14 ms·
Plaid settled $58M lawsuit over alleged consumer data sharing
- ve55 5y agoIt is particularly sad how common scenarios this are for users, especially in the US. I have known how terrible applications like Plaid (and alternatives) were, but at various points have been required to use them to do something like pay my rent (this is also a very common theme in my life: I strongly dislike a certain company or app, but find myself required to use them regardless, even knowing that my usage and information will be abused). Giving my full credentials and my security question answer in plaintext to a third party in order to 'link my bank accounts', and then having them scrape every bit of information they can from my personal banking statements and sell it is... nothing short of a nightmare scenario, from many standpoints (user security, user privacy, user education, anti-phishing, and so on). I guess it's nice to see this class-action lawsuit, but that it amounts to an average of $0.60 per affected user is, well, not particularly inspiring with respect to my hope that things will ever get better here. Plaid is used by many industry leaders including Venmo, Robinhood, and Coinbase. When it's not used, usually a similar alternative is. Perhaps the most frustrating part of this is that placing blame on these companies is difficult, as there's no interoperability or open banking APIs that can be used as an alternative.
- shostack 5y agoPart of the challenge is there is no great way to easily get my data out of banks and accessible in one place. Business model aside, they do solve a real problem in a space where there are no real incentives for banks to provide their own solution. I'd love to see a subscription-based, privacy-focused option with API access targeting the consumer personal finance crowd. I think Tiller may get some of the way there, but I'm not sure how secure they are.
- foxcurve 5y agoIf that's something you're interested in, I'd encourage you to send me an email (check profile). This is exactly what we've been working on for the better part of the year.
- trianglesphere 5y agoOne problem I have with plaid is that the most common use for them that I see is a company using them in order to setup direct deposit. It's also really hard to figure out how to manually set it up (I usually have to click deny on plaid and then I can input it myself) I'm not interested in handing over all my info when I can copy and paste two numbers instead
- swiley 5y agoIsn't there a standard API used in the US? GNU cash talks about it some in their documentation but I've never tried using it.
- madamelic 5y agoNope! US banks seem to have zero interest in doing so because it doesn't bring them money and Congress isn't interested in forcing them to. EU though is working on a solution between themselves. [0] US banks solutions range between "screw off, no scraping allowed even on your account" to (probably) "here's an undocumented SOAP API last touched in 1998" [0]: https://www.americanbanker.com/opinion/europes-new-api-rules-lay-groundwork-for-regulating-open-banking https://www.americanbanker.com/opinion/europes-new-api-rules...
- swiley 5y agoWell this is what I was thinking of: https://wiki.gnucash.org/wiki/Setting_up_OFXDirectConnect https://wiki.gnucash.org/wiki/Setting_up_OFXDirectConnect I know someone claims my bank supports it but I've never tried.
- hulitu 5y agoSo in US if you have enough money you can do anything and then settle in court if problem arise.
- zeroxfe 5y agoMost of the world works this way.
- munk-a 5y agoI disagree somewhat to this - it's certainly true to an extent but when it comes to gross negligence or malicious intent most of the world will seriously come down on you. Only in the US is intentional malice generally written off with fatalist cries of "It was inevitable that some market participant would abuse this system."
- user-the-name 5y agoNo, the US is actually much worse.
- arthur_sav 5y agoThe cost of doing business.
- pbreit 5y agoOn the flip side, if banks are not going to make my data available on a better basis, what choice is there?
- WaxProlix 5y agoSomething that doesn't fleece and abuse its customers and then expose their data irresponsibly?
- edoceo 5y agoCould we all open an Arbitration Case which may be in their TOS (I'll have to look). Edit: California JAMS Remember that one company that got "crushed" with bills cause a bunch of consumers use the Arb-Clause as intended? Supposed to block law-suits
- newfonewhodis 5y ago> Remember that one company Amazon? https://www.wsj.com/articles/amazon-faced-75-000-arbitration-demands-now-it-says-fine-sue-us-11622547000 https://www.wsj.com/articles/amazon-faced-75-000-arbitration...
- lutorm 5y agoIsn't giving your credentials to a third party also a violation of the terms of service with your bank? It seems, at the very least, the bank will just tell you "too bad" if there's a breach and someone drains your bank account using the credentials you gave Plaid. You'd be left suing Plaid. In fact, this seems like a _terrible_ liability for them. I guess they're hoping it won't happen and if it does then they'll just go bankrupt anyway?
- drewmol 5y ago> Giving my full credentials and my security question answer in plaintext FWIW: I've resorted to using a formula to derive my security question answers from the real answer (kept secret) and the text of the question itself. This seems to help mitigate the damage of the q's and a's getting exposed.
- d110af5ccf 5y agoI don't provide honest answers to them and discourage my family from doing so as well. I simply treat them as an additional set of passwords to be written down using pen and paper.
- mixmastamyk 5y agoRequired to use to pay your rent? Don’t think that is enforceable, is it?
- prepend 5y agoPlaids terms are really concerning to me as a user and I’m not willing to give them my bank credentials. My main fear is that they get hacked and my credentials are used to drain my accounts. Plaid waives any liability and my bank doesn’t do much if my credentials are used to do stuff like initiate wire transfers. Venmo is doing this weird thing where for some transactions they are saying they require plaid to get my bank credentials to log in and “verify.” Of course that breaks my first issue. But it also allows them to suck up and use all of my bank transactions forever. Seems like a shitty tradeoff just to Venmo money to people.
- toomuchtodo 5y agoI would recommend considering a bank that supports Zelle payments. Cut out the middleman (PayPal/Venmo). Fed Instant Payments are around the corner (2023), at which point instant payments should be available ubiquitously. https://www.zellepay.com/get-started https://www.zellepay.com/get-started
- prepend 5y agoMy bank supports Zelle and I use it with the few contacts willing to accept Zelle. But most friends don’t, nor do random people who need money. I was trying to buy a book off a street vendor and he took cash app and some app I had never heard of and Venmo, but no Zelle.
- eshyong 5y agoThis recently happened to me as well - Venmo tried to invalidate my payment method and pushed me to go through their "instant verification" process. Note that "manual verification" (i.e. the deposit method) is still an option on their app, though you may have to remove your current bank credentials and re-add it.
- paws 5y agoI recently received a helpful reply about liability from an HN user who says they're a Plaid employee. Thanks @phoenixy! https://news.ycombinator.com/item?id=27982516 https://news.ycombinator.com/item?id=27982516 While I'm still trying to understand the bigger picture implications, maybe you will find this helpful too.
- cmer 5y agoIt is absolutely crazy that in 2021, banks still don't have proper secure APIs for other software to interface with. Plaid is a major disaster waiting to happen. Are there any banks moving in that direction? I know of exactly zero in Canada.
- davidkassa 5y agoFDX is an emerging standard. You can see the members of the group here: https://financialdataexchange.org/FDX/The%20Consortium/FDX/The-Consortium/Members.aspx https://financialdataexchange.org/FDX/The%20Consortium/FDX/T... Quite a few in Canada.
- g_p 5y agoThe UK and EU have both adopted effectively what you describe under PSD2 - the UK banks in particular were forced by their competition and markets regulator (CMA) to adopt open interoperable APIs. The end result, now it's available, is that you have 2 levels of API access. One is for access to account information (I tend to think of this as read-only access), and the other is to allow for "payment initiation" (think of it as write access, although not a perfect analogy). An account information service provider (AISP) can do things like aggregate bank accounts into one view, across different banks. A payment service initiation provider (PISP) can create payment gateways and initiate payments against a bank account using an authenticated session (enabling direct bank payment online, without needing a debit or credit card and the associated infrastructure around that). You can't just rock up and access the APIs though - I believe you need to get your application approved and engage with the regulator, which is probably for the better, to avoid the "app store problem" of loads of apps springing up in the API ecosystem, asking for permission, then just leeching data to third parties after you apparently consent on page 46 of their terms.
- toomuchtodo 5y agoThis is the template for US financial regulators and legislators to implement. Plaid is filling a regulatory vacuum.
- 5y ago
- bananapub 5y agoit's so frustrating that this sort of shit keeps happening. 1. banks create gap in market by not providing useful access to their customer's data by...their customers 2. regulators don't step in to fix this market failure 3. some company steps in! yay! 4. company decides that charging customers for providing a good and/or service is insufficient, they need to do something creepy with selling off the customers data 5. lawsuit after the fact to maybe stop them being dickheads and definitely enriching a lot of lawyers why hasn't the FTC or something stepped in to make banks provide some secure read-only access?
- mistrial9 5y agomy colleague - you are missing the willing, enthusiastic, extensive and competing-to-out-do each other, aspect of tracking and selling profiles on "customers." I was told a story about a man in Florida making seven figures in the 90s by compliling and selling profiles, that were absolutely not legal and everyone knew it! so now its legal right?
- w4llstr33t 5y agoI think companies should still provide a way to link accounts via small deposits. It takes a few days, but at least you don't have to share your credentials. (This applies to US accounts, maybe there are better solutions elsewhere.) If you use Plaid, I think it should only be if there's no other option and you change your credentials after. I've always thought giving away your credentials to a screen scraping company like Plaid was crazy. In terms of the class action lawsuit, the only one who will see a meaningful payout from this are the lawyers.
- theptip 5y agoPlaid does support this: https://plaid.com/docs/auth/coverage/same-day/ https://plaid.com/docs/auth/coverage/same-day/ Their UI makes it really hard to find this option though, because Plaid makes their money from scraping your transaction history, which doesn't work if you do the micro-transaction approach. As a consumer, I'm not a big fan of Plaid's business model. But to be fair to them, a lot of the security issues come from the fact that until very recently, no US banks had any form of API to allow delegation of access. Based in large part on the success of Plaid, this is starting to change; some institutions are banning Plaid from using the password-based flow, and are replacing this with a more secure OAuth flow: https://plaid.com/docs/link/oauth/ https://plaid.com/docs/link/oauth/ This is the correct solution to the technical problem at hand. It'll benefit other systems too; for example it should be possible for open-source accounting software to use this flow to export your transaction history in a maintainable way, which previously relied on scraping that's unfeasible for an OSS project to keep up with (but which Mint could afford to implement). Hopefully the banks let you selectively grant permissions "can view my account list" and "can view my transaction list", or at least surface those permissions, so that consumers can be aware of what they are giving away -- I'd wager that most end users have no idea that Plaid is slurping their transaction history, and would be even more shocked that it's maintaining ongoing access to continue doing the same.
- TedDoesntTalk 5y agoI’ve always refused to use plaid thankfully and go with the micro transactions route (2 small deposits and withdrawals from your account).
- walrus01 5y agoThe "Current" online-only bank insists on using Plaid if you want to transfer money from an existing account to Current. No thanks. https://www.google.com/search?client=firefox-b-1-d&q=current+online+bank https://www.google.com/search?client=firefox-b-1-d&q=current... Also apparently if you want to use Plaid with many different online banking portals, you need to permanently disable 2FA, also no thanks.
- nexuist 5y agoFWIW my bank uses 2FA and it works with Plaid. Plaid has a working 2FA authorization process, they might just not have implemented with every portal yet.
- echopom 5y ago> If all 98 million people were to file a claim, each would receive just 60 cents. Thank you court of California to incentive startups and GAFA to use our data knowing their risk nothing. Just to be clear , Plaid has raised 600+ Millions in it's lifetime , this is nothing for them.
- akarma 5y agoI actually mentioned in a thread about Plaid in 2018 that they sold transaction history to third parties, and the cofounder came onto HN to explicitly deny that [1]. I actually felt convinced they didn't afterwards, as I couldn't imagine such a direct and clear refutation if it were true. [1] https://news.ycombinator.com/item?id=18655417 https://news.ycombinator.com/item?id=18655417
- tartoran 5y agoSo the cofounder was not telling the truth then?
- edoceo 5y agoCorrect.
- collectedparts 5y agoThe cofounder was telling the truth (or, at least, nothing in the lawsuit implies that he was not). The plaintiffs in this case are claiming that when they linked their bank accounts to PayPal/Venmo/etc using Plaid they didn't realize what they were doing, or that it's somehow unfair that Paypal/Venmo/etc got their banking data (despite knowingly inputting their credentials into Paypal/Venmo/etc). Paypal/Venmo/etc is not a third party in that case. They're the party that the customer was knowingly interacting with. A third party would be an unknown / unrelated data broker. Ie, the cofounder is claiming that they don't turn around and resell data to anyone other than the app that the customer was deliberately using.
- akarma 5y agoThe link mentions third party firms: > Plaid has settled a $58 million class action lawsuit over claims that the fintech firm passed on personal banking data to third party firms without user consent. and selling transaction histories: > the plaintiffs alleged that Plaid has “exploited its position as middleman” to obtain app users’ banking login credentials and use that information to gain access to and sell their transaction histories. For what it's worth I haven't read the actual lawsuit yet, but would love a link if it refutes the article.
- fasteddie 5y agoI'm a bit confused reading this. Is the lawsuit that users signing up for e.g. Venmo didn't know that they were also giving their transaction history/whatever to Venmo, or that Plaid was then taking the data passed to Venmo and reselling to, I don't know, a hedge fund? If it's the former -- I certainly think services need to clearly state what/why/how they are using the data, but it's on the services (like Venmo) and not Plaid.
- tehwebguy 5y agoI say this basically every time it comes up but I cannot imagine handing my bank login + password over to Plaid or pretty much any third party ever for pretty much any reason.
- RHSeeger 5y agoYou're not the only one. I find it staggering that people do this.
- meowtimemania 5y agoI’ve used Plaid to login to my bank account. How do I delete all my data from Plaid??
- buu700 5y agoI did this recently (well not all my data, but one bank account). I had to go through customer support, and they had some trouble with it but eventually figured it out. I'm not a fan of Plaid. The core concept is great, but training users to enter credentials (much less banking credentials) into third-party sites is nuts. Nowadays, it would be easy for someone to pivot from a compromise of a random company's web server to impersonating Plaid and pwning most of their customers' bank accounts. This would be trivial to fix by deprecating their current UI and switching to a small popup or redirecting to a different URL.
- jeandenis 5y ago(Plaid CTO here) You can use the Plaid Portal (https://my.plaid.com https://my.plaid.com) to view what types of data are being shared, to revoke access (to both the apps and Plaid) and delete data stored in Plaid’s systems. You can also put a data deletion request through support. Not as per my comment above that we don’t, and have not, sold data. https://plaid.com/legal/#consumer-support https://plaid.com/legal/#consumer-support
- dreyfan 5y agoWhy did you settle for $58M in fines when Yodlee does the same thing but they very blatantly sell customer data, and as of yet, remain untouchable?
- madamelic 5y agoVisibility in my opinion. Plaid is a financially juicy target that has a lot of customers.
- briffle 5y agoI have tried to login to this site, registered my phone number, and it says it can't find any accounts of mine. yet I know YNAB uses plaid as its backend, and has links to my banks, credit card companies, and even my mortgage. Is this a bug, or are those of use that use certain 3rd parties not able to see our data?
- deleted 5y ago[deleted]
- zaptheimpaler 5y ago98M customer accounts for $58M so 60c a piece. Sounds like they got a great bargain! Justice is served!
- a-priori 5y agoI just read the settlement document, and it looks like this is being reported incorrectly or at least ambiguously. The allegation is NOT that they shared/sold data to any third parties but that their Plaid Link user interface, where people enter their banking information to add it to Plaid, looks like the customer's financial institution (i.e, uses the bank's branding colours and logo). Because of this branding, people can reasonably assume that they are sending that data directly to their bank without knowledge, and therefore consent, to share their information with Plaid itself. If that understanding is correct then this isn't a business practice or security issue, but a user consent issue. That's a problem that definitely needs to be fixed, and the injunctive relief requires them to change the branding and disclosure to make it clearer that people are interacting with Plaid rather than their bank. But to me it's definitely not a reason to cancel your account or boycott Plaid or whatever. https://newmedialaw.proskauer.com/wp-content/uploads/sites/22/2021/08/Plaid-Memorandum-of-Points-for-Prelimary-Settlement.pdf https://newmedialaw.proskauer.com/wp-content/uploads/sites/2...
- ac29 5y agoLooks like there is some other deceptive stuff going on as well - for example, they apparently collected and stored transaction data even when developers didnt request it (at least, they are agreeing to delete this data now, so it must have been collected in some cases).
- a-priori 5y agoAgain, I don't see anything shady there. There's two things I see in the settlement about that: 1. They proactively retrieved transaction data when you connect an account. This sounds like an assumption that almost always people are going to want transaction data, so they just do it by default, presumably to improve the first-time user experience so the data's already there when you later request it. This is going to be changed to only retrieve transaction data on demand. 2. If Plaid's connection is broken (e.g. the user changes their password) then Plaid deactivates the connection but keeps the data. They've agreed to delete the data in this case. The drawback of this change is that since many connectivity issues are going to be temporary, this means that in those cases they'll need to delete the data, then retrieve it again when the user reconnects. Basically it sounds like they optimized a little too hard on user experience, especially when connecting a new account, and in the process they overstepped user consent. I don't see any bad intent there personally, it sounds like they were just a bit overzealous trying to make the experience super slick.
- vmception 5y agoThe worst thing about Plaid is the alternatives to Plaid that I've never heard of There is no secure way to "connect your bank account" in an app. No matter how fancy it looks, or what logo they put up, you are really just giving your username and password to a random person. A random person who may or may not be malicious, but is absolutely a giant target for malicious people. As for the rebuttals, be nice if there was a way for users to to verify.
- tommoor 5y agoTop tip: If you don't want to give Plaid your banking credentials and all of your purchase history (you really shouldn't, irregardless of this lawsuit), just search for jibberish in the "search for bank" option in any app that implements Plaid to get the option to "link manually"…
- root_axis 5y agoThe bottom line is that users aren't aware that they're giving up 6 months of past and future transaction history to the Plaid integrator when they login using Plaid. This is obviously deceptive.
- hamburgerwah 5y agoModern business in the US: 1) Make big profit doing bad thing that harms consumers 2) Pay fine for doing bad thing that is 10% or less of the ill-gotten profit 3) Repeat
- dmitrygr 5y agoCan we, for a moment, talk about how evil the very concept of Plaid is? We are literally TRAINING people to turn OFF 2FA on their bank accounts and give someone else their passwords! Yes, you read that right! And then we wonder why phishing works so well, and why 2FA is not widely used... I already advised everyone I know against Plaid, and am working with my bank's local branch to disable any and all access from their IPs, and force anyone whose passwords have been compromised (make no mistake, giving your password away is a compromise) to change their passwords and enable 2FA.
- jqpabc123 5y agoJust don't ever give your banking login credentials to anyone ... ever. Just don't do it. You knew it was a bad idea when you did it --- so don't repeat the mistake for any reason.
- xyst 5y agoPersonally, services that ask for your bank account credentials are a “no go” for me. The passwords themselves are likely stored securely, but the fact they are stored at all is concerning. All it takes is a bad actor within the company to re-write the screen scraping to then impersonate the users and have them wire out money to a foreign bank account. Some anti-fraud systems might catch this activity but for people that use the wire system on a frequent basis it might go unnoticed. Or they may screen scrape the information and sell it on the black market. Wouldn’t be too hard to target a specific group (elderly, retired) since you already have their bank credentials which subsequently has reliable/verified demographic information and account balances.