Hacker News new | ask | show | jobs
by jslampe 3383 days ago
I can appreciate the concerns some have voiced, but there's two main arguments for this approach.

1. It's better than what we have today. 2. PSD2 is standardizing and increasing access to financial data, making the entire ecosystem more competitive.

Regarding #1: I understand the concerns regarding privacy and security, but this injects a whole new range of improvement that quite honestly we don't have today. Unlike many countries that have rendered their bank account number useless, the US has not. Today, we all provide our bank account numbers to a variety of companies (our jobs for salary, rent, etc.) via a direct credit or debit authorization form to a third party. The proliferation of Private Account Numberss in the digital age is exactly what's makes them such a high-value target for criminals. A digital authentication and authorization approach allows us to set parameters around authorization, rotate keys, create programmatic constraints, inject real-time security, and a number of other consumer controls (e.g. remove authorization for that annoying magazine company that charges me every month for that Better Homes and Gardens magazine I never ordered). This can all be done without providing the level of access we and banks provide on our behalf every day.

Regarding #2: Banks are great at a number of things, like holding and securing our money. They're terrible at responding to market forces or consumer concerns. Instead, they use the mountains of red tape and regulation to fortify themselves from new market entrants. Greater, more open access to financial information levels the playing field; thus, increasing both innovation and better pricing for all.

TL;DR - this is way better than what we have today.

3 comments

Something that is often overlooked about PSD2 is the introduction of a real liability model and explicit customer consent. What happens today is that account aggregators and payment initiation providers (this is true in US and EU) are operating in a gray area where transparency, consumer protection, and liability are either completely neglected or totally insufficient.

PSD2 will create a clear regulatory framework, will introduce consumer protection, oversight from competent authorities and ultimately will create a transparent liability model for all the actors involved in the flow (data and payments). I think this is a great outcome for consumers and market competition. PSD2 is not perfect but is shaking the industry quite a lot.

I'm working on TrueLayer (http://truelayer.com) which is a universal bank API platform in the context of PSD2. Email in profile if you want to chat about this topic.

I wonder how much this regulation has to do with the EU commission being terrified after Brexit and wanting to create more financial linkage between member states. I feel this regulation may backfire in that regard. What will an institution like Deutsche do if/when they fuck up implementing this ? What will the government do in response ?

Especially given the state of European banks (TLDR: who are going to need a bailout soonish).

It pre-dates Brexit. It's coming into force now, but legislation passed in Nov 2015, and was being developed for some time before that
Creating "financial linkage" is an obvious direct result of the EU's primary mission.

Regarding the risks you (and other in this thread) mention: This really isn't something that has any impact on the system's exposure to risk. It's just a technical process for moving information and (limited amounts of) money between banks and financial service companies. If you're worried about a meltdown of the banking system, you have to look at the regulations on capital requirements, accounting standards, asset valuations etc.

A lot of PSD2 was pushed for by the UK I believe, pre Brexit
Indeed, and the EBA is based (for the moment at least!) in London.
> Unlike many countries that have rendered their bank account number useless, the US has not.

What do you mean by this? I am not in the US, but I find the bank account number to be useful quite useful as it provides a way for people to send me money :-)

I am not familiar with US banking system.

>> e.g. remove authorization for that annoying magazine company that charges me every month for that Better Homes and Gardens magazine I never ordered.

If you're banking in an EU country there will be a process to stop your account from being continuously charged for a service you did not purchase. For instance, in UK banks this is usually a standind order or direct debit, which you can cancel at any time.

In any case it's hard to see how making your account information available to third parties is going to protect you against this kind of thing.