives like Starling Bank and Revolut too. They're very good. They'r…

Revolut are a nightmare. After using it for several months and fully verified I apparently entered a CVV incorrectly on one transaction. Revolut blocked the card but with no notification, and no inapp indicators, all showed normal in app, all toggled enabled for maximum flexibility. It took ages to figure out, but swiping the card or using online was now returning to the merchant 'FRAUD/STOLEN' marker rather than just insufficient funds, this lead to Ayden blocking me from merchants and other hell. Best of all support kept telling me my account was fine and all enabled, it was only after Twitter escalation I learnt about a backend block their support staff couldn't see. Ridiculous, weeks to sort, dozens of tickets, suggestion to train support staff or provide in app indicator of block was ignored.This shit still happens today, avoid Revolut. Fintech can be rough, it ain't all great, tread carefully. Oh and they delete feedback from forums if not positive lol

Re: The Secret API of Banks

#116

In the UK the fintech (Financial Tech) scene is becoming more prevalent, for the better. Recently I switched to a new online-only bank called Monzo. It's fully licensed and all accounts are insured up to a certain amount by the UK government. It's great. They're in the top charts for apps in the UK now on the iOS App Store. There's a few other alternatives like Starling Bank and Revolut too. They're very good. They'r…

Revolut are a nightmare. After using it for several months and fully verified I apparently entered a CVV incorrectly on one transaction. Revolut blocked the card but with no notification, and no inapp indicators, all showed normal in app, all toggled enabled for maximum flexibility. It took ages to figure out, but swiping the card or using online was now returning to the merchant 'FRAUD/STOLEN' marker rather than jus…

Thank you so much for posting this. Kept waiting for my Revolut invite, but now I know to steer clear.

Re: The Secret API of Banks

#117

The actual secret API of banks-and by the way this is the initial strategy Plaid pursed if rumor is to be believed (essentially without the consent of the banks)-is by reverse engineering mobile app APIs. Most of these bank APIs try to use cheesy secret token vending to prevent casual API traffic on their endpoints, but the reality is that a sufficiently instrumented Android kernel (or rooted iOS device) will let you…

Why don't banks sell API access at a rate s/similar/lower than Google Maps API access? This is starting to feel like music and video piracy all over again.

Because the value is in not being commodified. Not giving API access is worth more than charging for it.

If all of your credit lines, checking, savings, and investment accounts were an API call away, the institutions providing those no longer build relationships that can be profitable; they're simply utilities you could swap out interchangeably. As such, they're not a fan of this idea.

Re: The Secret API of Banks

#118
post #109

Earlier quoted context omitted.

If I want to make my financial life difficult in the sake of security, that should be my choice. I'm sick of banks saying, either implicitly or outright, "we don't want to ratchet up security measures because people will find it inconvenient. You can say that because it's not your money on the line. Why can't I ask for chip-and-pin or nothing? No chip-and-signature, no swipe-and-pin, no swipe-and-signature,no it's-le…

"I'm sick of banks saying, either implicitly or outright, "we don't want to ratchet up security measures because people will find it inconvenient. You can say that because it's not your money on the line." But my money is not on the line. That's what a credit card is - I'm using the bank's money, and I am not charged for fraud. If the bank was seeing excessive amounts of fraud, they would ratchet up security measures…

> But my money is not on the line.

Well, I tend to think in context of a debit card, but covering your ears and screaming "zero fraud liability" doesn't solve everything.

You're still incurring costs and hassle getting your account detangled after a fraud, and the trouble for getting the cards reissued. The bank itself is going to have to deal with the costs of insurance and payments it was unable to recover. Eventually, somehow we're paying for that in higher fees or worse rates.

It also tends to undermine the fundamental legitimacy of the bank. Remember when banks tended to be big free-standing buildings with huge visible vaults? The message was "we're keeping your money safe." Not "we don't keep it safe, but we have really awesome insurance when we inevitably mess it uo!"

Re: The Secret API of Banks

#119

In the UK the fintech (Financial Tech) scene is becoming more prevalent, for the better. Recently I switched to a new online-only bank called Monzo. It's fully licensed and all accounts are insured up to a certain amount by the UK government. It's great. They're in the top charts for apps in the UK now on the iOS App Store. There's a few other alternatives like Starling Bank and Revolut too. They're very good. They'r…

Revolut are a nightmare. After using it for several months and fully verified I apparently entered a CVV incorrectly on one transaction. Revolut blocked the card but with no notification, and no inapp indicators, all showed normal in app, all toggled enabled for maximum flexibility. It took ages to figure out, but swiping the card or using online was now returning to the merchant 'FRAUD/STOLEN' marker rather than jus…

No bad experiences so far with Revolut, but will admit the customer support is pretty terrible. I had to enquire to the CS team about the top-up limit and ended up getting all of my answers from forums instead of the CS team.

Re: The Secret API of Banks

#120
post #82
post #35

Earlier quoted context omitted.

This is, on one hand, great. I made the switch to a similar bank myself a few years back. What I failed to realise at the time was how exposed I became to the vulnerabilities associated with being cashless. Cash is not just an ancient relic. Cash is an ancient relic and a fundamental component of a free society. My country has, in practise, become nearly cashless and I used to be proud to be one of the very early ado…

Could you elaborate on the risks of not using cash for you?

I guess ending up in a situation where you need cash to pay for something.
Post reply on HN