12 ms·
Plaid paid people $500 for their employer payroll logins
- smnrchrds 5y agoI thought duping customers [0] to think they were entering their credentials at their bank website while they were giving them to Plaid was bad. But this is some next level malice. How are they still in business? [0] https://www.ctvnews.ca/business/td-bank-files-lawsuit-against-plaid-accusing-it-of-trying-to-dupe-consumers-1.5145326 https://www.ctvnews.ca/business/td-bank-files-lawsuit-agains...
- shkkmo 5y agoI don't understand how this hasn't resulted in criminal charges when they went after Aaron Schwartz for so much less... If you trick someone into giving your their credentials and use them, how is that not the textbook definition of unauthorized access?
- netflixandkill 5y agoThey got me with that one once, the frame looked exactly like my bank's login and I thoughtlessly assumed it was some kind of federated authentication handoff. This is apparently enough of a problem that my bank is flagging them as likely fraud. Seems like this is going to wind up in court sooner rather than later.
- eloff 5y ago> this was part of a pilot program to build "consumer-permissioned tools that make it easier for consumers to securely share their information digitally." What a useless statement. That could mean anything.
- yonran 5y agoI bet many banks have similar language prohibiting sharing logins, so you could make the argument that the core business of Plaid could be considered hacking under CFAA. I hope that the legitimate use of tools to do things on the Internet will be normalized before this argument is tried in court.
- toomuchtodo 5y agoIt's a matter of having regulators require interoperability as Europe did with PSD2 [1]. Plaid is a hack due to legacy financial institutions not being required to provide these interfaces by regulatory bodies. [1] Revised Directive on Payment Services (PSD2)https://en.wikipedia.org/wiki/Payment_Services_Directive#Revised_Directive_on_Payment_Services_(PSD2) https://en.wikipedia.org/wiki/Payment_Services_Directive#Rev... (Revised Directive on Payment Services (PSD2))
- sagarm 5y agoYodlee (used by Mint and likely others) has been around for over a decade, and AFAIK nothing happened to them.
- deleted 5y ago[deleted]
- dzdt 5y agoSo this sounds like Plaid wanted to learn how to interface with the client-facing web interface of these payroll systems. So it paid people who have their own payroll on the system for access to that individual's login to study the user interface in order to develop a system that can interoperate with it. This sounds... not so bad?
- deleted 5y ago[deleted]
- jc_811 5y agoI think the biggest issue is that they were paying employees for login credentials to sensitive systems. Imagine you’re an IT manager and you find out that an employee is giving the company’s* usernames and passwords - to a 3rd party at their own discretion. I think this is a HUGE deal. Unless the employees had explicit permission from the employer (the article strongly insinuates they did not), I don’t see how this is anything besides a giant mess. *if you log into a company system, with a company provided username and password, those credentials belong to the company
- mgarfias 5y agoI got the impression it was the employee side of the app. As in me logging into ADP so they can figure out how to scrape ADP
- lbotos 5y agoYes, but I'm sure most employment contracts say something to the effect of "you will not grant unauthorized access to company property or systems." And the fact that the employee was paid, shows that the interest was in the employee's favor, not the businesses. (conflict of interest) It's the same as if a salesperson said "I'll give you $500 to help me get into your office building, and navigate me to the payroll department's desk. I just wanna understand the layout for a meeting I want to have in a few weeks."
- 5y ago
- hahaxdxd123 5y agoThe fact that Plaid even exists, and that their core business will probably continue to thrive for another decade makes me almost certain that the US will lose its stranglehold on innovation soon. In the US, I have to pass through so many rent seekers to move some digits over (Plaid, Stripe, and Visa/MasterCard). Meanwhile Europe has PSD2 now and China AliPay/WeChat Pay. Even India, which in the past 3 months has unfortunately proven dysfunctional has UPI, which is orders of magnitude better than what we have. When has the US recently passed legislation or standards that fosters innovation? (this is a serious good faith question - there seems to be a lot of govt grants for stuff like basic research, but a whiff of money churns out stuff like repealing net neutrality).
- seanhunter 5y agoIt boggles my mind how far behind the payments curve the US is. If you go to India or Indonesia you can pay guy cooking street food at the side of the road by scanning a QR code but in New York you still have people paying for sandwiches in Pret a Manger using a cheque.
- stuaxo 5y agoUnbelievable, I can't remember why last saw a cheque in the UK.
- cactus2093 5y agoDon’t believe everything you read online, especially when the parent commenter is clearly not even American based on their spelling. I live in the US and have only used a “check” a couple of times in the past 5 years. And almost nobody would ever use one at a retail store or restaurant or food truck, if anything they’re only used for sending large sums of money to small businesses who want to avoid the 3% card processing fee. It’s still bad that this fee is so high on our primary payment rails, but it’s not as ridiculous as people in this thread are making it sound.
- seanhunter 5y ago
- tehwebguy 5y agoOn the consumer side I can’t imagine ever giving my bank credentials to Plaid or any other company. Super unnerving that this is even a thing, it’s like the number one rule of passwords.
- tablespoon 5y ago> On the consumer side I can’t imagine ever giving my bank credentials to Plaid or any other company. Super unnerving that this is even a thing, it’s like the number one rule of passwords. Yeah, and it's also the number two and three rules with bank passwords. I sold Bitcoin for the first time a few months ago on Coinbase. Their only bank integration is via Plaid, and I did a double-take and noped the fuck out of that right away. It boggles my mind that's even a thing. Luckly I was able to get my money out via Paypal instead without too much hassle.
- caseyf7 5y agoWhen your company uses Carta you'll be forced to use Plaid under time pressure to exercise your stock options. Companies need to stop enabling Plaid because they are too lazy to implement their own payment systems.
- ncallaway 5y agoI agree. I really wanted to use mint, but couldn't bring myself to give away my bank password. I resorted to writing my own tooling using puppeteer running on my machine to automatically login to my bank accounts and download the CSV exports of my transaction data for each bank. I then normalize that transaction data, and import the data into Lunch Money. It was a pretty big hassle to write and get working reliably(ish), but I'm super happy now that it's done. Every 2-3 weeks I run the script, and 5 minutes later all of my transactions are available in Lunch Money. I have the peace of mind of knowing that I'm not exposing my banking credentials to random third parties.
- climb_stealth 5y agoDid you release the sources for this by any chance? I have been playing with the idea of doing something like this for a long time. But it seems like a huge job and I haven't been able to motivate myself towards it yet. My bank even supports showing a lot of those spending stats as in Lunch Money, but it is entirely on their end and I'm not in control of it at all. I can look at the graphs and numbers in the app but I can't export or store it in any way.
- beervirus 5y agoBut people are fine with giving Plaid their bank credentials for some reason.
- KingMachiavelli 5y ago> https://www.eff.org/cases/facebook-v-power-ventures https://www.eff.org/cases/facebook-v-power-ventures While it is bad and unethical to encourage sharing credentials, I really hope we don't continue to criminalize intermediary services that act on the user's behalf. User's should be able to use whatever product and services they want. If you don't want consumer's to use third party tools then either improve your own tools or implement better security. On the bright side it sounds like in the Power Venture's case they did a few other things to sort of 'impersonate' Facebook in order to encourage user's to use their product. So maybe things haven't escalated too far yet... the outcome of this & Plaid will certainly be interesting.
- deleted 5y ago[deleted]
- imgabe 5y agoFinancial institutions should all be required to provide API with various permissions so consumers can connect whatever 3rd party tools they want. Coinbase has a good API where you can specify read-only access to whichever accounts and wallets you want.
- wikibob 5y agoLook up PSD2. Exactly that is required in EU
- rmesters 5y agoNot just EU. Also Australia, Brazil, Japan, Saudi Arabia, Mexico, Singapore, Hong Kong, India. Canada is rumoured to have this soon as well.
- pintxo 5y agoAnd it's a net-negative for everyone not using any such service. The UX for my online banking has gone down significantly. Banks require now a lot of additional 2fa authorizations for various actions, even when you are already authenticated.
- helsinkiandrew 5y agoIt's hard to differentiate Plaids behaviour in getting user account details from those used by Amazon Refund Scams [1]. Their motive may be different but their actions just help make this sort of behaviour on the vulnerable (ie. non technically/security literate) easier to repeat by the more unscrupulous. [1] https://www.youtube.com/watch?v=le71yVPh4uk https://www.youtube.com/watch?v=le71yVPh4uk
- nly 5y agoProbably why my employers payroll system is only available internally / via a VPN