Live data from Hacker News

Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

news.ycombinator.com

31–40 of 47 posts

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#31
post #24

Hi all - co-founder of Plaid here. We're in the process of migrating this repository and replacing it with a dedicated iOS SDK repo, JS SDK, and (soon to be) Android SDK. However, I messed up the order of operations with this migration and can empathize with the reaction. I personally chatted with a lot of the commenters on the original issue before we did this and more than happy to engage/get feedback from anyone e…

No offense, but I think we’d all be better off with open bank API standards in the US.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#33
post #22

Plaid really do seem a little dodgy to me. In the UK they are effectively offering a PSD2-API forwarding service, which seems very much against the spirit of PSD2 and the open banking initiatives.

Plaid is mainly US where PSD2 does not apply. Banks sometimes get together to work on these topics but it rarely goes well (see ofx/ofc). What more frequently happens is a company like Plaid forces it and then works with banks to satandardize.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#34
post #28
post #24

Hi all - co-founder of Plaid here. We're in the process of migrating this repository and replacing it with a dedicated iOS SDK repo, JS SDK, and (soon to be) Android SDK. However, I messed up the order of operations with this migration and can empathize with the reaction. I personally chatted with a lot of the commenters on the original issue before we did this and more than happy to engage/get feedback from anyone e…

Can we get a way where we can centrally manage linked accounts? I have at least 5 apps that use plaid and I should be able to go to your website and see what authorizations I have enabled and disable them.

Yes! We're actually working on something in this space that I'm really excited about. If you shoot me an email I can get you on the beta and would love your feedback!

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#35

Earlier quoted context omitted.

What would you recommend for ACH bank account verification?

Micro deposit while cumbersome and slow, works fine. I don't believe access to all of my most personal data should be ‘frictionless’.

Micro deposits definitely do not work fine. If banks offered an authenticated way to confirm bank account & routing number instantly and without access to txn history, would be much better.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#36
> Plaid imitates major bank account UIs in their login forms to make users more comfortable submitting their bank credentials to Plaid.

But it's even worse than that. They're training their users to ignore the security advice that their banks and other web providers have been trying to teach them for years, which makes them more vulnerable to phishing attacks. As one of the commenters on Github said[1]:

> This is horrible, horrible, horrible, horrible, horrible practice. Any malicious actor can copy your design and present a perfectly genuine-looking Plaid input form and gather bank credentials from victims. There's absolutely no way to tell whether a Plaid input form is genuine without examining the HTML source of the page, which is far beyond the ability of almost all users. What good is your $1000 EV cert and your brand's hard-won trust if the user just sees Wacky Joe's Discount Dolphin Assholes, secured by letsencrypt.org in the area of the address bar where we've been telling them to look for a trusted name for about the last decade?

The commenter's next paragraph also bears repeating:

> You guys need to get your act together and realize that you're not in the business of hosting Wordpress blogs or building marketing pages for the latest Barbie Rides Horses Again game somehow still coming out for the Nintendo DS. You collect bank credentials. Re-read the previous sentence. Do it again. Essentially my entire net worth is kept in my Schwab brokerage account which shares the same login as my Schwab checking account. If someone gets my Schwab credentials and I don't notice before they empty me out, my life is over. You simply cannot half-ass security best practices for the sake of UX convenience.

[1] https://web.archive.org/web/20190415103059/https://github.co...

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#37

Plaid needs to be exposed as one of the most unethical companies in SV. If people are worried about online privacy then they should really be worried about a company that is so deceiving and makes it basically impossible to revoke permissions on something as sensitive as access to your bank account and transaction history once granted.

To revoke access change your bank password. My biggest concern with any of the bank api providers is who they use to scrape the banks. Most are offshore outside the reach of US law enforcement or court system.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#38
post #34
post #28

Earlier quoted context omitted.

Can we get a way where we can centrally manage linked accounts? I have at least 5 apps that use plaid and I should be able to go to your website and see what authorizations I have enabled and disable them.

Yes! We're actually working on something in this space that I'm really excited about. If you shoot me an email I can get you on the beta and would love your feedback!

Neat. I'll shoot you an email in a bit!

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#39

> Plaid imitates major bank account UIs in their login forms to make users more comfortable submitting their bank credentials to Plaid. But it's even worse than that. They're training their users to ignore the security advice that their banks and other web providers have been trying to teach them for years, which makes them more vulnerable to phishing attacks. As one of the commenters on Github said[1]: > This is hor…

I completely agree, but having your life savings under the same login as your checking account is insanity. Maybe I'm overly paranoid but I wouldn't even log in to my broker from my phone.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#40
post #24

Hi all - co-founder of Plaid here. We're in the process of migrating this repository and replacing it with a dedicated iOS SDK repo, JS SDK, and (soon to be) Android SDK. However, I messed up the order of operations with this migration and can empathize with the reaction. I personally chatted with a lot of the commenters on the original issue before we did this and more than happy to engage/get feedback from anyone e…

No offense, but I think we’d all be better off with open bank API standards in the US.

So maybe Plaid will be what Venmo was to Zelle. I have been following this space for a while now. When Plaid came into the picture, it made Yodlee be more open. So maybe in 10 more years we will have open bank APIs.

They have been trying to get banks to have APIs for years with no luck -- ofx/ofc. Mint went their own way for scraping and Watsi died because they did NOT want to do scraping. I was actually surprised when 2 years ago Xero got a "direct integration with Wells Fargo. Synapse got some funding a couple of days ago one can certainly hope

Post reply on HN