4 ms·
To everyone who doesn’t know how Plaid works: You give your banking username and password directly to Plaid, and it keeps it (so it can continue to login). I d
by cantrevealname 5mo ago
To everyone who doesn’t know how Plaid works: You give your banking username and password directly to Plaid, and it keeps it (so it can continue to login).
I don’t understand how anyone is OK with this. It goes against every security principle and it’s against the terms and conditions of every bank.
I realize that almost no bank provides a secure and proper API to get info and/or to transfer funds, but Plaid’s solution is a disaster waiting to happen.
- thebruce87m 5mo agoI thought that’s what Open Banking was supposed to solve: https://en.wikipedia.org/wiki/Open_banking https://en.wikipedia.org/wiki/Open_banking
- jimmcslim 5mo agoAnd indeed it does, in some markets. I'll speak to Australia... here we have the legislated Consumer Data Right [1]. This currently puts obligations on banks and energy retailers to make consumer data accessible via an API, via Authorised Data Holders (ADH - the banks and retailers) and Authorised Data Recipients (ADR). However! The major criticism I have of this scheme is that as an individual power user I do not have direct access to these APIs myself. I believe there was originally an intent to support this under the scheme, however due to somewhat legitimate security and access concerns, but also I expect pushback from anyone falling into the ADH category, this is not possible. Setting up an ADR has a not insignificant compliance burden. However I have recently come across Redbark [2] which is a simple service that has taken on the mantle, and provides a simple sync mechanism for any Consumers that believe they have a Right to their Data. Not affiliated, just a happy customer and I hope that they can make the economics work over the long term. [1] https://www.cdr.gov.au/ https://www.cdr.gov.au/ [2] https://redbark.co/ https://redbark.co/
- mbm 5mo agoYup, it would be really awesome if this concept was deployed in the US. Unfortunately, open standards don't seem to gain as much traction here outside of the tech industry.
- mbm 5mo agoHear you 100%. It felt very uncomfortable for me the first time I used it, as well. The problem is that there sort of isn't a better way right now in the US, and for now, Plaid or a Plaid-like competitor is the safest way. Eventually, it would be awesome if there were clean, open APIs, and standards around this, but for now, it's the best we have. The alternative of course for the DIY-er is some sort of browser automation, which honestly, is what I tried first. I really wanted it to work, but it didn't - which led us to Plaid.
- angoragoats 5mo ago> The problem is that there sort of isn't a better way right now in the US, and for now, Plaid or a Plaid-like competitor is the safest way So then the correct thing to do is to not automate this, until there is a better way. Why would you willingly give your bank credentials to a third party just so you can get some summary emails?? It doesn’t make any sense.
- mbm 5mo agoHear you 100%. It's certainly not for everyone, and I respect your position.
- angoragoats 5mo agoI appreciate it, but by giving horrible companies like Plaid your business you are encouraging and normalizing poor security practices. My parents are almost 80 and use a local bank that I’m pretty sure would just be scraped by Plaid. Do you think they’re going to understand the difference between OAuth and storing their credentials? Plaid and any company like it should be shut down.
- ryandrake 5mo agoIt's total insanity. Can't banks detect and ban Plaid? They should suspend/cancel customers' online access as "compromised" if they detect someone other than the user using the user's credentials to log in. All the security theatrics banks put users through and they don't check for obvious credential leaks?
- kylecazar 5mo agoI don't think this is still the case? When we built our Plaid integration it used OAuth and a redirect. Plaid just got an access token, you enter your user/pass at bank side. Edit: Seems like smaller/local banks are probably the ones that won't support OAuth. We didn't support those.
- mbm 5mo agoCorrect. That’s interesting — so you explicitly opted out for any non-OAuth institutions?
- kylecazar 5mo agoThis was B2B SaaS for large networks of ambulatory centers to manage/pay their vendors. The banks that were in scope were only the ones they used -- each one of the big names (and around half of them Bank of America). Can see it being more of an issue if it were a B2C finance app.