7 ms·
I am sure I will be called naive, but this is shocking to me. I assumed that Plaid was integrating with the banks and not doing this sort of thing because of th
by throwaway9980 6y ago
I am sure I will be called naive, but this is shocking to me. I assumed that Plaid was integrating with the banks and not doing this sort of thing because of the people associated with Plaid. Their seed round included Spark Capital and Google Ventures. Their most recent round included Mary Meeker and Andreessen Horowitz. [1]
These investors have reputations to protect. This type of thing would certainly come out in diligence:
"How do you gain access to the customer's account data with their bank?"
"We impersonate their bank."
"Do you tell them you do this?"
"No."
"Ok, that's probably fine."
How in the hell does this conversation pass muster?
[1] https://en.wikipedia.org/wiki/Plaid_(company)#Funding https://en.wikipedia.org/wiki/Plaid_(company)#Funding
- purple_ferret 6y agoA lot of these banks never had any APIs. Plaid made its name basically scrapping the html of account pages. Companies used it because there were no alternatives (no apis)
- throwaway9980 6y agoI understand the situation. Another of Plaid's investors is Goldman Sachs. I naively assumed that Plaid's ability to build their product was likely based on access to private APIs available to them based on their relationships and backing. If someone came to me and asked me to build what Plaid has built, I would decline the work. I would assume that impersonating a bank would be illegal. I would assume that the banks I am impersonating would treat me as a malicious actor. I would assume that I would go to jail for building a system like this. Absolutely unbelievable.
- f430 6y agoBack when I used to run a web scraping shop, we had this exact request. I didn't know it was illegal at the time but we ultimately didn't do it because lot of people just want to pay as little as possible for scraping without considering the amount of work that goes behind it.
- jjeaff 6y agoWeb scraping is not illegal per se. Though it may be against the specific terms of service of the site you are scraping.
- f430 6y agothat was before the 2018 ruling this was back in 2012, I remember Craigslist sued someone for scraping under CFAA. Thanks to EFF, this scummy tactic used to kill Aaron Swartz is no more.
- o-__-o 6y agoYou are misremembering. CFAA defines criminal acts not civil, so Craigslist could not sue someone under the CFAA. The DA would have to bring charges first and then the civil suit by Craigslist would reference the criminal suit.
- TuringNYC 6y agoEven if it isn’t illegal it can be against the terms of service and void your warranty/insurance
- LegitShady 6y agofraudulently obtaining people's banking information can be described many ways. The prosecutors won't call it web scraping and the judge hasn't seen that although he has heard of people who steal users information to hack their banks. Seems like a bad bet to me.
- tadfisher 6y agoPlaid does have real integrations with some institutions, using OAuth and the works. The list is relatively miniscule compared to the vast majority of institutions that still consider customer data their asset and not their customers'.
- jsinai 6y agoOn the other hand, Plaid’s behaviour means that your data is not yours either, but is up for grabs by a 3rd party for which you may not have given consent to. Plaid is no Robin Hood (the story not the app) here.
- Nextgrid 6y agoPlaid is equivalent to a carrier, right? They merely provide the data to their client (whatever service/app you're signing into) and it's up to that client to decide how to use it.
- thayne 6y agoI've learned that when it comes to banks, assuming things like that is usually wrong.
- f430 6y agoI don't think you are naive at all regarding this but generally people see famous people, name dropping and due diligence goes out the window. There are people who take advantage of that and are very successful. Disgusting because it is just another form of deceiving people's trust.
- tadfisher 6y agoI'm surprised, because Plaid is far from the first mover in the "scraped banking data API" space. Mint (now Intuit) and Yodlee come to mind, and they use essentially the same sign-in flow and come with the same limitations. There are organizations and companies that are trying to do this legitimately, through open standards and real incentives to both FIs and customers to share information in exchanges: - Open Banking Project: https://www.openbankproject.com/ https://www.openbankproject.com/ - MX: https://www.mx.com/ https://www.mx.com/ P.S. Can we get real Markdown support already? The fact that the Markdown URL format isn't supported is extremely user-hostile.
- shrimp_emoji 6y ago>P.S. Can we get real Markdown support already? The fact that the Markdown URL format isn't supported is extremely user-hostile. Hear hear! Markdown is definitely the new formatting standard, and it's amazing (I even take notes in .md files).
- throwaway9980 6y agoYou're right, they aren't the first. That said, when I use accounting software, it's pretty obvious to me that I am going to be sharing my transaction history with the accounting software. When I connect my bank account to Venmo, it is absolutely not obvious to me that I'm sharing my entire transaction history with Plaid. Replicating the appearance of my bank's login screens is critical to the illusion. Even if I did understand that they are storing and using my credentials, I should be able to expect from a reputable business that they are not scraping irrelevant transaction data and then using it for purposes that don't explicitly support the app I am using. Selling my transaction history definitely isn't supporting the use case I'm authorizing.
- milesskorpen 6y agoFortunately, Plaid doesn’t sell your transaction history, so this isn’t a concern.
- Cederfjard 6y ago
- Ihaveacomment12 6y agoI won't name names, you can Google them, but these people are ethical for optics. These are the same people supporting Modi, who's arguably worse than trump, a man who was banned from flying into America. Same capitalist who have injected a significant amount of capital to Indian Oligarchs like Ambani, to fund JIO and aggregate a billion users. Under the covers you'll find corruption in the deepest levels. 250M , yes Million, protested these same Oligarchs - and I'm surprised this isn't getting connected up the chain. Maybe a matter of time?
- kripy 6y agoThey're not hiding the fact. From their website [1]: "When you choose to connect your financial accounts to an app using Plaid, you will be prompted to enter the username and password associated with those accounts. Plaid then links your accounts to the app you want to use so you can share your data." [1] https://plaid.com/how-it-works-for-consumers/ https://plaid.com/how-it-works-for-consumers/
- waprin 6y agoDisagree, they are hiding the fact by assuming ignorance of most users. A true “link” , would use something like OAuth to have the bank handle authentication and provide explicitly scoped subset of consumer data to Plaid. Instead they are taking the plaintext password and getting total access. Just taking that passwords itself is a security vulnerability. Google doesn’t even know your Gmail password, just the hash, but since Plaid can’t use a password hash to login, it must store your plaintext password to your financial accounts, some of THE most sensitive data. Furthemore they have access to way more data than they should rather than clearly defined scoped subsets of it. The whole company is a privacy and security disaster. Of course it’s annoying that banks don’t provide reasonable OAuth APIs, but Plaid “disrupts” that by deceiving consumers into dangerous security vulnerabilities with their most sensitive personal data.
- dmak 6y agoYou speak idealistically, but the reality is that many of these banks did not having open banking standards nor APIs before. The scraping led to this movement and FSAs all over the world are starting to push for no scraping while financial institutions create APIs and contracts with these platforms.
- ZephyrBlu 6y ago"link" to me implies something along the lines of a FB/Google/GitHub OAuth login, not that they steal my credentials. I guess technically they just say, "you will be prompted to enter the username and password associated with those accounts" and don't specify that they (Plaid) will be using your credentials, but I don't think it's clear enough that you are giving your credentials away!
- etaioinshrdlu 6y agoVC's actually tend to love companies that are a little bit sneaky. Just not too sneaky to have to face consequences.
- abrowne 6y ago"Disruptive".
- conradev 6y agoThey do integrate natively with some banks, like JPMC: > When this is implemented, Plaid will access customer information through the bank’s secure API (application programming interface) connection. That will allow customers to share their information more safely and quickly with Plaid and the financial apps it supports while protecting their bank username and password. and also Wells Fargo: > The API used in the agreement will utilize a more secure, tokenized “handshake” between the companies’ servers through which customers’ financial data will be shared. Once integrated, the API will allow customers to share their financial data, while also maintaining the privacy of their user credentials. The enrollment process will be easy and designed to work seamlessly within Plaid-supported apps’ user experiences. I think it would be good to do some quick Google searches before getting (all of) the torches out. https://media.chase.com/news/plaid-signs-data-agreement-with-jpmc https://media.chase.com/news/plaid-signs-data-agreement-with... https://www.businesswire.com/news/home/20190919005081/en/Wells-Fargo-and-Plaid-Sign-Data-Exchange-Agreement https://www.businesswire.com/news/home/20190919005081/en/Wel...
- joshspankit 6y agoIn the “startup” world, this is simply the only way to do it when your goals are to be everyone’s service. Banks rarely create open APIs, and even when they do they are fragile and subject to whims as the banks are optimizing for security first (plus: they need strong incentives to maintain APIs since it’s not even in their core business). And since you can’t rely on an API, “there’s no other option” which compounds with the fact that coding up a web scraper for a specific bank takes maybe a dozen programmer-hours. Then throw on a disclaimer to cover legal, and start counting your billions of unhatched eggs.
- casey77 6y agoLet’s not forget the companies that enabled Plaid to do this. One of the worst offenders was Carta. They made you use Plaid to exercise your stock options. So you had to let Plaid scrape your account info to get the stock you worked so hard for. Most people had no idea they were allowing this.
- o-__-o 6y agoIt’s clear as day in the privacy policy. You did click on the privacy policy link and read through it right?