back

by seanieb·5y ago·view on hn ↗
I’ve some friends that works there, so I’m hesitant to say this, because I’m sorry for them, but Plaid is a terrible company. Their main product scrapes financial data from unsuspecting users that simply think they’re making a bank transfer and not signing away the privacy and security of their banking, 401k and trading information.

https://twitter.com/seanieb/status/1298871471645761537?s=20

18 comments
They are getting sued by TD Bank for this very reason:

> The bank said in the court filings that the interface "dupes" consumers into believing they are entering personal information into TD Bank's trusted platform.

> "In reality, however, consumers are unwittingly giving their login credentials to the defendant, who takes the information, stores it on its servers, and uses it to mine consumers' bank records for valuable data (e.g., transaction histories, loans, etc.), which the defendant monetizes by selling to third parties," TD claimed in the court records.

https://www.ctvnews.ca/business/td-bank-files-lawsuit-agains...

Also, giving your credentials to any third party, including Plaid, voids the warranty at many financial institutions. If your account gets hacked and your money stolen, you may find out that the zero liability policy no longer applies to you.

I am sure I will be called naive, but this is shocking to me. I assumed that Plaid was integrating with the banks and not doing this sort of thing because of the people associated with Plaid. Their seed round included Spark Capital and Google Ventures. Their most recent round included Mary Meeker and Andreessen Horowitz. [1]

These investors have reputations to protect. This type of thing would certainly come out in diligence:

"How do you gain access to the customer's account data with their bank?"

"We impersonate their bank."

"Do you tell them you do this?"

"No."

"Ok, that's probably fine."

How in the hell does this conversation pass muster?

[1] https://en.wikipedia.org/wiki/Plaid_(company)#Funding

I'm surprised, because Plaid is far from the first mover in the "scraped banking data API" space. Mint (now Intuit) and Yodlee come to mind, and they use essentially the same sign-in flow and come with the same limitations.

There are organizations and companies that are trying to do this legitimately, through open standards and real incentives to both FIs and customers to share information in exchanges:

- Open Banking Project: https://www.openbankproject.com/

- MX: https://www.mx.com/

P.S. Can we get real Markdown support already? The fact that the Markdown URL format isn't supported is extremely user-hostile.

A lot of these banks never had any APIs. Plaid made its name basically scrapping the html of account pages. Companies used it because there were no alternatives (no apis)
Let’s not forget the companies that enabled Plaid to do this. One of the worst offenders was Carta. They made you use Plaid to exercise your stock options. So you had to let Plaid scrape your account info to get the stock you worked so hard for. Most people had no idea they were allowing this.
They do integrate natively with some banks, like JPMC:

> When this is implemented, Plaid will access customer information through the bank’s secure API (application programming interface) connection. That will allow customers to share their information more safely and quickly with Plaid and the financial apps it supports while protecting their bank username and password.

and also Wells Fargo:

> The API used in the agreement will utilize a more secure, tokenized “handshake” between the companies’ servers through which customers’ financial data will be shared. Once integrated, the API will allow customers to share their financial data, while also maintaining the privacy of their user credentials. The enrollment process will be easy and designed to work seamlessly within Plaid-supported apps’ user experiences.

I think it would be good to do some quick Google searches before getting (all of) the torches out.

https://media.chase.com/news/plaid-signs-data-agreement-with...

https://www.businesswire.com/news/home/20190919005081/en/Wel...

They're not hiding the fact.

From their website [1]: "When you choose to connect your financial accounts to an app using Plaid, you will be prompted to enter the username and password associated with those accounts. Plaid then links your accounts to the app you want to use so you can share your data."

[1] https://plaid.com/how-it-works-for-consumers/

In the “startup” world, this is simply the only way to do it when your goals are to be everyone’s service. Banks rarely create open APIs, and even when they do they are fragile and subject to whims as the banks are optimizing for security first (plus: they need strong incentives to maintain APIs since it’s not even in their core business).

And since you can’t rely on an API, “there’s no other option” which compounds with the fact that coding up a web scraper for a specific bank takes maybe a dozen programmer-hours. Then throw on a disclaimer to cover legal, and start counting your billions of unhatched eggs.

VC's actually tend to love companies that are a little bit sneaky. Just not too sneaky to have to face consequences.
I don't think you are naive at all regarding this but generally people see famous people, name dropping and due diligence goes out the window.

There are people who take advantage of that and are very successful. Disgusting because it is just another form of deceiving people's trust.

> Also, giving your credentials to any third party, including Plaid, voids the warranty at many financial institutions. If your account gets hacked and your money stolen, you may find out that the zero liability policy no longer applies to you.

The trouble is, giving someone your account number also makes it not the bank's problem what they do with that number, even if it was clearly unauthorized by you. There's no good way to do ACH transfers without a high degree of trust in the recipient.

It's difficult to draw a clear line between what Plaid is doing and a phishing scam.
> takes the information, stores it on its servers, and uses it

So does, for example, Yodlee, when you use them to have an API for bank statements. I cannot say if they too monetize the data that opens up to them for grabs.

It took legislation and years of preparation to enforce APIs and interoperability onto European banks (yes, I can now use bank A's app to view my account balance in bank B, while maintaining control over what kind of access I'm giving). Can't see it happening in the US, though, although the demand for such APIs is clearly there, given that companies like Plaid and Yodlee prosper.

No, that's not the problem at all. The problem is that Plaid falsely used TD Bank without having a relationship with the bank. The company literally has a bank partnerships team so that "void warranty" argument doesn't even make sense.
> Also, giving your credentials to any third party, including Plaid, voids the warranty at many financial institutions.

Funny enough, I've seen that be the case at some banks that simultaneously integrate Plaid into their online account application flow for the initial/funding deposit but. Pretty ironic that users are implicitly coerced into voiding their liability protection at their existing bank during the course of opening an account at a new one. Who wouldn't hesitate to turn around and also invalidate your liability protections themselves if you used your new bank's credentials with Plaid elsewhere.

That´s interesting, and it is an important "stick". On the other side, I know some banks are giving a "carrot" to these types of companies by providing a "portal access" that allows these companies to connect their customers with their bank accounts so that the customer can select what to share with these sites.

Of course, once those portals are enabled we enter the Facebook game: Where a lot of customers will blindly give all access to Plaid like companies, and then consumer group advocates will criticize for the amount of information that they are (still) mining from ignoring customers.

Good god that's disgusting behavior. Surely VISA would have seen this as a huge risk?
Oh man I can't believe they actually pulled this on a Canadian Bank.

I tell my founders to always always fly straight or don't fly at all because if you cut corners or deceive, it will come back to you.

Had they been honest and played by the rules they could be sitting on a massive windfall.

Unfortunately, some VCs and founders think like gangsters and get surprised when things dont plan out. Just because it worked for someone in your circle doesn't mean its gonna work for you. It is a horrible behavior to emulate.

As someone who's worked in fintech for 10 years, I think this is a bad take. Out of all aggregators (what this is called), Plaid is by far the most open and privacy-forward.

First, they're transparent about being a 3rd party that's part of the flow (see https://plaid.com/blog/the-all-new-plaid-link/). It's clear it's Plaid, they use neutral colors and not the bank's, etc. They have a portal where you can manage your data (https://my.plaid.com/).

Second, they are very open about not selling data (unlike most of the their competitors). It's in their terms and their website (see https://plaid.com/how-we-handle-data/). I guess that could change, but from working with them I know it's part of their positioning so I'd be surprised if that changed.

Third, they've announced bank integrations and afaik they're moving to OAuth where the banks support it (I've seen this in the wild, but can't replicate right now). The key here is where banks support it. I think you have to look at the historical context: the banks do not want you to own your data as a consumer. They don't want fintech apps to exist. Having talked to banks about integrating directly with them, it's onerous and only the big players can do it. Plaid's fighting the good fight for fintech startups.

But yeah it's a less-than-ideal solution and it sucks that it doesn't work without creds flowing through and it's not clear regulators or banks will work to make it better. That sucks. I just think bashing on Plaid here is one-sided.

(throwaway account because I work in fintech)

> It's clear it's Plaid, they use neutral colors and not the bank's, etc.

Every time I've been confronted with a Plaid-backed bank login prompt, they use the bank's colors and logo, the word "Plaid" or their logo is either nowhere to be found or is in tiny fine print, and I run away screaming from that service.

The plaid flow is typing your bank credentials into a domain not controlled by your bank, it's pretty big fail right at the start.
> But yeah it's a less-than-ideal solution and it sucks that it doesn't work without creds flowing through

I can appreciate that Plaid is trying to push stuff forwards, but (Presumably) storing your bank credentials in plain-text is a far worse than a "less-than-ideal solution".

I once went to use plaid to apply for a mortgage on one of the new fancy broker platforms. It asked me to type my login credentials.. sketchy , but alright banks and mortgage companies seem to trust them? Then they asked me to disable 2FA on my account and at that point it was indistinguishable from a phishing attack to me. I noped out and changed my bank password immediately.
This is why a standard API is needed, like Open Banking in the UK. When I use a third party app, the access request is redirected to my bank app and authorisation is granted there. At this point it is explicit what data the third party will require. Once authorised, I’m redirected back to the third party’s app. At no point have I given my credentials. This must be renewed every 90 days. Furthermore I can view what apps have access to my account and can revoke this access at any time.

PS Yes I know people like Ben Thompson [1] and even the US Treasury (mentioned in the same link) advocated for a private solution like Plaid (and nearly by extension Visa), but seriously this seems like something that needs to be government regulated to prevent incentives for selling user data.

[1] https://stratechery.com/2020/visa-plaid-networks-and-jobs/

I tried to use their API for a personal project and found starting one month a bunch of transactions were missing from my bank account. It turned out Chase included a promotion on the pdf statement that month which threw off their scraping algo. Really woke me up to their "tech", I changed passwords and avoid them now.
I can confirm this as I currently use Plaid in a few projects. People have no idea what they are signing up for when they authorize this. It's possible to get near real time transaction data from somoene's bank account as well as monitor their account balances for any linked account essentially in perpetuity. With this data it's possible to back in to a lot of behaviors about someone's life. All of that is handed to any firm you authorize to link your bank account.
Now I know why I can never think of good ideas for a business, I'm thinking about what I can build to help my customers, but in today's SV I need to be thinking how can I more easily steal user data at a lower cost than my competitors.
FWIW their competitor Teller uses the bank's own native APIs.

The idea is the bank can't shut off Teller clients without shutting off their own customers. This involves a lot of iOS reverse engineering.

So things like Plaid's Capital One integration breaking for months have never happened with Teller - who've been running for something like 5 years now.

https://teller.io/

So Teller reverse engineers a bank's internal APIs and uses those to manage your account?
They really do need an OAuth rather than save-and-forward-credentials approach to account access. Hopefully the new FedInstant platform will have improvements in this area.

That said, I personally wasn't surprised to see they have this access. It makes sense that if you give them your bank password, they will have full access to your account unless they clearly convince me otherwise.

Yes, awhile back my bank account was decoupled from Venmo for reasons unknown. I unwittingly used Plaid to sign into my bank account instead of the usual wait a couple days procedure. No indication whatsoever - only found out because I saw an article, probably on here, about this company and their basically fraudulent practices.
I was under the impression that Venmo uses Plaid’s APIs on the backend, no?
This is so terrible. Is there an easy way for me to write to Plaid to delete all my information or do I have to go into each service and unlink?
If you're in CA, use the CCPA. They claim to have removed my information in response to a CCPA request.
IIRC, they have basically an instance of a scraper for every different bank web site, which to me doesn't seem very scalable. I'm not sure if this is still the case, but when I interviewed a few years ago, it definitely seemed that way.
That's not true. Plaid says they'll be accessing your information literally when you sign into your account.
Well, better one small company doing that garbage than Visa! It makes it easier to avoid.
I am sorry to say this but your friends should really give a thought to why they are still working there. I understand that people have families to feed and mortgage, but they should at least consider changing jobs if they are software engineers.
Pretty much how 99% of this data robbery happens by all surveillance companies.

This is why Facebook is so pissed off at Apple that it dares to ASK users first.

"Most users aren't aware what data is gathered about them" is about 10x more accurate than "users don't care about privacy", even though it's the latter that gets repeated all the time (with some help from the surveillance companies themselves spreading this propaganda).

Blame the banks for dragging their feet and not making proper APIs for these companies to use instead of screen scraping.
Why are you sorry for them? They are making the choice to work at Plaid when they know Plaid is a terrible legal phishing company.
I can't wait until we have smart contracts on a privacy coin that let me invest and grow my wealth anonymously.
Anonymously is unlikely - how would the government get their taxes?