Live data from Hacker News

Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

news.ycombinator.com

41–47 of 47 posts

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#41

> Plaid imitates major bank account UIs in their login forms to make users more comfortable submitting their bank credentials to Plaid. But it's even worse than that. They're training their users to ignore the security advice that their banks and other web providers have been trying to teach them for years, which makes them more vulnerable to phishing attacks. As one of the commenters on Github said[1]: > This is hor…

I completely agree, but having your life savings under the same login as your checking account is insanity. Maybe I'm overly paranoid but I wouldn't even log in to my broker from my phone.

You also might not want to keep your entire life savings in a single account. It's convenient, but also a single point of failure.

And if your life savings gets big enough, it might exceed the account balances that are protected by FDIC ($250K) or SIPC ($500K, I think).

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#42

> Plaid imitates major bank account UIs in their login forms to make users more comfortable submitting their bank credentials to Plaid. But it's even worse than that. They're training their users to ignore the security advice that their banks and other web providers have been trying to teach them for years, which makes them more vulnerable to phishing attacks. As one of the commenters on Github said[1]: > This is hor…

You mentioned EV certificates, but are those actually still meaningful? Troy Hunt wrote a series of articles [0][1][2] about the perceived value of Extended Validation certificates, and concluded that they were essentially useless.

Does anyone else have additional data for/against EV certs nowadays?

[0] https://www.troyhunt.com/on-the-perceived-value-ev-certs-cas...

[1] https://www.troyhunt.com/extended-validation-certificates-ar...

[2] https://www.troyhunt.com/paypals-beautiful-demonstration-of-...

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#43
post #22

Plaid really do seem a little dodgy to me. In the UK they are effectively offering a PSD2-API forwarding service, which seems very much against the spirit of PSD2 and the open banking initiatives.

It's very convenient. But also very expensive (maybe) The raw costs of getting an AISP licence are about £1000 in the UK... but that's ignoring all of the time and effort to understand PDS2, legals etc but $500+/month for Plaid to do it for you ? I'm not sure. Sounds avoidable like vendor lock in to me.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#44
post #24

Hi all - co-founder of Plaid here. We're in the process of migrating this repository and replacing it with a dedicated iOS SDK repo, JS SDK, and (soon to be) Android SDK. However, I messed up the order of operations with this migration and can empathize with the reaction. I personally chatted with a lot of the commenters on the original issue before we did this and more than happy to engage/get feedback from anyone e…

I don't think people are upset about the repo being "archived" and having lost access to the issue, per se. I think people are (justifiably) furious because you offer a product which is fundamentally insecure in it's current state and seem to refuse to fix it. And it's not that websites which are using your product are susceptible to attacks, but that a malicious website can impersonate your product and it will be indistinguishable from a legitimate site. Let that sink in. A malicious website can be indistinguishable from a legitimate customer of yours, and users WILL enter their banking information. That is the heart of people's completely justified outrage here, and it's baffling that anybody on your security team could have possibly signed off on this. If people on your security team don't see the problem here they should be immediately fired and never work in the security field again. You guys better have some really expensive lawyers, because it feels like you are being criminally negligent here and should absolutely be held liable when some users inevitably have their lives destroyed as a result.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#45
post #34
post #28

Earlier quoted context omitted.

Can we get a way where we can centrally manage linked accounts? I have at least 5 apps that use plaid and I should be able to go to your website and see what authorizations I have enabled and disable them.

Yes! We're actually working on something in this space that I'm really excited about. If you shoot me an email I can get you on the beta and would love your feedback!

There’s no glory in being excited to launch a basic permissions/access panel for end users of an auth product that should’ve shipped on Day 1. Shameful.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#46
Not to downplay the security implications here, but Plaid has pretty much changed finance. It’s a straightforward case of trading security / privacy for functionality. Apps like Venmo, Robinhood, Wealthfront, and most every other financial startup would not exist without Plaid.

Re: Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs

#47
post #24

Hi all - co-founder of Plaid here. We're in the process of migrating this repository and replacing it with a dedicated iOS SDK repo, JS SDK, and (soon to be) Android SDK. However, I messed up the order of operations with this migration and can empathize with the reaction. I personally chatted with a lot of the commenters on the original issue before we did this and more than happy to engage/get feedback from anyone e…

No offense, but I think we’d all be better off with open bank API standards in the US.

Obviously. But why would banks ever do that? They see Robinhood, Lending Club, Venmo, etc as competitors. No way there going to open up API’s to them unless the government forces the banks to do it.
Post reply on HN