4 ms·
How does it work if not by screen scraping?
by lookingfj 9y ago
How does it work if not by screen scraping?
- amb23 9y agoI'd assume they're taking advantage of the Open API laws for financial institutions in Europe. The US is a long ways away from having this.
- martinald 9y agoIt uses the internal APIs mobile banks use afiak. For what it's worth the open API laws aren't in power yet in Europe and tbh I imagine nearly all banks will fail to implement by the deadline. Or if they do, the APIs will be fairly crippled.
- jasiek 9y agoSo does Europe. Open Banking Ltd in the UK is attempting to develop these standards, but they are working with tens of stakeholders across impossible deadlines - which means they cut scope and quality. And since banks in the UK are sponsoring the show, it is beyond certain that no disruptive moves will be taken, and interests of the incumbents will remain preserved.
- dabeeeenster 9y agoMost UK banks require a 2 factor device so probably not. Maybe there is direct access?
- giobox 9y agoI'm in no position to answer authoritatively, but for what its worth the three accounts I have left in the UK, with different banks, can all be accessed without a 2 factor device.
- vidarh 9y agoMany do, but the key is that the mobile apps generally only require access to 2FA for registration, so if they implement the mobile app interface they can get away with having users use the 2FA device once. This is the case for Barclays, for example, where in fact once the mobile app is registered, that can be used as a Pinsentry (2FA) device replacement.
- sjtgraham 9y agoIt works by using the same private APIs that the bank's own mobile app. We reverse engineer their app, work out the API contract, implement our client, and normalize the data. Reverse engineering mobile APIs is a superior strategy to screen-scraping because: - they already return structured data - the security model for that channel is different, e.g. no need for 2FA all the time so truly unattended use cases are possible - it's much more difficult for banks to make breaking changes. When banks do make a breaking change the old version is supported for a decent amount of time to allow their own banking app users to upgrade, we can take advantage of this window to provide a consistent level of service. Finally, we often don't need user credentials. If there is an option to authenticate with another mechanism during registration, e.g. EMV CAP (A.K.A Barclays PINSentry etc) we use that.
- clappski 9y agoThis all sounds like it could potentially be illegal, have you spoken to a lawyer and cleared it all?
- Alupis 9y agoOr potentially broken easily - since these are private API's that the bank is free to change whenever they feel like it.
- Spivak 9y agoNot without pushing out an update to all of their clients. Which presumably they would know about.
- chrisallenlane 9y agoIt seems like they would only find out after the update has been pushed, though - ie, after the app has been broken. Unless they have relationships with the banks now, and would be given a heads-up. Perhaps that's the case. It sounds like it may be.
- alexbilbie 9y agoJudging by the the developer's twitter account it's probably using the APIs used in the banks' mobile apps