back
275 comments
I’ve some friends that works there, so I’m hesitant to say this, because I’m sorry for them, but Plaid is a terrible company. Their main product scrapes financial data from unsuspecting users that simply think they’re making a bank transfer and not signing away the privacy and security of their banking, 401k and trading information.

https://twitter.com/seanieb/status/1298871471645761537?s=20

They are getting sued by TD Bank for this very reason:

> The bank said in the court filings that the interface "dupes" consumers into believing they are entering personal information into TD Bank's trusted platform.

> "In reality, however, consumers are unwittingly giving their login credentials to the defendant, who takes the information, stores it on its servers, and uses it to mine consumers' bank records for valuable data (e.g., transaction histories, loans, etc.), which the defendant monetizes by selling to third parties," TD claimed in the court records.

https://www.ctvnews.ca/business/td-bank-files-lawsuit-agains...

Also, giving your credentials to any third party, including Plaid, voids the warranty at many financial institutions. If your account gets hacked and your money stolen, you may find out that the zero liability policy no longer applies to you.

As someone who's worked in fintech for 10 years, I think this is a bad take. Out of all aggregators (what this is called), Plaid is by far the most open and privacy-forward.

First, they're transparent about being a 3rd party that's part of the flow (see https://plaid.com/blog/the-all-new-plaid-link/). It's clear it's Plaid, they use neutral colors and not the bank's, etc. They have a portal where you can manage your data (https://my.plaid.com/).

Second, they are very open about not selling data (unlike most of the their competitors). It's in their terms and their website (see https://plaid.com/how-we-handle-data/). I guess that could change, but from working with them I know it's part of their positioning so I'd be surprised if that changed.

Third, they've announced bank integrations and afaik they're moving to OAuth where the banks support it (I've seen this in the wild, but can't replicate right now). The key here is where banks support it. I think you have to look at the historical context: the banks do not want you to own your data as a consumer. They don't want fintech apps to exist. Having talked to banks about integrating directly with them, it's onerous and only the big players can do it. Plaid's fighting the good fight for fintech startups.

But yeah it's a less-than-ideal solution and it sucks that it doesn't work without creds flowing through and it's not clear regulators or banks will work to make it better. That sucks. I just think bashing on Plaid here is one-sided.

(throwaway account because I work in fintech)

I once went to use plaid to apply for a mortgage on one of the new fancy broker platforms. It asked me to type my login credentials.. sketchy , but alright banks and mortgage companies seem to trust them? Then they asked me to disable 2FA on my account and at that point it was indistinguishable from a phishing attack to me. I noped out and changed my bank password immediately.
I tried to use their API for a personal project and found starting one month a bunch of transactions were missing from my bank account. It turned out Chase included a promotion on the pdf statement that month which threw off their scraping algo. Really woke me up to their "tech", I changed passwords and avoid them now.
I can confirm this as I currently use Plaid in a few projects. People have no idea what they are signing up for when they authorize this. It's possible to get near real time transaction data from somoene's bank account as well as monitor their account balances for any linked account essentially in perpetuity. With this data it's possible to back in to a lot of behaviors about someone's life. All of that is handed to any firm you authorize to link your bank account.
Now I know why I can never think of good ideas for a business, I'm thinking about what I can build to help my customers, but in today's SV I need to be thinking how can I more easily steal user data at a lower cost than my competitors.
FWIW their competitor Teller uses the bank's own native APIs.

The idea is the bank can't shut off Teller clients without shutting off their own customers. This involves a lot of iOS reverse engineering.

So things like Plaid's Capital One integration breaking for months have never happened with Teller - who've been running for something like 5 years now.

https://teller.io/

They really do need an OAuth rather than save-and-forward-credentials approach to account access. Hopefully the new FedInstant platform will have improvements in this area.

That said, I personally wasn't surprised to see they have this access. It makes sense that if you give them your bank password, they will have full access to your account unless they clearly convince me otherwise.

Yes, awhile back my bank account was decoupled from Venmo for reasons unknown. I unwittingly used Plaid to sign into my bank account instead of the usual wait a couple days procedure. No indication whatsoever - only found out because I saw an article, probably on here, about this company and their basically fraudulent practices.
This is so terrible. Is there an easy way for me to write to Plaid to delete all my information or do I have to go into each service and unlink?
IIRC, they have basically an instance of a scraper for every different bank web site, which to me doesn't seem very scalable. I'm not sure if this is still the case, but when I interviewed a few years ago, it definitely seemed that way.
That's not true. Plaid says they'll be accessing your information literally when you sign into your account.
Well, better one small company doing that garbage than Visa! It makes it easier to avoid.
I am sorry to say this but your friends should really give a thought to why they are still working there. I understand that people have families to feed and mortgage, but they should at least consider changing jobs if they are software engineers.
Pretty much how 99% of this data robbery happens by all surveillance companies.

This is why Facebook is so pissed off at Apple that it dares to ASK users first.

"Most users aren't aware what data is gathered about them" is about 10x more accurate than "users don't care about privacy", even though it's the latter that gets repeated all the time (with some help from the surveillance companies themselves spreading this propaganda).

Blame the banks for dragging their feet and not making proper APIs for these companies to use instead of screen scraping.
Why are you sorry for them? They are making the choice to work at Plaid when they know Plaid is a terrible legal phishing company.
I can't wait until we have smart contracts on a privacy coin that let me invest and grow my wealth anonymously.
It would have gone through had Visa's CEO not been so honest at the time of the merger announcement saying that they intended to use Plaid's data to get a leg up on their competitors.

> The DOJ cited Visa CEO Al Kelly’s description of the deal as an “insurance policy” to neutralize a “threat to our important US debit business.”

I don't even think it's a data issue. He literally says they bought Plaid because they're a threat. That's textbook anti-competitive behavior and a big smoking gun when it comes to anti-trust cases.
Such a poor comment from Kelly that I almost wonder if it was intentional.
Whatever you think about Visa or this merger, this would be a major disappoint to Plaid's team members who thought they were in for a huge financial windfall.

If that applies to anyone here, my sympathies and best of luck figuring out what's next for Plaid. Hopefully the morale hit isn't too big on the team.

That Visa isn't fighting this should validate that the government's antitrust enforcement has been lax. For a merger valued in billions of dollars, hiring even the best lawyers for a long fight would have been a rounding error. The only way this happens is for Visa's lawyers to think that the government would likely win.
Finally some antitrust enforcement!

This was clearly going to be anti competitive and bad for consumers.

Plaid has a great product and will either spac / ipo or be a great acquisition target for someone else.

Important to note that there is no break-up fee that Visa (or Plaid) will pay.

Source: https://www.bizjournals.com/sanfrancisco/news/2021/01/12/vis...

I'm surprised by this. I used to work in Foster City.

The joke on the campus was that VISA stood for "Very Inconspicuous Spy Agency".

You'd think that there wouldn't be this kind of miscommunication in the chain of command.

All jokes aside, I'm very curious to check out Plaid now because I didn't pay attention when it was independent and Visa is a *very* smart organization, so Plaid must be something special.

My guess is that that Plaid will go public via a SPAC deal now. I think it's highly likely GSAH (Goldman Sachs Acquisition Holdings) is that SPAC that does a deal. They have $750M to play with and given Visa was going to buy Plaid for $5.3B, the numbers kind of make sense.
Glad to see they're starting to flex that antitrust muscle a little bit, it's been atrifying over the past few decades.
There's a decent bit of M&A activity going on in finanacial services lately- SoFi recently announced going public, Simple being dissolved after BBVA merging with PNC, Lending Club merging with Radius Bank, and now Plaid's merger termination with Visa. Lots more demand exists for building fintech tools, since significantly more transactions that would normally take place in-person have moved towards being online due to the pandemic. It makes a lot more sense for the whole ecosystem to move towards being data-driven and API-friendly both for consumers to to have less friction between services, and for businesses to deliver a better customer experience. Having the merger fall through is probably better on all sides such that one corporation doesn't retain too much power and act as monopolistic gatekeeper driving up fee prices.

Also, wanted to say thanks to Zach for doing a Fireside Chat with Lambda School students last month! It's great to hear from your perspective about industry knowledge & experience in order to prepare for a career in tech.

Guess this is related:

Plaid blog post 'The Year Ahead' https://plaid.com/blog/the-year-ahead/ (https://news.ycombinator.com/item?id=25754256)

Would be Stripe's largest acquisition to date, but their private market valuation would make it affordable if paid for mostly with stock.
Yet Intuit was able to shut down Credit Karma's potential as a competitor with ease. Something fishy in the district of Washington.
It is still called a "merger" if one company is buying out another company. Don't we normally call that an acquisition?
I gave them access to my bank via coinbase. If I change my bank password would they lose access to my account? If not, what do I need to do to make Plaid lose my banking access?
Looking at this from an opionated Open Banking side here in the UK, this is a good thing.
I think this was well played by the gov't, the idea of Visa and Plaid merging is really clearly going to reduce competition in the payments space
Plaid acquired a direct competitor Quovo in 2019 for $200m. I am sensing a trend.

https://www.businessinsider.com/plaid-acquires-quovo-2019-1

Their link to delete data for CA residents: https://plaid.com/legal/data-protection-request-form/
Could even break those companies up further, at least Visa since financial censorship is becoming prominent with their monopoly share of the market
Finicity is already a great alternative to Plaid.

I imagine bottles of champagne are popping at Mastercard HQ right now.

Well as both a Visa card user and Plaid customer I suppose I'm happy about this!
I am surprised Plaid is a business. It is a bunch of scripts of dubious security. How businesses are coming on board with that is worrisome.

On the other hand, if we could have standard API and let people integrate services, totally welcome that. But let's not pretend this is anything like that.

If you know something more, please educate me.

That breakup fee is good $$$ though
It blows me away our legal system can prevent this but not a tech social media plutocracy?