5 ms·
How Plaid Reconciles Pending and Posted Transactions
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- lol768 7y agoThis mostly seems to be required because banks don't provide usable data properly. There should be a way to tie together authorisations and finalized transactions. Any API/interface that doesn't permit this is just broken. Monzo's API includes a unique transaction ID as well as a timestamp to indicate when (if it has happened) the transaction 'settled'. The open banking APIs implemented by the CMA9 include a BookingDateTime and Status (Booked or Pending) and an immutable transaction ID. It's surely just common sense to do this. Why is there no regulation to require banks expose a usable API in NA?
- liveoneggs 7y agowhy would a bank be required to expose this for a 3rd party commercial user?
- arcticbull 7y agoIn my mind the question is why wouldn't they be? It's your transaction data, you have many legitimate uses for it, why not require open access? It's like GDPR but for your bank records. The data's available now, it's just crap. Sometimes banks need a kick in the pants to straighten up.
- thepangolino 7y agoIt should be required to pass it on to you and for you to seamlessly pass it on to any third party of your choosing.
- ChrisSD 7y agoAs mentioned on another thread, the UK enforces such an API for the largest banks (it's voluntary for the others at the moment) https://www.openbanking.org.uk/ https://www.openbanking.org.uk/ This is part of a wider "challenger bank" initiative. Creating space for smaller, usually digital only, banks to create more competition in the consumer banking market. This was thought to be especially important after the "too big to fail" crash. Directly breaking up the larger banks was never going to happen, so instead they created an environment where competition could (hopefully) flourish.
- liveoneggs 7y agothe US doesn't need more banks. The market is actually culling them dramatically- https://www.fdic.gov/bank/statistical/stats/2019Mar/FDIC.pdf https://www.fdic.gov/bank/statistical/stats/2019Mar/FDIC.pdf (number of banks since 1990!) From what I can tell there are 10x (about) as many "banks" in the US.
- syn0byte 7y agoWe don't have the whole story of their infrastructure and that a lot of Plaid's data sources are scraped and/or aggregated and repackaged in nonstandard ways. ACH and transaction tracking have been working fine for the last 20 years prior to a clever ML system. Nacha ACH spec per BoA for example: https://files.nc.gov/ncosc/documents/eCommerce/bank_of_america_nacha_file_specs.pdf https://files.nc.gov/ncosc/documents/eCommerce/bank_of_ameri...
- lol768 7y agoIt's not exposed though, right? ACH is just for banks settling between themselves, is it not? The entire point of OB and PSD2 is that any regulated company can get access to this data.
- jaden 7y agoIt's encouraging to see Plaid making this level of effort to be accurate. It seems like it could be a viable alternative to Mint using something like https://github.com/yyx990803/build-your-own-mint https://github.com/yyx990803/build-your-own-mint (written by the author of Vue.js). It's scary to think what would happen if one of these services (Mint, Personal Capital, Plaid) had a backend data breach. If they can log in to your financial sites, a breach would mean the attacker would be able to as well.
- ceejayoz 7y ago> If they can log in to your financial sites, a breach would mean the attacker would be able to as well. As an added bonus, banks may disclaim liability because you shared your credentials with a third party.
- temp129038 7y agoIsn't it more scary to think how many people are so cavalier with sharing their online banking credentials with a third-party app like Plaid? I don't think enough people realize that when you authenticate with Plaid, even for apps that don't provide "Mint-like" functionality and have no need for your transaction history, you're giving that developer permission to pull your transaction history, personal information, account balance, etc without any additional permission at anytime.
- 7y ago
- dangero 7y agoReminder that most banks still don’t provide an oauth api for granting read only access to your account info, so we end up with scraping data and problems like this to solve. Plus there is a ton of completely unnecessary risk created here by forcing users to furnish full access credentials to their bank accounts. It’s beyond stupid.
- temp129038 7y agoOn the other hand, it's crazy to me that we're all talking about how evil Facebook is for selling the fact that I liked "Family Guy" 15 years ago but for some reason we're all OK cheerleading a company that literally enables real-time financial surveillance on unsuspecting users with a purposefully deceitful onboarding flow that hides any mention of what permissions you're actually providing and no simple way to revoke those permission.
- ctoth 7y agoOn the other other hand it literally takes 30 seconds to change your bank credentials so...