Live data from Hacker News

Teller – API for your bank account

blog.teller.io

171–180 of 282 posts

Re: Teller – API for your bank account

#171
post #167

Can someone explain to me this dichotomy I see with the almost thermo-nuclear war when it comes to copyright protection of total drivel, but when it comes to fin-tech there is literally a flourishing industry of screen scraping typing companies and well-publicized plays like Mint and it's just like a big shrug? How are these companies able to mitigate through the banking companies TOU and such?

It's always about money.

Banks benefit from certain bugs/holes in their software (e.g. shitty UI for viewing transaction history/balance -> more overdrafts -> more fees).

With copyright, why create something new when you can just sue somebody?

Re: Teller – API for your bank account

#172
post #117

Earlier quoted context omitted.

Enterprisey APIs with adoption beat nicely designed APIs without adoption anytime. Besides, that does not explain, why none of the other banks can get their act together. If FinTS is too difficult to implement, how come they are not offering something simpler?

> Enterprisey APIs with adoption Your conflation of "bad" with "enterprisey" is unfortunate. Also, is it really adoption if different banks only support specific features/versions? > If FinTS is too difficult to implement, how come they are not offering something simpler? Well banks aren't really in the business of APIs, are they? Nobody is graduating #2 in their class at Stanford with a CS degree and going to work f…

Banks aren't in the business of offering APIs because there's little incentive to do so. Even if there were a lack of talented technology-based employees, that likely wouldn't prevent APIs from being developed.

The issue of incentive boils down to the fact that business clients, being the main source of revenue for retail banks, simply aren't making enough noise about their desire for APIs.

Re: Teller – API for your bank account

#173
post #118

This is annoying, I got all excited and then realising this is for a handful of UK banks. Would be great if it were tagged as a UK thing more prominently.

I was really not excited, expecting it to be US-exclusive, until I clicked the link and saw it was UK banks. Whoop ;)

I had he exact opposite reaction: expecting it to be US-exclusive and got to the last paragraph where it said they don't support any US banks. Big ole' :-( face.

Re: Teller – API for your bank account

#175

Earlier quoted context omitted.

This is startup-ese for "Every single one of our users is breaking their bank's ToS, and we maintain plausible deniability by telling them to go and read complex legal documents themselves". I can totally understand the motivation (particularly with PSD2 around the corner, which will mandate banks to provide legit APIs - I'm guessing the plan is to grab market share before that happens). However, I am very skeptical…

Yeah. "No cases of fraud or loss due to screen-scraping" doesn't mean your service isn't going to be the one that leaks a treasure trove of banking credentials. It's also highly probable that it has happened, it just wasn't attributed properly.

Why do you assume everything has already happened? Do you also assume Gmail passwords have already been hacked? Just asking.

Re: Teller – API for your bank account

#176
post #124

Earlier quoted context omitted.

Can you break that down? How do the roaming regulations enable those bigger players to do that?

http://ec.europa.eu/transparency/regdoc/rep/10102/2016/EN/SW... - see page 32 (ARRPU). Operators in different countries have different profits per user (obvious). If you have someone like T-Mobile or Orange, they'll use the proceeds from say... France, to finance their operations in say... Poland. This will put pressure on other national operators to further lower prices. Lower prices mean lower profit margins, mean…

That would be referred to the competition commission and could be blocked.

Re: Teller – API for your bank account

#177

UK banks don't accept any liability if you give your online banking credentials to a third party. If some fraud was to come about as a result of someone using Teller then they would be out of pocket or has Teller got agreements with the compatible banks to overcome this situation (either by Teller reimbursing the customer or the bank)?

Hi, Firstly, we don't always need a credential. Some banks provide other auth mechanisms, e.g. EMV CAP. We use this for Barclays and Nationwide. Using Teller might not violate your bank's terms of service, which is why we advise you to read them in conjunction with ours. Furthermore, it is the view of some senior bank people that I speak to that PSD2 will make such clauses in banking terms illegal. It is also worth m…

Credential storing is a big risk.

While it may be true that there hasn't been historical fraud attributed to "screen-scraping", what has been seen historically is insider fraud - you pretty much have to expect a certain rate of incidents where your own employees, included tenured ones in high trust positions, will intentionally risk jail time and attempt to steal money; in the finance industry (despite all reasonable precautions) it's not a question of if it will happen, it's a question of how often it'll happen (i.e. if it's 1 incident per annum per 100 employees or if it's 1 incident per annum per 1000 employees), how large will be the impact (most precautions don't prevent the risk as such, but limit the amounts involved), and what are you going to do about it.

E.g. the idea that your main technical administrator might sell a database of stored credentials to organized crime; (or get his/her family kidnapped in order to get access to them, that has happened as well) isn't ridiculous fiction, it's a rare but feasible scenario that's more likely to happen than e.g. a datacenter burning down, so what you're going to do in similar cases is quite relevant, not only to your own internal risk analysis but also to your customers. A bank might say "oh, we've got it covered, but if a major hack-event happens, our capital reserves and deposit insurance will still guarantee that you don't lose your savings" - an API company can't fall back on that.

Re: Teller – API for your bank account

#178
post #11

Earlier quoted context omitted.

Your terms: "We are not liable for any loss or damage that may result from your use of our services. This includes any direct, indirect, or consequential losses; any loss or damage caused by tort, including negligence, breach of contract or otherwise." You don't get taken seriously in the financial space with terms like that. You need to accept responsibility for errors and carry errors and omissions insurance. Compa…

Bank of America's assets total over 2 trillion dollars. I would imagine it's easier for large financial institutions to create such strong guarantees for its users.

That's kind of the point - if you have large assets, that might be some assurance of your liquidity if e.g. a $100 million bad event happens; but if you do not and can't pledge large amounts of capital as pretty much a collateral, then you'd be expected or even required to buy insurance for very large amounts.

Re: Teller – API for your bank account

#179

UK banks don't accept any liability if you give your online banking credentials to a third party. If some fraud was to come about as a result of someone using Teller then they would be out of pocket or has Teller got agreements with the compatible banks to overcome this situation (either by Teller reimbursing the customer or the bank)?

Hi, Firstly, we don't always need a credential. Some banks provide other auth mechanisms, e.g. EMV CAP. We use this for Barclays and Nationwide. Using Teller might not violate your bank's terms of service, which is why we advise you to read them in conjunction with ours. Furthermore, it is the view of some senior bank people that I speak to that PSD2 will make such clauses in banking terms illegal. It is also worth m…

> It is also worth mentioning there has never been a single case of fraud or loss attributed to "screen-scraping"

...how do you know?

Re: Teller – API for your bank account

#180
post #167

Can someone explain to me this dichotomy I see with the almost thermo-nuclear war when it comes to copyright protection of total drivel, but when it comes to fin-tech there is literally a flourishing industry of screen scraping typing companies and well-publicized plays like Mint and it's just like a big shrug? How are these companies able to mitigate through the banking companies TOU and such?

There are two main differences between screen-scraping content and screen-scraping transactions.

First is that copyright applies to written content (even short content such as tweets) and does not apply to factual data.

Second is that whatever rights may apply to the data, in the fintech scenario the users are scraping their own data.

So all kinds of copyright-specific laws, of which there are many, don't really apply in this case - and those are the laws that can easily get used against the service provider, unlike the possible ToS violation where the bank would have to against their own customers to enforce it.

Post reply on HN