7 ms·
The use of third party KYC services like Onfido is widespread in the cryptocurrency space as well, where over-compliance is the norm right now. Consumers are gi
by buildbuildbuild 4y ago
The use of third party KYC services like Onfido is widespread in the cryptocurrency space as well, where over-compliance is the norm right now. Consumers are given little choice as to which provider stewards their ID scans, bank statements, biometric data, etc.
This user experience has trained the most vulnerable, non-tech-savvy audiences to provide just about anything requested when asked for ID verification. Including to phishers.
If you push back too hard against arbitrary, invasive KYC requests, you start down a path towards becoming unbanked.
The USA is badly in need of modern consumer privacy regulations.
- cmeacham98 4y agoIf you think this one is bad: look at Plaid, which literally phishes users bank credentials as "fintech".
- anamexis 4y ago“Phishing” implies fraudulent deception.
- buildbuildbuild 4y agoI think their growth numbers would have looked much differently if they had transparently disclosed the reality on their login form from day one: “Plaid will store your plaintext password and use it to periodically access your bank account.” Burying truth deep in a TOS is seen by some as deceptive.
- jefftk 4y agoI doubt this would have affected signups that much: most people interested in their service don't care much. (Though instead of "access", which could imply "take money out" to some people, they'd probably use a more descriptive term)
- PainfullyNormal 4y ago> “Plaid will store your plaintext password and use it to periodically access your bank account.” That's terrifying. I'm looking into privacy.com as an alternative to using my real debit card number online because it gets stolen at least once a year. Having my bank account itself compromised does not sound like an improvement. Then again, how often do banks get hacked and have their credentials compromised? At least as often.
- dawnerd 4y agoI believe plaid has oauth integration with the larger banks now. I remember using it with chase and chase showing me an auth and permission approval request screen.
- 2Gkashmiri 4y agowhy can't banks have oath like authentication so this BS doesnt happen?
- twelve40 4y agobecause there are close to 20000 of them in the US, and while chase has the resources to do oauth properly, not every junky credit union can afford that
- jrochkind1 4y agoFew/no small credit unions (or banks) have their own bespoke online portal they developed just for them. They use a vendor. I bet a few vendors would cover a pretty large % of those 20K banks.
- twelve40 4y agowhat's in it for them anyway?
- jrochkind1 4y agoI don't know, what's in it for the big banks either? Probably the same thing as what's in it for smaller banks and their vendors? Apparently nothing, or not enough? Unless customers are going to use the feature to choose their bank? Or it saves the bank money from avoiding fraud? Maybe one or the other will be so eventually. When it is, the vendors/platforms that "junky credit unions" use will add it, same thing as when big banks will add it. A vendor that small banks and credit unions use for their online platform probably has the same order of magnitude of aggregate consumer customers as a big bank has, I don't see why it wouldn't be about as do-able for one of those vendors as a big bank.
- cmeacham98 4y agoI believe they've improved it now, but their login page literally used to say "Plaid" nowhere, and at least for my bank (Bank of America) looked almost identical to the official login. Here's an example: https://d1hzvs60s6jsjg.cloudfront.net/IMAGES-1/208624076/plaid3.png https://d1hzvs60s6jsjg.cloudfront.net/IMAGES-1/208624076/pla... Does this look like it's going to be shipping your credentials off to be stored by a third party?
- edgineer 4y agoLast I checked, privacy.com uses Plaid, too. When privacy.com had asked me to use Plaid to add a payment method, Plaid's privacy policy talked of gathering transaction information and using it for advertising among other things. I think Plaid's stance was that if the host service (the one asking you to use Plaid) wanted to be invasive then it's up to them, or if this host would be upstanding and maintain your privacy, that could happen, too. It was up to the customer to check their policies. But this limitation was not spelled out nor promised that I could see. Their policy may have changed since then.
- junon 4y ago"Phishing" does not mean what you think it means. Blame the banks for Plaid's need to exist.
- cmeacham98 4y agoPhishing generally means "pretend to be X to get user's info/credentials for X", do you have a different definition?
- junon 4y agoPhishing is typically tricking an individual into divulging sensitive information. Credential stealing is typical, but still a subset. Plaid uses banking credentials on a user's behalf. Yes, it's similar to using stolen credentials because... it's the same thing, except consent, audits, insurance, etc. all play a role whereas with criminal activity they do not.
- cmeacham98 4y agoThis seems to be some weird semantic angle where because Plaid is audited that makes what they're doing not phishing? I'm not sure I agree with that definition or that it is particularly common. That said, if it makes you feel better, pretend my comment read "Plaid pretends to be the users' banks in order to trick users into giving Plaid their bank credentials and stores those credentials without their knowledge or consent".
- junon 4y agoThat is the definition of phishing. This is why "vishing" is "voice phishing", etc. Phishing is stealing information. It's not a "semantic angle" - it's the definition of phishing. You're free to consulting a dictionary to fact check me. Plaid is not phishing, by any true definition of the word.
- cmeacham98 4y ago
- collegeburner 4y agoahahahaha man who do you think is the one who added all this KYC shit and who scares companies into over compliance... and you want more regulation as a solution. we could start by removing all KYC requirements and fighting crime as crime instead of imputing some criminality to a financial transaction. like even if it's part of a criminal enterprise the transaction itself isn't the "wrong" part.
- jcz_nz 4y agoUmm. Removing KYC requirements just makes it easier to launder dirty money. Why would we do that? As it is the US is considered a safe-heaven for dirty money - google South Dakota trusts. “Fighting crime as crime” is meaningless.
- collegeburner 4y agoumm removing KYC requirements also allows people to transact privately. yes bad people can do bad things with freedom, news at 5. i'm aware of south dakota trusts and intend to use one in the next few years to protect my assets and operate privately. fighting crime as crime isn't meaningless, it's how we're supposed to do things.
- jcz_nz 4y agoLol no. Your desire to avoid taxes is not a “right”, it’s a criminal intent. Oh, and newsflash - a SD trust is an absolute red flag, and will just mark you for “Enhanced Due Diligence”, where you will be asked to prove the source of funds. And chances are that info will be then shared with your local financial crimes agency - and without your knowledge. And if you think your lawyer or accountant don’t make those reports… heh.