11 ms·
Fintech startup Plaid raises $250M at a $2.65B valuation
- bonsai80 8y agoThe thing that keeps me away from all of these kinds of things is the requirement to hand over my user/pass for financial accounts. Questions for those that know the space: 1. Is that a big struggle for fintech companies or do most people just shrug it off? 2. Are companies working on (and making progress) standards for system communication without user/pass?
- yoran 8y agoDoes anyone know if such a thing exists in Europe?
- jorge-d 8y agoThere is Bankin[0] which I believe shares a few similarities, however it mostly works with French bank accounts for now. [0] https://bankin.com https://bankin.com
- deleted 8y ago[deleted]
- BukhariH 8y agoThe original one (expensive): https://www.yodlee.com/yodlee/europe-africa https://www.yodlee.com/yodlee/europe-africa UK startups: https://teller.io/ https://teller.io/ https://truelayer.com/ https://truelayer.com/
- carlsborg 8y agofigo too perhaps
- scient 8y agoI hope not, because its such a shitshow. You literally give your bank credentials to a third party who then logs in to your account and scrapes info off of it - info that you have no control over. Capital One was smart enough to block them off (which is the bank I use), and now they actually provide proper OAuth based APIs to access your account.
- deleted 8y ago[deleted]
- asianthrowaway 8y agoThings are changing with PSD2 regulations. Banks in the EU starting in 2019 will have to provide open (and secure) APIs to third parties.
- scient 8y agoOne can only hope this would make it to the US as well. The problem largely seems to be banks being ancient behemoths in terms of technology, and introducing APIs like this poses a significant risk from security and policy perspective. Plus its not going to be a major source of revenue either, so why bother?
- tobias3 8y agoWell, at least in Germany we kind of have the FinTS protocol to get at the data and don't have to scrape. So less need for an intermediary. I also saw something about EU regulations for bank APIs, but unfortunately not one common API.
- travisoneill1 8y agoStartup. $2.65B valuation. I guess "startup" just means any non-public company now.
- mlevental 8y agowelcome to 5 years ago. I see people opening up conventional small business (think pizza place) calling themselves startups. but really who cares
- estsauver 8y agoI think the pg definition of "A startup is a company that is pursuing a very high growth strategy" still applies. If you believe Plaid is trying to get themselves to 5B in the next two years, it can probably still apply. I think of it as "Startup" vs "Steady State."
- akarma 8y agoThere's been a whistleblower or two on HN about how Plaid scapes and sells your bank account transaction history to third parties. It seems more unethical than most selling-user-data strategies in that the users don't even know Plaid is involved in the transaction whatsoever; they're just a hidden middle layer. I'd be interested to know if this is still part of their monetization strategy, or if anyone at Plaid can confirm definitively that they do not collect and sell your bank account transaction history? Edit: So sorry on my part, specifically on selling data, must've mixed this up now that I've read the comment (linked below). It involved scraping user data against the wishes of the banks, and doing huge amounts of customer analytics with such data, and another separate thread on giving transaction history as part of the service. Still a negative but different than above-- will leave this up so as to not destroy thread.
- lbotos 8y agoThey at least collect it, as they offer that as a service: https://plaid.com/products/transactions https://plaid.com/products/transactions I flirted with the idea of using a trial account to feed that data to a Prometheus server to build graphs in Grafana. A slightly more powerful mint/personal capital would be a super valuable tool.
- bdcravens 8y agoYes - the key issue being is that the product offering is an API used by second-party with assumed permission from first-party; they are not selling that data to a third-party.
- randomacct3847 8y agoIt’s the Facebook API issue but IMO transaction data is much more sensitive so it’s a bigger issue. I have used the Plaid API and have no idea how they audit developers to make sure they are using the data as intended and storing that data securely. One hack incident of a developer that exposes bank numbers and transaction data would be a huge reputational hit.
- 8y ago
- rchaud 8y agoThe billion-dollar battle to share your personal financial information to even more unaccountable third parties.
- jncraton 8y agoI'm interested to see where this goes. I use Plaid as a developer, and it feels like the user experience keeps getting worse. This isn't Plaid's fault, but as more and more financial institutions require 2FA, it gets much less automatic for Plaid to scrape data. Instead of just seeing updated transactions, users frequently need to enter a 2FA code before Plaid can successfully complete the update. This is very clunky, especially if you've linked 10+ accounts. Hopefully, Plaid (or even government regulations) will be able to encourage banks to create real APIs and Plaid can move away from scraping entirely.
- dpflan 8y agoWasn’t YC company Standard Treasury trying to help banks become more API accessible? If the banks have an API an offering, I can see how a standard would need to exist to support the primary use cases (auth, balance, transaction), and perhaps Plaid is showing what they could look like (reducing the complexity of interfacing disparate banks’ approaches to managing bank data). [NB: if there is a standard or info I am clearly not knowledgeable of based upon this comment, please educate me!]
- colinloretz 8y agoThat was the goal but they were acquihired by Silicon Valley Bank. https://www.svb.com/news/company-news/api-banking-startup-standard-treasury-joins-silicon-valley-bank/ https://www.svb.com/news/company-news/api-banking-startup-st...
- kbyatnal 8y agoAnd then they left SVB to try again https://treasuryprime.com https://treasuryprime.com
- dpflan 8y agoWow. Thanks for the update. From TP"s site: """ We're the team behind Standard Treasury and the Silicon Valley Bank API Banking Platform which forms the backend for Stripe Atlas - we're the experts in this space. """
- eurothrow 8y agoCan anyone point to a list of apps/services that use this? For privacy reasons, I'd prefer to avoid anything of the sort.
- astura 8y agoYou would know if you're being asked for your banks username and password by a third party and can decide if you want to share that information; it's not something that you really need to know anything about ahead of time to be able to avoid. The apps I know who use Plaid are Drop and Venmo. Some banks use it to instantly link external accounts without having to do trial deposits.
- siamakfr 8y agoThat's not entirely true. They try and imitate your bank's branding on the log in page and do not make any mention of Plaid. For example, when setting up Venmo, I thought I was logging into something my bank had created.
- astura 8y agoI mean, the only reason I even know what Plaid is is because the services I've used advertise they are using Plaid, for example, Drop: https://imgur.com/a/l4PM6QG https://imgur.com/a/l4PM6QG I remember seeing it on Citibank too. You're still sharing your bank account information with someone else. Even if it's your bank's API or whatever, "something my bank created" could be "something my bank had hired an external company to create," or even "a front end my bank created that uses third party software to do all the data processing on the back end." I'm not sure of a meaningful distinction between each case. If you want to minimize sharing bank account information "for privacy" then you don't give your bank account information to anyone.
- ghostly_s 8y ago> If you want to minimize sharing bank account information "for privacy" then you don't give your bank account information to anyone. That's the whole point. You don't know you're giving your account information to anyone. I use Venmo and had no idea they relied on this technique until reading your comment.
- dpflan 8y agoWill Plaid be a data brokerage for financial transaction information?
- chatmasta 8y agoPlaid is a great idea, but the implementation worries me. My understanding is that, for most banks, you give Plaid your username and password, and Plaid scrapers on their servers log into your online banking account. Even worse, Plaid obfuscates this behavior from users by replicating their banks login window and making it appear that you are logging directly into your bank. I'm not sure how to feel about this, because I understand that banks' lack of open API access is the central problem. But it seems irresponsible to present Plaid as a secure solution, when its login system is technically a phishing page. I think a much cooler, probably safer, solution would be a mobile SDK that runs the scrapers directly from the user's phone, instead of on Plaid's servers.
- deleted 8y ago[deleted]
- SilasX 8y agoThat ... sounds like it violates every bank's ToS out there, and not the abusive buried-in-fine-print part, either. Every bank could, quite reasonably, cut off your access for this.
- eropple 8y agoThey could, but they won't (barring a change in the ecosystem). Basically everyone does exactly this when a bank doesn't have a federated login system. Take, for example, Personal Capital.
- SilasX 8y agoSo all these services are storing plaintext passwords for the banks?
- eropple 8y agoYup. When done as-correctly-as-possible those passwords should be encrypted on a per-user basis and keys should not be stored in the same datastore as the ciphertext. That's what we ultimately did for a project circa 2013; I assume that most folks do similarly.
- dalbasal 8y agoI spoke to a young guy recently, who is doing a graduate/rotation with one of of the big US banks. He was excited for the rotation in one of the (several) "moonshot divisions," with a goal of 10X-ing the bank in theory. I told him that I hope _giant bank_ doesn't have 10X growth in it, but... ... I think that any truly disruptive idea for fintech/banking is likely to be of the "turn a billion dollar company into a million dollar company" variety.
- creeble 8y agowhy doesn't Mint have is kind of valuation? I guess I don't understand how they differ, I do get that they both rely on giving your bank credentials to a third party and that they both scrape your financial history.
- tommymachine 8y agoMint is owned by Intuit, valued at 53.88B!
- siamakfr 8y agoIs the gist of this company logging into a bank's web service using a user's credentials and scraping their account data and exposing that data via APIs to other developers? I thought they actually integrated with the banks on the backend, but if this is all they do, I'm not comfortable using any product that snoops my bank info without any accountability.
- martinald 8y agoWhat's the difference between Plaid and Yodlee?
- deedubaya 8y agoI’ve stopped using a number of products because the underlying Plaid connection to my banks would routinely break and take weeks (!!) to get fixed. It got to the point that functioning connections was a rarity, and things not working was the norm. I want Plaid to succeed and I want to use those products, but beware of building something on top of Plaid; you may be driving customers away.
- kfroggie 8y ago“Plaid consolidates financial data from multiple sources and categorizes transaction data with up to 24 months of history, making it easy to use and analyze.”
- harryf 8y agoSide note: I once heard from the venture arm of a rather well known CRM that Patagonia gets upset when you embroider your logo on their jackets ( e.g. in this picture https://techcrunch.com/wp-content/uploads/2018/12/DSC1296-2.jpg?w=1390&crop=1 https://techcrunch.com/wp-content/uploads/2018/12/DSC1296-2.... )...
- huac 8y agothat's not true, patagonia offers embroidery themselves: https://www.patagonia.com/corporate-sales-silk-screening-embroidery.html https://www.patagonia.com/corporate-sales-silk-screening-emb... they DO refuse to do corporate orders for certain companies, e.g. oil companies / oil bankers, given that those are antithetical to their mission.
- ejcx 8y agoI met quite a few folks on the Plaid engineering team and was really impressed with the people I met and how they were approaching building their product. Congrats to them, and a lot more work to do!
- elvirs 8y agoI looked into plaid+stripe solution for our ACH payments need and after playing around with it a little I just didn't feel like I can put that in front of my clients and tell them 'Yeah put in your bank login and password on our website to make the payment, we promise it's secure'. Their solution didnt sell with me and I went for Stripe ACH where they make microdeposit and customer has to verify the amounts. Even PaySimple's eCheck solution sounds more reasonable to put in front of clients than to demand their bank login and password. IMHO
- astura 8y agoEvery service I've used where you can verify your account with your bank's username/password had it as an option, not required.
- zonethundery 8y agoI am not yet convinced that giving away your bank username and password to plaid/mint/other scrapers does not exempt the bank from the liability limits established in Reg E. The user effectively gives away control of their deposit accounts. If it is subsequently misused (unlike an access device like a debit card), the user's disclosure of the password might give the bank an affirmative defense. Push to shove, in a large breach with bulk cashouts via wire a depository institution might not honor the claims. It seems obvious that revocable access w/ tokens is a solution, but that gives up the game on the transaction data (and likely drives some of banks' reluctance to offer that functionality). I'd love to have my mind changed about this, if someone can point me in the right direction.
- writepub 8y agoIt seems disingenuous for the banks to not provide an API spec, and then invest in and present Plaid as an alternative. This is not a technology problem, this is about entrenched players making a buck wherever possible, without doing the logical thing. I'm glad Europe has defined an API for it's banks to avoid this from happening there
- sjtgraham 8y ago> I'm glad Europe has defined an API for it's banks to avoid this from happening there Except it hasn't. If you're referring to PSD2, that is not what that is at all.
- Quanttek 8y agoFor those interested: In Europe, banks are forced to provide fintech companies access to customer data when the user consents to this under its "open banking" initiative https://www.cnbc.com/2017/12/25/psd2-europes-banks-brace-for-new-eu-data-sharing-rules.html https://www.cnbc.com/2017/12/25/psd2-europes-banks-brace-for... Personally speaking, i have a problem with companies like Plaid and SOFORT (EU), where they kind-of hide the fact that you provide them with your login credentials (and not the bank). From what I understand from this thread, Plaid may be selling your data and gives developers full access to the customer's transaction history. This is worrying
- vichu 8y agoPer whockey's comment here[0], it doesn't seem like Plaid is selling your data directly to 3rd parties - though it doesn't prevent the developers you're giving your data to from selling it. [0] https://news.ycombinator.com/item?id=18655507 https://news.ycombinator.com/item?id=18655507
- cryptica 8y agoI remember I spoke with both the CEO and CTO over Skype several years ago. They actively reached out to me because of an open source project I created and they wanted to recruit me. They made quite an impression on me but I wasn't prepared to move to the US back then. Damn. Missed opportunity. Obviously they were very proactive in reaching out to the developers that they wanted rather than just passively waiting for resumes to flow in.
- sonnyblarney 8y agoThe thought of giving any of my passwords to a 3rd party is problematic ... but my banking password ? This is an issue. Also a risk, because any bank could simply shut this down pretty quickly and if one does it, the others could follow. The first 3rd party that messes up, with the whiff of a scandal ... and this is going to dissapear, or rather, the banks may decided that they'll do some API, but not for free. I'm waiting for 'Cambridge Analytica' but with your money this time.
- ceejayoz 8y ago> Also a risk, because any bank could simply shut this down pretty quickly and if one does it, the others could follow. I mean, Mint's been doing it for twelve years, and they're hitting thousands of banks. They're definitely on the major banks' radar by now.
- deleted 8y ago[deleted]
- jplahn 8y agoGiving a plug to https://truelayer.com/ https://truelayer.com/. They have a great team and they're making a big push to bring PSD2 compliant banking integrations to Europe. I haven't heard of many other offerings within Europe.
- semerda 8y agoCongrats Plaid! Is Open Banking Standards going to abolish any international market opportunities for Plaid? - CMA9 Major Banks in the UK are ready to roll out Open Banking Standards. - In Australia the ACCC is pushing for 1 July 2019 and within 12 months all Australian banks, including the related brands of the big four, will be brought within the scope of open banking. - Canada too with it's 2020 initiatives. US would be crazy not to adopt a similar standard but maybe this is where Plaid is specializing in due to the large number of US banks?
- CodeSheikh 8y agoI would not be comfortable giving my banks, cards info to Plaid so they can provide an easy integration (API) to third party developers. Why Venmo would need to hit Plaid API to get my banking info when they can provide their own API and allow seamless integration with my bank and credit card? I honestly don't see the benefit over risk of handing over all my financial institutions information so they can provide a seamless API to consumers.
- RGamma 8y agoIsn't it bloody easy enough already to pay for stuff? Fintech startups (this one with its dubious implementation especially) with huge valuations make me sad...