Hacker News new | ask | show | jobs
by BillinghamJ 2562 days ago
I feel it's worth bearing in mind that this is normal to the point that the financial regulator in the UK standardised the activity as part of the EU-wide PSD2. It is being phased out in favour of open banking in the next couple of years, now that there's a requirement for more OAuth-like approaches. (In fact, Plaid just launched in the UK on the open banking APIs)

Banks are well aware that this is a thing and they're not that bothered.

If you want to see this improve, maybe push on US regulators to formalise it?

1 comments

Here the Finnish Financial Supervisory Authority stated in Jan 2018 that this practice is not allowed:

https://www.finanssivalvonta.fi/en/regulation/interpretation...