6 ms·
Because of this we created Bankscrap[1], a Ruby gem to access multiple banks. We basically find the APIs that the Banks are using for their mobile apps and expo
by javiercr 10y ago
Because of this we created Bankscrap[1], a Ruby gem to access multiple banks. We basically find the APIs that the Banks are using for their mobile apps and expose them through a common Ruby library with an unified data model.
Each bank has an open source adapter (this is different to Teller) and we encourage the community to help us building more adapters. So far we got adapters for 4 major banks in Spain, and 3 more are a work in progress.
Whether PSD2 is going to happen or not, we believe public APIs for banks will happen (even if banks don't like it).
IMHO banks arte not scared because of security concerns: they all have APIs in production already, they are just not documented. Their main concerns is basically how APIs used by third party services could affect their businesses.
[1] https://github.com/bankscrap/bankscrap https://github.com/bankscrap/bankscrap
- slavoingilizov 10y agoSo who bears the legal responsibility? Is it the business which uses your gems or the customer? You're effectively breaking most banks' terms of service, at least in the UK. It's great that you've solved the tech challenge, but that's not the biggest one to solve.
- javiercr 10y agoFrom our understanding what we do is legal in the EU, according to the European Union Computers Programs directive 2009: > The person having a right to use a copy of a computer program shall be entitled, without the authorisation of the rightholder, to observe, study or test the functioning of the program in order to determine the ideas and principles which underline any element of the program if he does so while performing any of the acts of loading, displaying, running, transmitting or storing the program which he is entitled to do. There is in fact a EU proceeding against MathWorks for preventing a competitor to reverse-engineering their product to achieve interoperability [2] In any case, we currently offer no guarantee to our users and we encourage them to use our open source libraries at their own risk. [1] http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2009:111:0016:0022:EN:PDF http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2... [2] http://europa.eu/rapid/press-release_IP-12-208_en.htm http://europa.eu/rapid/press-release_IP-12-208_en.htm
- delinka 10y agoI'm not sure you've addressed the concern. Sure, reverse-engineering an interface is legal. However, use of these APIs by third-party, non-vetted apps or libraries potentially incurs other legal risks. I suppose you've somewhat addressed it with your final comment: "...at their own risk." I'm not risking access to all my money on using your library to access my bank account. If you say the risk is mine, and, since I'm using your library rather than an approved binary, the bank can show that the risk is mine, when someone finds and exploits a weakness in your library to take my money, I'm screwed.
- slavoingilizov 10y agoExactly! If someone hacks my bank, I can sue them and get my money back. If someone hacks the app using your library, I have zero rights. No business would take that risk and use your library at scale. Yes, open source is great, etc. But it doesn't solve the problem.
- javiercr 10y ago> If someone hacks the app using your library. Sorry, but I still don't understand what you mean here. There could be a bug in the library in the same manner that there could be bugs in any other open source library. Could those bugs become a security issue for your app? Yes, they could. Despite of this we all use open source software, right? Let's say you were using Active Merchant[1], would you sue Shopify if someone hacked your app to process irregular payments through your Bank's payment gateway (accessed by Active Merchant [2])? [1] https://github.com/activemerchant/active_merchant https://github.com/activemerchant/active_merchant [2] https://github.com/activemerchant/active_merchant/tree/master/lib/active_merchant/billing/gateways https://github.com/activemerchant/active_merchant/tree/maste...
- drvdevd 10y agoAlso, most OSS licenses protect the developers against this kind of nonsense anyway ('...not guaranteed fit for any purpose...'), for good reason.
- farnulfo 10y agoSometimes ago I found the weboob (Web Outside Of Browser) which has CLI for french banks : http://weboob.org/applications/boobank http://weboob.org/applications/boobank
- javiercr 10y agoWe weren't aware of this project. It's interesting. However it looks like is just a collection of web scrappers. This is the implementation for Barclays bank: https://git.weboob.org/weboob/devel/blob/master/modules/barclays/browser.py https://git.weboob.org/weboob/devel/blob/master/modules/barc... Bankscrap, despite of its name, tries to avoid web scraping in favor of XML/JSON apis provided by the banks. Right now all our working adapters are API-based, not web scrapers.
- jgust 10y agoThat is an unfortunate domain name, unless it's meant to be purposefully amusing.
- farnulfo 10y agoI think it is :-)
- m_t 10y agoIt seems to a be very recurring discussion in the comments on each LinuxFR release post. You can add that some modules have the same kind of name (BNporc which would translate to BNswine for BNP Paribas[0]). Or some applications: QHandjoob[1], QFlatBoob[2] or QHavedate[3] where the icon is a stickman with an erect penis getting ready to have sex doggy style[4]. They used to have a nazi svatiska on the Caisse d'Épargne module logo[5]. At least they changed that one. Really, how anyone could use that professionally is beyond me. [0] http://weboob.org/modules#mod_bnporc http://weboob.org/modules#mod_bnporc [1] http://weboob.org/applications/qhandjoob http://weboob.org/applications/qhandjoob [2] http://weboob.org/applications/qflatboob http://weboob.org/applications/qflatboob [3] http://weboob.org/applications/qhavedate http://weboob.org/applications/qhavedate [4] http://weboob.org/media/images/applications/qhavedate.png http://weboob.org/media/images/applications/qhavedate.png [5] https://symlink.me/projects/weboob/repository/changes/modules/caissedepargne/favicon.png?rev=fa3b0ee1 https://symlink.me/projects/weboob/repository/changes/module...
- koolba 10y agoWhy doesn't the User-Agent in this adapter reflect the actual library? https://github.com/bankscrap/bankscrap-bbva/blob/master/lib/bankscrap/bbva/bank.rb#L11 https://github.com/bankscrap/bankscrap-bbva/blob/master/lib/... Does it break functionality if you don't pretend to be an Android phone? Adding the library version in their would be helpful for debugging too. Ideally it'd be possible to override at the app level so that it correctly shows up in their logs.
- javiercr 10y agoThat's a good question. We try to mimic as much as possible the requests that banks' mobile apps would do to avoid them becoming "hostile".