Hacker News new | ask | show | jobs
by manishsharan 499 days ago
I see you are using Plaid for Bank integration. The last time I checked Plaid , there were security issues with regards to how it handled passwords by copying Bank login screens. I believe TD was suing Plaid for this reason.

I wish you best of luck but I avoid any service that uses Plaid.

2 comments

TD Bank has signed a data sharing agreement with Plaid: https://stories.td.com/ca/en/news/2023-12-14-td-bank-group-a...
Plaid, when able, uses OAuth or similar APIs; they (and all the other financial aggregators) use screen scraping only when that's not a possibility. A lot of the big banks have already made a deal with Plaid in this regard.

If you have a Capital One or Citi account, both use a direct integration.

That doesn't solve the problem of Plaid granting access to an absurd amount of financial details to their users (i.e. the companies to which I'm "verifying my bank account").

My account number is fine (and the entire point). My balance and last n transactions? That's just absurd and shows both how broken the US retail banking landscape is in many aspects, and the level of Stockholm syndrome exhibited by a large fraction of their depositors.