Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The fact is pretty much hidden. I tried to link my Toshl (a budget app) account to my bank, to import automatically my movements. I saw that they were using Plaid, and I found that weird. I went to search the page you linked, and I still didn't know how was it connecting to my bank. I used an "application password" with limited permissions from my bank to use with Plaid, and funnily enough it didn't work. In fact, my bank locked my account because Plaid tried to login through the regular user interface with a wrong password several times. It was only then when I saw in forums and such that what Plaid does is to scrape HTML.

When you use Plaid, you don't get the impression that's what they're doing. We're used to dialogs to "give permissions to an app" that don't share our user/password with anybody. Plaid purposefully emulates those dialogs and gives you the impression that you're just logging in with your bank, instead of explicitly telling you "we will store your user and password and use that to log-i with your bank".



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: