Hacker News new | ask | show | jobs
by temp129038 2570 days ago
You're giving Plaid and your average user way too much credit.

If the inherit trust is so obvious, then why would Plaid not include a very common step in authentication flows like FB and Google to explicitly tell users what they are agreeing to share with XYZ developer before submitting their credentials (which may be just a bank account number, but might also be transaction history, personal information, account balance, etc.)? They've purposefully omitted this step because conversion would almost certainly tank.

1 comments

I've been playing around with Plaid the past few days and they very clearly list the permissions during authentication:

https://i.imgur.com/xNPTIzy.png

They even link to a dashboard that displays all the information you are sharing with developers:

https://my-sandbox.plaid.com/account

That said, I agree that the average user won't realize the implications. Additionally, revocation/deletion of the data requires emailing them.