6 ms·
Plaid Deletes GitHub Issue Exposing Imitation of Bank Login UIs
Plaid imitates major bank account UIs in their login forms to make users more comfortable submitting their bank credentials to Plaid. This issue was addressed in this Github issue (archived from WaybackMachine): http://web.archive.org/web/20190415103059/https://github.com/plaid/link/issues/68
The Github issue has since been deleted, as shown here: https://github.com/plaid/link/issues/68. I'm hoping this isn't a repost, but this behavior seems ridiculous to me, and I'm hoping to bring it to wider attention (if it isn't already).
Edit: post flagged for some reason. Oh well.
- wexxx 7y agoNot to downplay the security implications here, but Plaid has pretty much changed finance. It’s a straightforward case of trading security / privacy for functionality. Apps like Venmo, Robinhood, Wealthfront, and most every other financial startup would not exist without Plaid.
- rishirishi 7y agoHard delete of an issue over closing it or closing comments... for such a security sensitive issue... under the rug sweeping.
- sschueller 7y agoWell, thanks to the fact that you can't delete anything off the internet it will still be presented as evidence in court some day. This confirms to me that staying as far away as possible from plaid is the right move.
- rishirishi 7y agoWhat would you recommend for ACH bank account verification?
- jamiek88 7y agoMicro deposit while cumbersome and slow, works fine. I don't believe access to all of my most personal data should be ‘frictionless’.
- pbreit 7y agoMicro deposits definitely do not work fine. If banks offered an authenticated way to confirm bank account & routing number instantly and without access to txn history, would be much better.
- temp129038 7y agoPlaid needs to be exposed as one of the most unethical companies in SV. If people are worried about online privacy then they should really be worried about a company that is so deceiving and makes it basically impossible to revoke permissions on something as sensitive as access to your bank account and transaction history once granted.
- robot 7y agocan you revoke by changing your password?
- temp129038 7y agoI’m not sure, but does it matter? I take issue with a product that markets to consumers as an easy way to authenticate for the purpose of pulling or pushing funds, but is actually authorizing developers to scrape years of transaction history in 20 minutes, my real time balance, my phone/email/address etc. without another level of permission. It’s disgusting. I just wanted an alternative to microdeposits to prove to an app that I own a bank account, not give the app free range to steal all my bank data in the process of doing so.
- okigan 7y agoLooks like Betterment & Wealthfront use plaid, which could affect many on HN [1][2]. [1] https://www.quora.com/Why-doesnt-Betterment-or-Wealthfront-use-a-service-like-Plaid-or-Yodlee-for-adding-bank-account-information https://www.quora.com/Why-doesnt-Betterment-or-Wealthfront-u... [2] https://www.investmentnews.com/article/20190108/FREE/190109954/plaid-buys-data-aggregation-rival-quovo-for-200-million https://www.investmentnews.com/article/20190108/FREE/1901099...
- homero 7y agoThe scariest thing is whether they keep downloading transactions or just verify i own the account like they make you think they're doing.
- carlineng 7y agoIn today’s economy, data is the most valuable asset a company can own, and financial/transaction data is the holy grail. I would be very surprised if their current valuation could be justified purely on their subscription sales alone.
- diggan 7y agoSeems to have happened not because they deleted that specific issue but because they have disabled issues in general for that specific repository. Take a look at https://github.com/plaid/link https://github.com/plaid/link and see there is no "Issues" tab. When doing that, it removes all existing issues.
- samcday 7y agoThis is depressing. It feels to me like the number of tech unicorns that have been caught red handed doing something immoral/unethical/illegal is starting to outweigh the ones that haven't.
- BillinghamJ 7y agoI feel it's worth bearing in mind that this is normal to the point that the financial regulator in the UK standardised the activity as part of the EU-wide PSD2. It is being phased out in favour of open banking in the next couple of years, now that there's a requirement for more OAuth-like approaches. (In fact, Plaid just launched in the UK on the open banking APIs) Banks are well aware that this is a thing and they're not that bothered. If you want to see this improve, maybe push on US regulators to formalise it?
- AnssiH 7y agoHere the Finnish Financial Supervisory Authority stated in Jan 2018 that this practice is not allowed: https://www.finanssivalvonta.fi/en/regulation/interpretations/01_2018/ https://www.finanssivalvonta.fi/en/regulation/interpretation...
- rhizome 7y agomichaelckelly commented on Dec 7, 2018 @skierpage and @briangordon we appreciate your concerns, which is why our compliance team vets anybody who uses Link. As to malicious knock offs, this is a matter that most successful companies lookout for and deal with -- as we and our security team do. This person should not be allowed to provide services that use bank APIs. Who should do the preventing? Banks.
- ryanackley 7y agoHere's my main beef with Plaid: a lot of times when you use it as an end user you have no idea that you're giving one of Plaid's customers full history on all of your transactions, accounts, credit cards, loans, etc. Plaid presents you with a ToS that you will probably never read. Compare that to something like "Sign-in with Google" or "Sign in with Github". They put it in plain english exactly what the website you are signing into is asking permission for and you explicitly say I'm ok with that.
- amluto 7y agoI wonder if an enterprising attorney general could try to go after Plaid for CFAA violations. They are arguably making unauthorized, fraudulent access to banks’ computer systems.
- TheSpiciestDev 7y agoThis is the first time I'm hearing of Plaid and is it actually something banks have signed-off on and are ok with? This whole thing looks to make for a bad precedence.
- Aspos 7y agoAbsence of open banking standards and regulation produces such monsters.
- csswizardry 7y agoHah. This is the only company that has ever f—ked me over. I’m a self-employed consultant who flew out to SF to work with them and was told the gig was off the working-day before we were set to begin. My lawyer said I absolutely had a case but I’d need to be prepared to open an international lawsuit against them (I’m UK-based) and I just couldn’t muster the effort. They got away with it. They also quite cheerfully asked me ‘Hey! Next time you’re in the area we’d love to look at working together?’ Classy.
- Nursie 7y agoPlaid really do seem a little dodgy to me. In the UK they are effectively offering a PSD2-API forwarding service, which seems very much against the spirit of PSD2 and the open banking initiatives.
- pbreit 7y agoPlaid is mainly US where PSD2 does not apply. Banks sometimes get together to work on these topics but it rarely goes well (see ofx/ofc). What more frequently happens is a company like Plaid forces it and then works with banks to satandardize.
- origamitang 7y agoIt's very convenient. But also very expensive (maybe) The raw costs of getting an AISP licence are about £1000 in the UK... but that's ignoring all of the time and effort to understand PDS2, legals etc but $500+/month for Plaid to do it for you ? I'm not sure. Sounds avoidable like vendor lock in to me.
- whockey 7y agoHi all - co-founder of Plaid here. We're in the process of migrating this repository and replacing it with a dedicated iOS SDK repo, JS SDK, and (soon to be) Android SDK. However, I messed up the order of operations with this migration and can empathize with the reaction. I personally chatted with a lot of the commenters on the original issue before we did this and more than happy to engage/get feedback from anyone else over email/phone/in-person. Feel free to shoot me an email at william [at] plaid [dot] com if you want to chat/have any feedback.
- lykr0n 7y agoCan we get a way where we can centrally manage linked accounts? I have at least 5 apps that use plaid and I should be able to go to your website and see what authorizations I have enabled and disable them.
- whockey 7y agoYes! We're actually working on something in this space that I'm really excited about. If you shoot me an email I can get you on the beta and would love your feedback!
- temp129038 7y agoNo offense, but I think we’d all be better off with open bank API standards in the US.
- wexxx 7y ago
- reustle 7y agoI really hate that transferwise essentially requires me to use Plaid, yet they don't support RSA keys!
- tzs 7y agoSince HN doesn’t turn URLs in text submissions into clickable links like it does in comments, here are the URLs given for your clicking convenience. http://web.archive.org/web/20190415103059/https://github.com/plaid/link/issues/68 http://web.archive.org/web/20190415103059/https://github.com... https://github.com/plaid/link/issues/68 https://github.com/plaid/link/issues/68
- greenyoda 7y ago> Plaid imitates major bank account UIs in their login forms to make users more comfortable submitting their bank credentials to Plaid. But it's even worse than that. They're training their users to ignore the security advice that their banks and other web providers have been trying to teach them for years, which makes them more vulnerable to phishing attacks. As one of the commenters on Github said[1]: > This is horrible, horrible, horrible, horrible, horrible practice. Any malicious actor can copy your design and present a perfectly genuine-looking Plaid input form and gather bank credentials from victims. There's absolutely no way to tell whether a Plaid input form is genuine without examining the HTML source of the page, which is far beyond the ability of almost all users. What good is your $1000 EV cert and your brand's hard-won trust if the user just sees Wacky Joe's Discount Dolphin Assholes, secured by letsencrypt.org in the area of the address bar where we've been telling them to look for a trusted name for about the last decade? The commenter's next paragraph also bears repeating: > You guys need to get your act together and realize that you're not in the business of hosting Wordpress blogs or building marketing pages for the latest Barbie Rides Horses Again game somehow still coming out for the Nintendo DS. You collect bank credentials. Re-read the previous sentence. Do it again. Essentially my entire net worth is kept in my Schwab brokerage account which shares the same login as my Schwab checking account. If someone gets my Schwab credentials and I don't notice before they empty me out, my life is over. You simply cannot half-ass security best practices for the sake of UX convenience. [1] https://web.archive.org/web/20190415103059/https://github.com/plaid/link/issues/68#issuecomment-440894224 https://web.archive.org/web/20190415103059/https://github.co...
- buckminster 7y agoI completely agree, but having your life savings under the same login as your checking account is insanity. Maybe I'm overly paranoid but I wouldn't even log in to my broker from my phone.
- greenyoda 7y agoYou also might not want to keep your entire life savings in a single account. It's convenient, but also a single point of failure. And if your life savings gets big enough, it might exceed the account balances that are protected by FDIC ($250K) or SIPC ($500K, I think).