3 ms·
I often wonder if authors of PSD2 whitepapers ever read the text of the directive they're discussing. PSD2 is _not_ a carte blanche for every regulated PISP/AI
by matthew_192 10y ago
I often wonder if authors of PSD2 whitepapers ever read the text of the directive they're discussing.
PSD2 is _not_ a carte blanche for every regulated PISP/AISP to consume Bank APIs for any arbitrary user. API access will be secured by the Account servicing PSP (ASPSP) security credentials. I.e. in order to initiate a payment the PISP will have to collect the users security credentials (password, mTAN or other OTP) issued by the ASPSP.
Same goes for AISPs, where the customer must be initially authenticated with ASPSP credentials and then authenticate again after 90 days.
- sjtgraham 10y agoYes. Many of them do not read the directive let alone the RTS.
- nickonline 10y agoThere's still so many open questions though * How do I know the PISP/AISP is going to do what they say, how are they accredited? * If Spain has a very lax accreditation process then fraudulent PISP/AISP's will congregate there to scam other europeans - how do you stop this game of wack-a-mole when each country in the EU is defining their own system? * There's hugely complicated Strong Customer Authentication regulation that's just been released in draft adding complexity to an already complex system The problem is not _any_ arbitrary user that people are worried about, it's scams. If I approach 1000 people and 1 manage to scam one, I have access to all their financials