Earlier quoted context omitted.
It's the same in France, yet some aggregators (e.g. Bankin) are using those credentials directly (and afaik the risk is handled via some sort of insurance). I'm personally waiting for the PSD II law to be deployed (see https://blog.teller.io/2016/04/26/tauth.html ) in order to have clear-cut protections & boundaries, before leveraging Bankin or similar (Teller) as a SaaS product builder.
How do you actually share your credentials? I assume you have to provide a 2FA-token when logging on?
Teller – API for your bank account
91–100 of 282 posts
Re: Teller – API for your bank account
#92Earlier quoted context omitted.
Sure they might find out an App Update was issued in the App Store... but they cannot possibly know what API changes were made without reverse-engineering the API's all over again. Not to mention, once they discover what changed, now this service has to go make the changes on their system... meanwhile that bank doesn't work with this service anymore. So the App is broken for some undefined period of time.
The bank has to deploy their client code to all of their users before they can depreciate the old API. That should give them plenty of buffer time to reverse engineer the changes.
"All" of their client code is a bunch of apps, that mostly auto-update. My bank (small town credit union) has a banking app that refuses to work at all unless it's the most recent version of the App. I see no reason why this would be a challenge for the bank - it's only a challenge for this service.
Re: Teller – API for your bank account
#93Re: Teller – API for your bank account
#94When will this be available in the US?
You need legally available reverse engineering without dmca-hammer to be applied plus PSD2 directive coming soon forcing banks to open.
Those are EU things.
Re: Teller – API for your bank account
#95Earlier quoted context omitted.
It seems like they would only find out after the update has been pushed, though - ie, after the app has been broken. Unless they have relationships with the banks now, and would be given a heads-up. Perhaps that's the case. It sounds like it may be.
Apps won't be updated instantaneously on devices, though. There'll have to be some backwards compatibility for a good while if the banks want to change their APIs drastically. You can't just shut down access to your customers apps.
Yes you can, and banks already do this. Even the E-Trade app refuses to work unless it's on the most current version. When you control the apps and the API, you can pretty much do as you please.
Re: Teller – API for your bank account
#96"We realise that our revenue will most likely be a very long tail with a small number of customers bringing in most of the cash." Either they or I don't understand what long tail means.
Re: Teller – API for your bank account
#97How many times have you thought to yourself “Damn, I really wish my bank account had an API”? Now that's an intro!
You think? For me as a Dutch guy my only though was "literally never". We have ideal for payments ( https://www.ideal.nl/en/payment-service-providers/ ) and every bank has its mobile app that is integrating via ideal. So all payments on my phone the app just pops up, I do a finger scan and done. All apps are very decent for all normal banking business. I can't think of any use case I would need to trust a third party…
Re: Teller – API for your bank account
#98How many times have you thought to yourself “Damn, I really wish my bank account had an API”? Now that's an intro!
At this point I'd take the enterprisey German API over nothing.
I'd love our government or the EU stepping in.
Re: Teller – API for your bank account
#99Which countries are supported? Not seeing that info anywhere. I only saw in a comment here that Teller has relationships with "every major UK bank".
It is UK only.
Re: Teller – API for your bank account
#100Earlier quoted context omitted.
I believe this is true for most US banks also. I can't even count how many promising-looking Fintech products I had to pass over because the only auth mechanism they offered was through sharing online banking credentials. Until bank policies regarding credentials-sharing actually change, I think it's really irresponsible for products to even ask for credentials at all, let alone offer it as the default/only auth opti…
Users could be unwittingly putting their entire life savings at risk. Is this a realistic concern? I thought the point of a bank was that situations like that can be reversed 100% of the time.