4 ms·
Isn't plaid the company that puts up a phishing-esque 'real looking' bank login page, then captures the login info and then makes that banking data available t
by failTide 4y ago
Isn't plaid the company that puts up a phishing-esque 'real looking' bank login page, then captures the login info and then makes that banking data available to whichever third party had set the thing up?
Not sure if they're still doing that. Definitely don't ever want that to happen with my medical records.
- ThunderSizzle 4y agoIt's a fantastic self-hosted concept (e.g. a password vault that sync the data the password unlocks). It's a nightmare for security as a service concept
- failTide 4y agoThat's an interesting idea - although there would need to be a way to prove the data wasn't tampered with, since a lot of companies are using plaid to make decisions on loans and things. What the banking industry should do is just come up with a standard format for sharing financial data, with keys to prove the data was real, and let the consumer export those files and share with anyone they want. No need for multi million dollar federated systems.
- mal-2 4y agoIt is unforgivable that they implemented it as an iframe. Who needs EV SSL verification? never heard of it. You can't even see if there's an HTTPS lock indicator! It was bad enough that it asks for bank login credentials, but doing so with no server validation at all is a terrible flow to be teaching users to accept.
- iancarroll 4y agoYou can’t implement what you suggest in a browser. The only trusted identity that browsers have is the parent page in the URL bar — which Plaid doesn’t remove. If Plaid tried to create some kind of secondary URL bar, phishing pages could just recreate it. aka the “line of death”: https://textslashplain.com/2017/01/14/the-line-of-death/ https://textslashplain.com/2017/01/14/the-line-of-death/
- mal-2 4y agoI know, but that limitation should have sunk the whole idea instead of them relying on iframes. They could make a popup like PayPal (doesn't solve the picture-in-picture attack you linked to, but still better than iframe). The best way to avoid phishers would be to not collect login credentials at all. I expect some kind of token signed by your bank (and generated on your bank's site) could have created a secure way to verify your account without asking for your password. Users have been trained for years with "we will never ask for your password", and for good reason.
- mike22 4y agoThis token based approach is slowly arriving. Don’t know if Plaid does it yet. Yodlee and Intuit have already implemented it (OAuth and FDX) with at least and handful of banks. https://www.yodlee.com/envestnet-yodlee-and-charles-schwab-enter-financial-data-access-agreement https://www.yodlee.com/envestnet-yodlee-and-charles-schwab-e... https://developer.yodlee.com/resources/news/yodlee-and-jpmorgan-chase-sign-data-agreement https://developer.yodlee.com/resources/news/yodlee-and-jpmor... https://media.chase.com/news/chase-intuit-to-give-customers-greater-control-of-their-information https://media.chase.com/news/chase-intuit-to-give-customers-...
- kristiankyvik 4y agoPlaid does indeed support this kind of flow for quite a few banks, especially in Europe (but also in other markets). See oauth flow for details: https://plaid.com/docs/link/#supporting-oauth https://plaid.com/docs/link/#supporting-oauth