Live data from Hacker News

The Secret API of Banks

gduverger.com

211–220 of 257 posts

Re: The Secret API of Banks

#211

Earlier quoted context omitted.

The problem is that the value of an API is in the fact that it is open as in open , not "open" like "open banking". An API that can only be accessed by a few huge players is next to useless. Those guys have already figured out a workaround for the lack of APIs, mainly screen-scraping. However the real innovation comes from small startups, sometimes originating from a one-man side-project - this "open" banking complet…

Maybe the problem arises from this different interpretation for "open" that different people have. Look, the Linux source code is open. But doing something meaningful with it takes a huge effort. A one man team can't build Android out of Linux. This doesn't make it less open. The bar is higher because those companies will literally have access to to all of you financial information and your money. And not just yours,…

> just not how you want it

Which is a big deal in 2018 and the era of open data, data portability (even Facebook offers data exports). Why don't banks offer data exports?

Re: The Secret API of Banks

#212

Earlier quoted context omitted.

At the moment you can already grant third parties access to your data - you can pass along your online banking credentials and they will scrape the web UI (there is an entire industry built on that - companies like TrueLayer will take any bank’s credentials and some cash and give you JSON in exchange, scraping the online banking UI behind the scenes). Stupid people will be stupid and will find a way to shoot themselv…

You are not and were never prevented from accessing your own data . You keep repeating that while also mentioning you have options to access it. You may not like the options you have to access that data because you have different needs than most other people. But insisting you're not allowed feels more than just exaggeration. Open banking means it's not 100% proprietary and exclusive to each bank, it doesn't mean the…

I am prevented from accessing my own data. A lot of bank's online banking is absolutely awful and doesn't go back more than 3 months worth of transactions.

Thankfully none of this bullshit actually applies to me (I use Monzo Bank which does have an API) but I feel the pain for everyone else.

> it doesn't mean they have to open all doors and say "do what you want, I'm not even here"

So hold on, does this means we now need regulation on how we can use cash? Because at the moment, stupid people can withdraw all their cash and throw it away, and nobody is there to prevent them from doing so.

How about we let people be responsible for their own data, and let them do whatever they want with it?

Re: The Secret API of Banks

#213
post #173

Earlier quoted context omitted.

> If you allow people access to their own account data via an API then they will seek out software to help them access it Is that a bad thing? How about we let people do whatever they want with their data? Not to mention the lack of APIs doesn’t stop this - there is an entire industry built on top of scraping bank’s web UIs. Companies like TrueLayer will happily take online banking credentials and provide you with an…

> Is that a bad thing? Of course not. But it makes sense to ensure that the vendors of these products are FCA approved. > How about we let people do whatever they want with their data? For the same reason we can't have quite a lot of other nice things - scammers and shysters will take advantage. > there is an entire industry built on top of scraping bank’s web UIs. There is, and now you can have a choice - a well fun…

> For the same reason we can't have quite a lot of other nice things - scammers and shysters will take advantage.

In that case, let's get rid of cash, cards, and frankly everything, because otherwise scammers will take advantage.

Re: The Secret API of Banks

#214
post #173

Earlier quoted context omitted.

> Is that a bad thing? Of course not. But it makes sense to ensure that the vendors of these products are FCA approved. > How about we let people do whatever they want with their data? For the same reason we can't have quite a lot of other nice things - scammers and shysters will take advantage. > there is an entire industry built on top of scraping bank’s web UIs. There is, and now you can have a choice - a well fun…

> For the same reason we can't have quite a lot of other nice things - scammers and shysters will take advantage. In that case, let's get rid of cash, cards, and frankly everything, because otherwise scammers will take advantage.

Allowing anyone to use any software to access their banking data would allow them unprecedented abilities to automate, and attack.

I'm sorry if you don't feel that's adequate. Perhaps you should have a conversation with one of the many people that object to OpenBanking because it's far too permissive and they don't want the possibility of any third party getting their banking data, ever, oversight or not.

Re: The Secret API of Banks

#215

Earlier quoted context omitted.

You are not and were never prevented from accessing your own data . You keep repeating that while also mentioning you have options to access it. You may not like the options you have to access that data because you have different needs than most other people. But insisting you're not allowed feels more than just exaggeration. Open banking means it's not 100% proprietary and exclusive to each bank, it doesn't mean the…

I am prevented from accessing my own data. A lot of bank's online banking is absolutely awful and doesn't go back more than 3 months worth of transactions. Thankfully none of this bullshit actually applies to me (I use Monzo Bank which does have an API) but I feel the pain for everyone else. > it doesn't mean they have to open all doors and say "do what you want, I'm not even here" So hold on, does this means we now…

> Because at the moment, stupid people can withdraw all their cash and throw it away, and nobody is there to prevent them from doing so.

This is not actually a real world problem though. If it were it would likely be addressed.

Why do so many people think only in theoretical extremes?

Re: The Secret API of Banks

#216
post #215

Earlier quoted context omitted.

I am prevented from accessing my own data. A lot of bank's online banking is absolutely awful and doesn't go back more than 3 months worth of transactions. Thankfully none of this bullshit actually applies to me (I use Monzo Bank which does have an API) but I feel the pain for everyone else. > it doesn't mean they have to open all doors and say "do what you want, I'm not even here" So hold on, does this means we now…

> Because at the moment, stupid people can withdraw all their cash and throw it away, and nobody is there to prevent them from doing so. This is not actually a real world problem though. If it were it would likely be addressed. Why do so many people think only in theoretical extremes?

I don’t see account access being abused either. People could already be giving out their credentials, but somehow it’s not happening, so I don’t see the argument against personal access tokens.

Re: The Secret API of Banks

#217

Earlier quoted context omitted.

Maybe the problem arises from this different interpretation for "open" that different people have. Look, the Linux source code is open. But doing something meaningful with it takes a huge effort. A one man team can't build Android out of Linux. This doesn't make it less open. The bar is higher because those companies will literally have access to to all of you financial information and your money. And not just yours,…

> just not how you want it Which is a big deal in 2018 and the era of open data, data portability (even Facebook offers data exports). Why don't banks offer data exports?

It's mostly because your Facebook account doesn't have a balance :).

On the other hand I'm not sure what data you need exported and can't. A bank data export is the monthly bank statement. Most banks allow you to to export every transaction going back some years from the app or website. Going further back you can address the bank and they will provide you with such an export going as far back as the local laws mandate.

You're going to have some issues getting realtime access and this is the how I was referring to. Pretty sure Facebook doesn't help you with this either.

Re: The Secret API of Banks

#218

Earlier quoted context omitted.

You are not and were never prevented from accessing your own data . You keep repeating that while also mentioning you have options to access it. You may not like the options you have to access that data because you have different needs than most other people. But insisting you're not allowed feels more than just exaggeration. Open banking means it's not 100% proprietary and exclusive to each bank, it doesn't mean the…

I am prevented from accessing my own data. A lot of bank's online banking is absolutely awful and doesn't go back more than 3 months worth of transactions. Thankfully none of this bullshit actually applies to me (I use Monzo Bank which does have an API) but I feel the pain for everyone else. > it doesn't mean they have to open all doors and say "do what you want, I'm not even here" So hold on, does this means we now…

> online banking is absolutely awful and doesn't go back more than 3 months

It doesn't mean you can't request it directly with the bank. It is more cumbersome but they have to be able to provide that data as far back as the country's laws require them to keep it.

It's just that usually data older than 12-24 months is archived and I can guarantee you no API no matter how open it is will allow you to get the data directly from the archive. That's not what the system is meant to do. You'll still get 1-3 years but using a generic app instead of a proprietary one. And you just moved the goalposts.

> So hold on, does this means we now need regulation on how we can use cash?

Moving your own cash has always been your business. But touch someone else's cash or account has always been regulated, yes. Some companies manage to exploit some gaps in that regulation and give you something but that's not because they should, it's because they can :).

Let me give you an example: you can treat your illness as you please. But if you want to treat other people's illnesses you need a medical degree. A pretty high bar. Unfair, right? :)

> How about we let people be responsible for their own data, and let them do whatever they want with it?

You're basically advocating for the removal of most regulation anywhere. I'm not sure you understand the implications. Which makes me think you'd be the first one to complain that nobody put rules in pace so you don't get bitten just as soon as "being responsible" bites you back.

Re: The Secret API of Banks

#219
post #121

The actual secret API of banks-and by the way this is the initial strategy Plaid pursed if rumor is to be believed (essentially without the consent of the banks)-is by reverse engineering mobile app APIs. Most of these bank APIs try to use cheesy secret token vending to prevent casual API traffic on their endpoints, but the reality is that a sufficiently instrumented Android kernel (or rooted iOS device) will let you…

Cert pinning. EOL.

Can be easily bypassed.

Re: The Secret API of Banks

#220

Earlier quoted context omitted.

Which is utter nonsense. They already have APIs, they're used in their mobile apps.

That's not an API, that's a private protocol for which they can easily anticipate and control load (e.g. by pushing changes to their apps).

All the banks I'm with use rest APIs in their apps (you can see this by MITMing the traffic), no "private protocol" whatever the hell that is.

As for controlling load, I'm not sure I follow. If you have 1m people with the mobile app installed and all of them decide to check their balance at the same time your systems are going to crumble if you've only provisioned for 10,000.

Web/Mobile banking doesn't talk to the mainframes directly, it's essentially a caching layer which gets committed later when the mainframe does it's job. Not much different from your average web app just with longer delays.

Post reply on HN