I'm interested to see where this goes. I use Plaid as a developer, and it feels like the user experience keeps getting worse. This isn't Plaid's fault, but as more and more financial institutions require 2FA, it gets much less automatic for Plaid to scrape data. Instead of just seeing updated transactions, users frequently need to enter a 2FA code before Plaid can successfully complete the update. This is very clunky…
Wasn’t YC company Standard Treasury trying to help banks become more API accessible? If the banks have an API an offering, I can see how a standard would need to exist to support the primary use cases (auth, balance, transaction), and perhaps Plaid is showing what they could look like (reducing the complexity of interfacing disparate banks’ approaches to managing bank data). [NB: if there is a standard or info I am c…
Fintech startup Plaid raises $250M at a $2.65B valuation
51–60 of 143 posts
Re: Fintech startup Plaid raises $250M at a $2.65B valuation
#52Re: Fintech startup Plaid raises $250M at a $2.65B valuation
#53I want Plaid to succeed and I want to use those products, but beware of building something on top of Plaid; you may be driving customers away.
Re: Fintech startup Plaid raises $250M at a $2.65B valuation
#54Earlier quoted context omitted.
They could, but they won't (barring a change in the ecosystem). Basically everyone does exactly this when a bank doesn't have a federated login system. Take, for example, Personal Capital.
So all these services are storing plaintext passwords for the banks?
Re: Fintech startup Plaid raises $250M at a $2.65B valuation
#55Earlier quoted context omitted.
They could, but they won't (barring a change in the ecosystem). Basically everyone does exactly this when a bank doesn't have a federated login system. Take, for example, Personal Capital.
So all these services are storing plaintext passwords for the banks?
Re: Fintech startup Plaid raises $250M at a $2.65B valuation
#56Questions for those that know the space: 1. Is that a big struggle for fintech companies or do most people just shrug it off? 2. Are companies working on (and making progress) standards for system communication without user/pass?
Re: Fintech startup Plaid raises $250M at a $2.65B valuation
#57Earlier quoted context omitted.
I have my own issues with Plaid, but I think you’re reaching a bit here. Everything Plaid does is opt in by the end user. They’re not selling data unbeknownst to the user (assuming co-founder above is being genuine), the user is giving another service permission to use their data. As for bank logins...that’s been around since long before Plaid. But I agree there must be a better way. Though I don’t have any great pra…
Do users have any idea exactly what they're giving up here though? Do they have fine-grained permissions to allow read-only vs write access, and to choose between transaction and account level data? And is there anything that prevents those second-party developers from then turning around and selling data to third parties (besides their own TOS with Plaid)?
Obviously this is a hugely sensitive service, I’m not denying that. But there’s a way to do it right and it seems that Plaid is attempting to do that. So I’m not ready to declare them evil before they actually do anything evil.
Re: Fintech startup Plaid raises $250M at a $2.65B valuation
#58Plaid is a great idea, but the implementation worries me. My understanding is that, for most banks, you give Plaid your username and password, and Plaid scrapers on their servers log into your online banking account. Even worse, Plaid obfuscates this behavior from users by replicating their banks login window and making it appear that you are logging directly into your bank. I'm not sure how to feel about this, becau…
That ... sounds like it violates every bank's ToS out there, and not the abusive buried-in-fine-print part, either. Every bank could, quite reasonably, cut off your access for this.
Re: Fintech startup Plaid raises $250M at a $2.65B valuation
#59Earlier quoted context omitted.
It’s the Facebook API issue but IMO transaction data is much more sensitive so it’s a bigger issue. I have used the Plaid API and have no idea how they audit developers to make sure they are using the data as intended and storing that data securely. One hack incident of a developer that exposes bank numbers and transaction data would be a huge reputational hit.
Edit: I stand corrected, I didn't think you get full account number access but you do. Leaving original comment below. They don't expose bank numbers though, that's kind of the point. Developer access is all tokenized. That said, plaid does give you access to tons of detailed financial transaction data, and it's easy for companies to tie this to PII in their own systems, and I'm sure many of those companies have less…
Re: Fintech startup Plaid raises $250M at a $2.65B valuation
#60Plaid is a great idea, but the implementation worries me. My understanding is that, for most banks, you give Plaid your username and password, and Plaid scrapers on their servers log into your online banking account. Even worse, Plaid obfuscates this behavior from users by replicating their banks login window and making it appear that you are logging directly into your bank. I'm not sure how to feel about this, becau…
That ... sounds like it violates every bank's ToS out there, and not the abusive buried-in-fine-print part, either. Every bank could, quite reasonably, cut off your access for this.
It's worse than that. Sharing passwords with third-parties typically "voids the warranty." If money is stolen from your account, the bank can deny reimbursing you because giving a third-party your password voids their zero-liability guarant guarantee.