Earlier quoted context omitted.
For future reference the tip off is that YNAB/Plaid asks for your bank account's username and password directly. If they were using some proper API, you'd be redirected to an Authorization page on your bank's domain where you could review the requested permissions and the app requesting, and then choose to grant it.
Exactly this, Plaid "kindly requests" you violate the ToS you have with the bank and hand over the keys to your finances. I have never noped out of anything so hard.
Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
111–120 of 257 posts
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#112It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…
In the UK, which has implemented open banking already, you can use services like https://syncforynab.com/ (no affiliation, just a happy customer) to link your accounts to YNAB. Some challenger banks like Monzo and Starling allow you to set up webhooks for transactions so they're immediately available in YNAB through Sync for YNAB rather than having to use x-hourly syncs via open banking companies that are officially…
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#113Earlier quoted context omitted.
Depends on where you are - a SIM swap attack is surprisingly easy to do in many places. But more generally, a sophisticated actor doesn't have to be targeting you specifically. Many people assume that "nobody would put in so much effort to steal from me ", but they don't have to be. A sophisticated attacker with the capability to intercept SMS would likely be casting a very wide net. Once people start noticing, they'…
This argument seems strange to me.. how many attacks are by someone literally armed with a customer list from a financial institution? The "casting a wide net" seems directly opposed to the effort involved in a SMS intercept attack which requires significant resources. I don't see a practical circumstance where this is a reasonable risk I guess. I just don't know. I would love an article-length explainer out there so…
If your wide net lets you see 2FA codes, sometimes you can do stuff.
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#114Earlier quoted context omitted.
> The big telecom lobbying argument vs CRTC about how urban markets need to subsidize rural infrastructure costs is not something 95% of canadians like to hear, but it kinda makes sense (They say rural infra simply isn't cost effective because Canada is so expansive, but you expect high speed Internet access in your Muskoka cottage, right?) That still doesn't explain why internet service is way more expensive in Cana…
I don't mean this to be crass, I presume you've never driven across Canada then? I suspect if you had, you'd very soon realize why it's so expensive. 11 people per square mile, the same as Botswana, except at least in Botswana you can just drive in a straight line for hours, and you don't have snow salt and freezing temperatures to contend with. If a team from Rogers in Toronto had to go to Kenora Ontario to service…
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#115It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…
It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#116It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…
> YNAB (You Need A Budget) use services like Plaid to...take my username and password and impersonate me to get my banking data WHAT. THE. F. I'm a longtime, happy YNAB user. I had no idea this was going on until just now. I always just assumed there were secure APIs used to import my data. YNAB's Capital One "integration" stopped working a few years ago (possibly because they cracked down on screen scraping?) and I…
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#117Earlier quoted context omitted.
I don't mean this to be crass, I presume you've never driven across Canada then? I suspect if you had, you'd very soon realize why it's so expensive. 11 people per square mile, the same as Botswana, except at least in Botswana you can just drive in a straight line for hours, and you don't have snow salt and freezing temperatures to contend with. If a team from Rogers in Toronto had to go to Kenora Ontario to service…
Except what matters is the density distribution. 85% of Canadians live within 100 miles of the US border, for instance. https://www.vox.com/2016/5/5/11584064/canada-population-map
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#118As a developer living in a country that has fully implemented "Open Banking", here's a quick setting of expectations for Canadian developers so they don't get too excited as I did when this was first being introduced. Open Banking is not, in fact, open in almost any sense of the world. It is standardised and the standards are freely available ("open"), but other than that, you still need to have an official "blessing…
Sounds like the situation in Australia, which NZ sounds like they’re copying.
https://www.apicentre.paymentsnz.co.nz/join/api-community-co...
So it's "free for 12 months", but the idea is that I build or create an "innovation".
Not interested, I just want APIs for my data, I'm not interested in building a SaaS, I don't want that kind of responsibility for other people's data.
Back to using my personally developed scraper, driven by puppeteer.
Side-benefits, I can and have adapted my scraper to also pull my data from other institutions, like investments and retirement accounts, and dump it into a database as JSON and normalized form.
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#119It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…
Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.
Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023
#120Earlier quoted context omitted.
Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.
Edit: Never mind, I was confusing the use of Plaid for linking accounts (like Robinhood does) with its use to actually monitor accounts (like YNAB).