4 ms·
I know, but that limitation should have sunk the whole idea instead of them relying on iframes. They could make a popup like PayPal (doesn't solve the picture-i
by mal-2 4y ago
I know, but that limitation should have sunk the whole idea instead of them relying on iframes. They could make a popup like PayPal (doesn't solve the picture-in-picture attack you linked to, but still better than iframe). The best way to avoid phishers would be to not collect login credentials at all. I expect some kind of token signed by your bank (and generated on your bank's site) could have created a secure way to verify your account without asking for your password. Users have been trained for years with "we will never ask for your password", and for good reason.
- mike22 4y agoThis token based approach is slowly arriving. Don’t know if Plaid does it yet. Yodlee and Intuit have already implemented it (OAuth and FDX) with at least and handful of banks. https://www.yodlee.com/envestnet-yodlee-and-charles-schwab-enter-financial-data-access-agreement https://www.yodlee.com/envestnet-yodlee-and-charles-schwab-e... https://developer.yodlee.com/resources/news/yodlee-and-jpmorgan-chase-sign-data-agreement https://developer.yodlee.com/resources/news/yodlee-and-jpmor... https://media.chase.com/news/chase-intuit-to-give-customers-greater-control-of-their-information https://media.chase.com/news/chase-intuit-to-give-customers-...
- kristiankyvik 4y agoPlaid does indeed support this kind of flow for quite a few banks, especially in Europe (but also in other markets). See oauth flow for details: https://plaid.com/docs/link/#supporting-oauth https://plaid.com/docs/link/#supporting-oauth