Live data from Hacker News

Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

finledger.com

211–220 of 257 posts

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#211

Earlier quoted context omitted.

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

I'm pretty salty about this. It's totally unethical, they knew it wasn't legal, and yet... they're going to be OK outside the fine? Why do we bother being ethical when nobody besides us gives a shit outside a slap on the wrist? You know how many people thought of Plaid before it was a thing, then rightfully wrote it off as "don't attempt"? What kind of sick precedent does this set? Why do I even bother caring.

And the fine was a joke... less then $1 per person affected.

> Nearly 98 million people were affected, according to the settlement

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#212

As a developer living in a country that has fully implemented "Open Banking", here's a quick setting of expectations for Canadian developers so they don't get too excited as I did when this was first being introduced. Open Banking is not, in fact, open in almost any sense of the world. It is standardised and the standards are freely available ("open"), but other than that, you still need to have an official "blessing…

If you're based in Europe or UK, Nordigen has a completely free API do exactly what you described (I'm one of the cofounders). We're connected to 1,500 EU/UK banks and you can connect your bank account to your script/app without any license, certificates or any fees. We don't charge for accessing banking data, we only charge for complimentary data enrichment services like transaction categorisation. https://nordigen.…

I'm interested in having an API access to my own banking data.

However, personally, this feels almost as bad privacy-wise as screen scraping my bank account.

Reading your privacy policy only promotes my distrust.

I realize I may not be your target demographic though.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#213

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

Don’t tie banks have extra steps to do things beyond read-only authentication?

My bank requires 2FA to send money to new payees. While losing my user/pass would lead to information leak, there’s little chance of my money being shipped off without further breeches.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#214
post #153
post #144

Earlier quoted context omitted.

It's enforced - sometimes - by the bank. My bank provides read access to everything with a username + password, but to transfer money or update details requires an SMS confirmation.

I remember a presentation by the head of security of an Internet-only bank years ago, about banking malware. The latest malware was a man-in-the-browser style one: it intercepted your input and changed what you saw on-screen. This was used to defeat extra authentication: the malware inserted a (fake) deposit (something like "yearly subscription mr. X" for $2134.56) into your on-screen total and phoned home. The victi…

That type of hack doesn’t require the user/password. It’s also on the same league as the Nigerian Prince, just appealing to kindness rather than greed.

Idiots fall for these scams all the time, password not needed.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#215

Earlier quoted context omitted.

Wise (formerly TransferWise) has different meanings for "debit" and "direct debit". Their "debit" option works the way you think. You give only your bank card number, expiry date, and CVV. However, their "direct debit" option requires you to enter your bank debit card number and bank password into Wise's web form. It is not a redirect to the bank website. The URL says " https://wise.com/ ..." when you're asked to ent…

Are you in the US? I think Wise’s ways of adding funds vary depending on what’s available in terms of payment infrastructure in each country. In the UK where Wise is based, direct debits are very common for routine payments but do not require a card number. But for receiving money Wise UK’s closest equivalent right now is to authorise payment via open banking and your bank ( the newish UK specs for doing this are rea…

I'm speaking about Canada. I should have mentioned that. You're right that the payment options are probably quite different in each country where Wise operates.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#216

Earlier quoted context omitted.

Plaid is only one security breach away from being utterly destroyed. And they will take out the financial lives of all their customers with them. It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. The TOS of your online banking probably says that if you disclose your username and password to any third party then you have no liability protections.

> It’s utterly irresponsible and I have no idea how Plaid hasn’t been shut down. You have no recourse if they are breached. Wise (formerly TransferWise) is another example. You have to move funds into your Wise account before you can do a transfer, payment, or currency exchange. Wise offer various ways to fund your account such as wire transfer, credit card payment, debit card payment, etc., each of which has differe…

In what country does it have that option? Doesn't seem to be a thing in Australia as far as I can tell. But we do have multiple different ways of doing free (or free for the sender and very low cost for a merchant) payments and transfers, including real-time transfers to/from financial institutions...

Given that it seems to be a similar case in Europe, UK etc. I assume this might just be a US thing?

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#217

Earlier quoted context omitted.

Hi! I work at Plaid. We’re strong advocates for API-based connectivity -- our goal is for 75% of our traffic to be committed to APIs by the end of the year. As part of that, we've actually converted our integration with Capital One to be 100% API-based and use OAuth for authentication. You can read more here: https://www.capitalone.com/about/newsroom/data-sharing-agree...

What you did was wrong and you all knew it. It seems to have paid off though, so congratulations. Nobody with half a brain would trust you.

I don’t see this as wrong at all, it’s an extremely useful feature with no alternative. Actually if alternatives start to appear it’s to services like theirs.

And insulting their whole user base like this sure will get you lots of support.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#218

It's about time. When I learned that applications like YNAB (You Need A Budget) use services like Plaid to connect to my bank account, and that these services literally take my username and password and impersonate me to get my banking data, I was a little sketched out. I use YNAB every day, and having it connected to my bank account is incredibly useful, but if something goes wrong and Plaid loses my money somehow,…

This put me off this type of banking app the first time I tried to register an account with them ten years ago, and I haven't touched them since.

I suppose EU users have an easier time with the PDS2 directive mandating interoperability between banking actors, but I'm unsure how many have found a way around properly implementing it.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#219
post #92

Earlier quoted context omitted.

> YNAB (You Need A Budget) use services like Plaid to...take my username and password and impersonate me to get my banking data WHAT. THE. F. I'm a longtime, happy YNAB user. I had no idea this was going on until just now. I always just assumed there were secure APIs used to import my data. YNAB's Capital One "integration" stopped working a few years ago (possibly because they cracked down on screen scraping?) and I…

Hi! I work at Plaid. We’re strong advocates for API-based connectivity -- our goal is for 75% of our traffic to be committed to APIs by the end of the year. As part of that, we've actually converted our integration with Capital One to be 100% API-based and use OAuth for authentication. You can read more here: https://www.capitalone.com/about/newsroom/data-sharing-agree...

Do you make it unmistakably clear for new users that if you have a data breach and someone loses $400,000 because you leaked their password, they are likely shit out of luck?

Don't know US regulations, but my country has plenty of case law determining that the customer is liable for every single dollar of loss if someone uses their account details to steal their money or take a massive loan in their name.

Re: Canada calls screen scraping ‘unsecure,’ sets Open Banking target for 2023

#220
post #31
post #24

To everyone in this thread complaining that this is just Canada being Canada and trying to snuff out the upstarts... what the fuck are you going on about? I'm a US citizen and I want this screen scraping / credential sharing / whatever you want to call it to die in a fire already. Forcing banks to implement any sort of API access seems both preferable to the dumpster fire we have today, as well as more inviting to up…

This. As others mentioned, the whole point of an effort towards OpenBanking is that services like Plaid literally store your username/password in their system and impersonate you to do whatever they do. Any software dev worth their salt would instinctively know this is a big security no-no, so to have this happen with your banking credentials of all things and on such a large scale seems insane to me. An effort to im…

And even that effort demonstrates the incompetency of most financial institutions - anyone with a security team worth their salt would have mandatory two-factor authentication, which would make the approach unworkable.
Post reply on HN