5 ms·
> YNAB (You Need A Budget) use services like Plaid to...take my username and password and impersonate me to get my banking data WHAT. THE. F. I'm a longtime,
by xibalba 5y ago
> YNAB (You Need A Budget) use services like Plaid to...take my username and password and impersonate me to get my banking data
WHAT. THE. F.
I'm a longtime, happy YNAB user. I had no idea this was going on until just now. I always just assumed there were secure APIs used to import my data. YNAB's Capital One "integration" stopped working a few years ago (possibly because they cracked down on screen scraping?) and I was upset with Capital One. Perhaps Capital One took steps to prevent insecure access/screen scraping?
- varenc 5y agoFor future reference the tip off is that YNAB/Plaid asks for your bank account's username and password directly. If they were using some proper API, you'd be redirected to an Authorization page on your bank's domain where you could review the requested permissions and the app requesting, and then choose to grant it.
- kryptk 5y agoExactly this, Plaid "kindly requests" you violate the ToS you have with the bank and hand over the keys to your finances. I have never noped out of anything so hard.
- amluto 5y agoIt would be interesting if an attorney general went after Plaid for CFAA violation.
- varenc 5y agoI'm conflicted on the issue. Plaid only has to do this insane screen scraping because there's no other way to get my own financial data. The details of how it's done pains me, but I also think I should have freedom of choice with my data. IMHO, the Canadian proposal seems like the ideal solution. Force the banks to offer a secure and more efficient way for consumers to access their open banking data. (This will also massively lower the barrier to entry for another Plaid competitor) edit: Plaid's docs mention that banks may detect and block this screen-scraping. They frame it as the bank limiting "your ability to access your financial information", which I think is somewhat valid. They're quite obtuse about the whole scraping thing though: https://plaid.com/trouble-connecting/#:~:text=Your%20financial%20institution%20may%20be%20limiting%20your%20ability%20to%20connect https://plaid.com/trouble-connecting/#:~:text=Your%20financi...
- coldacid 5y agoI'm not conflicted on it at all. Plaid might need to do this for them to work, but there's nothing that makes Plaid required for anything you do with your banking. People keep mistaking convenience for necessity, and that's how we keep ending up with hacked-together services that leak everyone's info and worse. I'd rather have no convenience than a convenience that hands off the keys to my life behind my back. And so should the rest of us.
- underwater 5y agoYou're basically saying that if a law makes something impossible, then it's OK to ignore the law?
- dageshi 5y agoThis is how most old/out of date laws/not fit for purpose laws end up being revised.
- poopsmithe 5y agoYou gave them your bank account login credentials and you didn't think it was strange?
- smnrchrds 5y agoPlaid has designed the screens to resemble each bank's login screen. They essentially phish people. I, as a tech-savvy person, noticed something was up when I saw the URL didn't match my bank's. But most people would put in their password, thinking they are logging into their bank's website, and would be none the wiser.
- phoenixy1 5y agoOK, I work at Plaid and I feel like I have to jump in here -- while it's true that we've iterated on the Plaid Link UI over time and it hasn't always looked like it does now, you can see what the login screen currently looks like here: https://plaid.com/plaid-link/ https://plaid.com/plaid-link/ and here: https://plaid.com/demo/ https://plaid.com/demo/ IMO it does clearly tell end users that they are connecting to Plaid.
- smnrchrds 5y agoSo some good finally came from that TD lawsuit. The last time I saw a Plaid login in a service I use, it was a definite phishing screen. It's good that you have moved away from phishing people, but it doesn't change the fact that a) you phished them for years, and b) you still do not in any way warn them that if they use your service it 'voids the warranty', so if their account gets hacked (not necessarily through Plaid), they will be SOL.
- xibalba 5y agoAs another HNer responded: cred screens are given the appearance of being your financial institution, so I assumed an api auth token being issued after “logging in” with the institution. Still, shame on me for not inspecting more closely.
- phoenixy1 5y agoHi! I work at Plaid. We’re strong advocates for API-based connectivity -- our goal is for 75% of our traffic to be committed to APIs by the end of the year. As part of that, we've actually converted our integration with Capital One to be 100% API-based and use OAuth for authentication. You can read more here: https://www.capitalone.com/about/newsroom/data-sharing-agreement/ https://www.capitalone.com/about/newsroom/data-sharing-agree...
- lucasyvas 5y agoWhat you did was wrong and you all knew it. It seems to have paid off though, so congratulations. Nobody with half a brain would trust you.
- Fogest 5y agoLet's be real, banks wouldn't see government regulation like this if something like Plaid didn't force them to have to implement more secure ways to get your own financial data.
- lucasyvas 5y agoI actually do agree - but two wrongs don't make a right here. Taking raw credentials from users without them knowing is completely messed up and a massive danger to the end-user. It's not justifiable in those terms.
- Fogest 5y agoYes I agree it can be scary, but it seems like this is the way a lot of companies have to do things if they want regulation to change at any reasonable pace. Just look at Uber and AirBnB as examples. Most cities they started in they were operating in kinda grey areas or even breaking laws. But they could afford to eat any fines and continue on anyway. It forced governments to put regulations in place to support these systems. Especially when it comes to banking, it moves at such a snails pace for anything to ever evolve. The two banks I am with in Canada only just recently finally added support for 2FA. But it's not even the type where you can use your own authenticator app. You have to use SMS, Phone Call, or their app. My one bank has my "password" being restricted to 6 characters. It's basically got to be a 6 digit pin. It's incredibly insecure already, Plaid doesn't make it much worse. Now with 2FA finally there I feel a lot more secure using Plaid. Because now everytime I want to import my transactions in YNAB I have to enter my 2FA code before it can pull things.