Live data from Hacker News

Facebook Asking for Some New Users' Email Passwords

thedailybeast.com

41–50 of 377 posts

Re: Facebook Asking for Some New Users' Email Passwords

#41

Earlier quoted context omitted.

Plaid might be my least favorite company ever. It's such a privacy nightmare and they do not even tell you basic information about what you are sharing (or how to revoke sharing rights) going through their typical flow on some random fintech app. If you look at their website, you could be giving away just the bank and routing number, or potentially your entire bank transaction history, balance, identity information,…

I alluded to this in my other comment, but I don't blame Plaid. Blame the banks - Plaid isn't doing this behind their banks, but with their blessings. Again, Mint was doing this for years. When it comes to Credit Card Fraud, the banks are buying all sorts of AI based solutions - after all it's their money. When it comes to customer cash, then its the wild west. I recently found out that my Wells Fargo password isn't…

> I hope they take data security more seriously than Wells Fargo.

But it doesn't really matter how seriously Plaid takes data security, as their whole business is around providing your account data (including your transaction data) to other companies. What matters is if the thousands of business customers of Plaid take data security seriously.

Re: Facebook Asking for Some New Users' Email Passwords

#42

Title seems misleading. Per the article it seems they demand email confirmation, but merely offer to access your email for you in order to accomplish that. (This is not a defense of Facebook's actions here)

Per the tweets they reported on, there was no alternative. You either have to give Facebook your email password, or you don't get an account.

Re: Facebook Asking for Some New Users' Email Passwords

#43

Earlier quoted context omitted.

Plaid might be my least favorite company ever. It's such a privacy nightmare and they do not even tell you basic information about what you are sharing (or how to revoke sharing rights) going through their typical flow on some random fintech app. If you look at their website, you could be giving away just the bank and routing number, or potentially your entire bank transaction history, balance, identity information,…

I alluded to this in my other comment, but I don't blame Plaid. Blame the banks - Plaid isn't doing this behind their banks, but with their blessings. Again, Mint was doing this for years. When it comes to Credit Card Fraud, the banks are buying all sorts of AI based solutions - after all it's their money. When it comes to customer cash, then its the wild west. I recently found out that my Wells Fargo password isn't…

Why not blame Plaid?

Plaid's value is providing the SDK that developers can plug into their app to connect user bank accounts with their app. They have purposefully decided not to show a very common step in the user-facing bank link/onboarding flow of displaying exactly what information you are providing the developer with (e.g. think about FB Connect, Twitter, and Google and how each requires developers to show exactly what permission is being asked of the user).

Plaid has several endpoints you can hit. It could be as little as the bank number/routing number (to pull/push funds), but it can be years of bank transaction history and/or all identifying information about you from your bank (e.g. names, emails, phone numbers, addresses) and/or your current bank balance as well. An app that doesn't even provide mint-like functionality (e.g. showing your spending habits) could be pulling years of bank transaction history and you would not even know. That's horrifying.

Again, Plaid can and should take responsibility for not showing a simple permissions page. There is no way this is just an "oversight" on their part. It's a deliberate decision because they know it would be a conversion killer if people actually consciously understood how much information they are granting to random apps.

Re: Facebook Asking for Some New Users' Email Passwords

#44

I had someone create a Facebook account with my email once. I let it persist for a year until I got tired of the friend request notices. Did a password reset and deleted the account.

Did you verify the email for them?

I'm not sure how rigorous email verification workflows are in general. I had someone manage to transfer their Apple account to one of my emails a few years ago.

Re: Facebook Asking for Some New Users' Email Passwords

#46

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

Plaid might be my least favorite company ever. It's such a privacy nightmare and they do not even tell you basic information about what you are sharing (or how to revoke sharing rights) going through their typical flow on some random fintech app. If you look at their website, you could be giving away just the bank and routing number, or potentially your entire bank transaction history, balance, identity information,…

[deleted]

Re: Facebook Asking for Some New Users' Email Passwords

#47

Earlier quoted context omitted.

Yes. Mint also does this. From what I've heard, there are a lot of banks without APIs, so the next best approach is to login on behalf of users and scrape the data.

It also implies saving passwords without hashing... Not good.

Sure, but is that not what an online password manager is? :P

Re: Facebook Asking for Some New Users' Email Passwords

#48

All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...

Mint legitmatized that authorization flow years before Plaid came around and the banks decided that was the best way to move forward instead of adopting something like an oauth2 flow.

I remember when Mint first came around, and a coworker was telling me about how cool it was. I started completing the the signup process, but I stopped cold once I realized they needed to be provided account credentials from my bank. Never completed it, and never went back to it. I never thought it would last as long as it had. I guess I gave the public too much credit.
Post reply on HN