> The bank said in the court filings that the interface "dupes" consumers into believing they are entering personal information into TD Bank's trusted platform.
> "In reality, however, consumers are unwittingly giving their login credentials to the defendant, who takes the information, stores it on its servers, and uses it to mine consumers' bank records for valuable data (e.g., transaction histories, loans, etc.), which the defendant monetizes by selling to third parties," TD claimed in the court records.
https://www.ctvnews.ca/business/td-bank-files-lawsuit-agains...
Also, giving your credentials to any third party, including Plaid, voids the warranty at many financial institutions. If your account gets hacked and your money stolen, you may find out that the zero liability policy no longer applies to you.
These investors have reputations to protect. This type of thing would certainly come out in diligence:
"How do you gain access to the customer's account data with their bank?"
"We impersonate their bank."
"Do you tell them you do this?"
"No."
"Ok, that's probably fine."
How in the hell does this conversation pass muster?
There are organizations and companies that are trying to do this legitimately, through open standards and real incentives to both FIs and customers to share information in exchanges:
- Open Banking Project: https://www.openbankproject.com/
- MX: https://www.mx.com/
P.S. Can we get real Markdown support already? The fact that the Markdown URL format isn't supported is extremely user-hostile.
> When this is implemented, Plaid will access customer information through the bank’s secure API (application programming interface) connection. That will allow customers to share their information more safely and quickly with Plaid and the financial apps it supports while protecting their bank username and password.
and also Wells Fargo:
> The API used in the agreement will utilize a more secure, tokenized “handshake” between the companies’ servers through which customers’ financial data will be shared. Once integrated, the API will allow customers to share their financial data, while also maintaining the privacy of their user credentials. The enrollment process will be easy and designed to work seamlessly within Plaid-supported apps’ user experiences.
I think it would be good to do some quick Google searches before getting (all of) the torches out.
https://media.chase.com/news/plaid-signs-data-agreement-with...
https://www.businesswire.com/news/home/20190919005081/en/Wel...
From their website [1]: "When you choose to connect your financial accounts to an app using Plaid, you will be prompted to enter the username and password associated with those accounts. Plaid then links your accounts to the app you want to use so you can share your data."
And since you can’t rely on an API, “there’s no other option” which compounds with the fact that coding up a web scraper for a specific bank takes maybe a dozen programmer-hours. Then throw on a disclaimer to cover legal, and start counting your billions of unhatched eggs.
There are people who take advantage of that and are very successful. Disgusting because it is just another form of deceiving people's trust.
The trouble is, giving someone your account number also makes it not the bank's problem what they do with that number, even if it was clearly unauthorized by you. There's no good way to do ACH transfers without a high degree of trust in the recipient.
So does, for example, Yodlee, when you use them to have an API for bank statements. I cannot say if they too monetize the data that opens up to them for grabs.
It took legislation and years of preparation to enforce APIs and interoperability onto European banks (yes, I can now use bank A's app to view my account balance in bank B, while maintaining control over what kind of access I'm giving). Can't see it happening in the US, though, although the demand for such APIs is clearly there, given that companies like Plaid and Yodlee prosper.
Funny enough, I've seen that be the case at some banks that simultaneously integrate Plaid into their online account application flow for the initial/funding deposit but. Pretty ironic that users are implicitly coerced into voiding their liability protection at their existing bank during the course of opening an account at a new one. Who wouldn't hesitate to turn around and also invalidate your liability protections themselves if you used your new bank's credentials with Plaid elsewhere.
Of course, once those portals are enabled we enter the Facebook game: Where a lot of customers will blindly give all access to Plaid like companies, and then consumer group advocates will criticize for the amount of information that they are (still) mining from ignoring customers.
I tell my founders to always always fly straight or don't fly at all because if you cut corners or deceive, it will come back to you.
Had they been honest and played by the rules they could be sitting on a massive windfall.
Unfortunately, some VCs and founders think like gangsters and get surprised when things dont plan out. Just because it worked for someone in your circle doesn't mean its gonna work for you. It is a horrible behavior to emulate.
First, they're transparent about being a 3rd party that's part of the flow (see https://plaid.com/blog/the-all-new-plaid-link/). It's clear it's Plaid, they use neutral colors and not the bank's, etc. They have a portal where you can manage your data (https://my.plaid.com/).
Second, they are very open about not selling data (unlike most of the their competitors). It's in their terms and their website (see https://plaid.com/how-we-handle-data/). I guess that could change, but from working with them I know it's part of their positioning so I'd be surprised if that changed.
Third, they've announced bank integrations and afaik they're moving to OAuth where the banks support it (I've seen this in the wild, but can't replicate right now). The key here is where banks support it. I think you have to look at the historical context: the banks do not want you to own your data as a consumer. They don't want fintech apps to exist. Having talked to banks about integrating directly with them, it's onerous and only the big players can do it. Plaid's fighting the good fight for fintech startups.
But yeah it's a less-than-ideal solution and it sucks that it doesn't work without creds flowing through and it's not clear regulators or banks will work to make it better. That sucks. I just think bashing on Plaid here is one-sided.
(throwaway account because I work in fintech)
Every time I've been confronted with a Plaid-backed bank login prompt, they use the bank's colors and logo, the word "Plaid" or their logo is either nowhere to be found or is in tiny fine print, and I run away screaming from that service.
I can appreciate that Plaid is trying to push stuff forwards, but (Presumably) storing your bank credentials in plain-text is a far worse than a "less-than-ideal solution".
PS Yes I know people like Ben Thompson [1] and even the US Treasury (mentioned in the same link) advocated for a private solution like Plaid (and nearly by extension Visa), but seriously this seems like something that needs to be government regulated to prevent incentives for selling user data.
[1] https://stratechery.com/2020/visa-plaid-networks-and-jobs/
The idea is the bank can't shut off Teller clients without shutting off their own customers. This involves a lot of iOS reverse engineering.
So things like Plaid's Capital One integration breaking for months have never happened with Teller - who've been running for something like 5 years now.
That said, I personally wasn't surprised to see they have this access. It makes sense that if you give them your bank password, they will have full access to your account unless they clearly convince me otherwise.
for the uninitiated:
https://www.frbservices.org/financial-services/fednow/index....
https://www.frbservices.org/financial-services/fednow/what-i...
This is why Facebook is so pissed off at Apple that it dares to ASK users first.
"Most users aren't aware what data is gathered about them" is about 10x more accurate than "users don't care about privacy", even though it's the latter that gets repeated all the time (with some help from the surveillance companies themselves spreading this propaganda).