Hacker News new | ask | show | jobs
by eastbayjake 33 days ago
In fairness they redirect you to your bank to login, you authorize the application (which can be revoked at any time), and then they redirect you back with tokenized information. (In fact it's kind of a pain point that when I use Plaid to link my bank for eg reimbursement deposits from my FSA/HSA, it has tokenized the account numbers so I can't actually tell which account is which.) I guess I get for less savvy users why that might look scary but the alternative is... keying your account number directly into a merchant's system for ACH, which is actually scary (and the default on many government websites which I actually trust less!)