Hacker News new | ask | show | jobs
by tgsovlerkhgsel 1870 days ago
PSD2 seems like a total disaster to me.

From my understanding, banks are required to provide an API. Not a specific one - any API. Which means each bank has a different one and you need yet another rent seeker that aggregates those APIs.

That's on top of requiring specific, often outdated security mechanisms, so now every time I want to pay something with a credit card I have to do extra authentication, >1 GB of my phone's memory is filled just with bank auth apps (again, each bank has their own).

2 comments

> you need yet another rent seeker that aggregates those APIs.

If anyone can implement such an aggregator, market competition should drive the cost of that close to zero soon enough.

And indeed it is. Nordigen's product for example is free; they make money on upselling an optional product on top.

https://nordigen.com/

Since the aggregator will process sensitive data, you need a lot of audits etc.

If you'd like to use the API to access your own account using open source software, good luck (unless you find an aggregator that is certified and allows you to access your own account through them).

> Not a specific one - any API

Defining this is a job for industry bodies and suchlike, as is keeping it current. Lest we forget jokes like the 2020 Brexit agreement containing references to Netscape Navigator 4.0

Having a rule that banks need to agree on one and then implement it would be fine. What is not fine is allowing each bank to come up with their own, especially as banks have no interest of making usage of their API easy.