Hacker News new | ask | show | jobs
by robot 2562 days ago
can you revoke by changing your password?
1 comments

I’m not sure, but does it matter?

I take issue with a product that markets to consumers as an easy way to authenticate for the purpose of pulling or pushing funds, but is actually authorizing developers to scrape years of transaction history in 20 minutes, my real time balance, my phone/email/address etc. without another level of permission. It’s disgusting.

I just wanted an alternative to microdeposits to prove to an app that I own a bank account, not give the app free range to steal all my bank data in the process of doing so.

In Europe we have PSD2 and similar things which are working towards much more of an oauth type of situation.
In Europe there are industry consortiums working specifically on the account access topic: https://www.openbankingeurope.eu/