3 ms·
I am not yet convinced that giving away your bank username and password to plaid/mint/other scrapers does not exempt the bank from the liability limits establis
by zonethundery 8y ago
I am not yet convinced that giving away your bank username and password to plaid/mint/other scrapers does not exempt the bank from the liability limits established in Reg E.
The user effectively gives away control of their deposit accounts. If it is subsequently misused (unlike an access device like a debit card), the user's disclosure of the password might give the bank an affirmative defense. Push to shove, in a large breach with bulk cashouts via wire a depository institution might not honor the claims.
It seems obvious that revocable access w/ tokens is a solution, but that gives up the game on the transaction data (and likely drives some of banks' reluctance to offer that functionality).
I'd love to have my mind changed about this, if someone can point me in the right direction.