Live data from Hacker News

Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

news.ycombinator.com

21–30 of 47 posts

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#21

This is the first time I'm hearing of Plaid and is it actually something banks have signed-off on and are ok with? This whole thing looks to make for a bad precedence.

Absence of open banking standards and regulation produces such monsters.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#23
post #8

Earlier quoted context omitted.

can you revoke by changing your password?

I’m not sure, but does it matter? I take issue with a product that markets to consumers as an easy way to authenticate for the purpose of pulling or pushing funds, but is actually authorizing developers to scrape years of transaction history in 20 minutes, my real time balance, my phone/email/address etc. without another level of permission. It’s disgusting. I just wanted an alternative to microdeposits to prove to a…

In Europe we have PSD2 and similar things which are working towards much more of an oauth type of situation.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#24
Hi all - co-founder of Plaid here. We're in the process of migrating this repository and replacing it with a dedicated iOS SDK repo, JS SDK, and (soon to be) Android SDK. However, I messed up the order of operations with this migration and can empathize with the reaction. I personally chatted with a lot of the commenters on the original issue before we did this and more than happy to engage/get feedback from anyone else over email/phone/in-person. Feel free to shoot me an email at william [at] plaid [dot] com if you want to chat/have any feedback.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#25

I feel it's worth bearing in mind that this is normal to the point that the financial regulator in the UK standardised the activity as part of the EU-wide PSD2. It is being phased out in favour of open banking in the next couple of years, now that there's a requirement for more OAuth-like approaches. (In fact, Plaid just launched in the UK on the open banking APIs) Banks are well aware that this is a thing and they'r…

Here the Finnish Financial Supervisory Authority stated in Jan 2018 that this practice is not allowed:

https://www.finanssivalvonta.fi/en/regulation/interpretation...

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#26

Here's my main beef with Plaid: a lot of times when you use it as an end user you have no idea that you're giving one of Plaid's customers full history on all of your transactions, accounts, credit cards, loans, etc. Plaid presents you with a ToS that you will probably never read. Compare that to something like "Sign-in with Google" or "Sign in with Github". They put it in plain english exactly what the website you a…

I wonder if an enterprising attorney general could try to go after Plaid for CFAA violations. They are arguably making unauthorized, fraudulent access to banks’ computer systems.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#27
post #23

Earlier quoted context omitted.

I’m not sure, but does it matter? I take issue with a product that markets to consumers as an easy way to authenticate for the purpose of pulling or pushing funds, but is actually authorizing developers to scrape years of transaction history in 20 minutes, my real time balance, my phone/email/address etc. without another level of permission. It’s disgusting. I just wanted an alternative to microdeposits to prove to a…

In Europe we have PSD2 and similar things which are working towards much more of an oauth type of situation.

In Europe there are industry consortiums working specifically on the account access topic: https://www.openbankingeurope.eu/

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#28
post #24

Hi all - co-founder of Plaid here. We're in the process of migrating this repository and replacing it with a dedicated iOS SDK repo, JS SDK, and (soon to be) Android SDK. However, I messed up the order of operations with this migration and can empathize with the reaction. I personally chatted with a lot of the commenters on the original issue before we did this and more than happy to engage/get feedback from anyone e…

Can we get a way where we can centrally manage linked accounts? I have at least 5 apps that use plaid and I should be able to go to your website and see what authorizations I have enabled and disable them.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#30

Plaid needs to be exposed as one of the most unethical companies in SV. If people are worried about online privacy then they should really be worried about a company that is so deceiving and makes it basically impossible to revoke permissions on something as sensitive as access to your bank account and transaction history once granted.

probably so, but the if you look at all the large recent successes in SV, all of them have had serious moral and legal lapses. As they are well funded, and have powerful friends, they have thus far avoided jail time.

So my cynical view, is that Plaid is just playing a game of doing what works and has proven to work. I am not excusing their bad behavior, just trying to point out what's motivating it. Robbers will always rob, and cheaters will always cheat, but we as a society need to make it less profitable to rob and cheat--and not just for the lower classes, for the elites as well.

Rahm Emanuel wrote on this recently in The Atlantic, and then shortly thereafter took a well paid job in financial services. So I guess, more do as I say not do as I do.

https://www.theatlantic.com/ideas/archive/2019/05/middle-cla...

Post reply on HN