Big Banks Lock Horns with Personal-Finance Web Portals
on.wsj.com
on.wsj.com
Oh well, until banks decide to stop allowing users to manually save .qfx files the worst they can do is make life inconvenient.
By tokenizing each account, it ensures that if a breach of any of those products were to happen, the bank authentication credentials won't be leaked.
When using Express Web connect to automate Web connect downloads from your financial institution's Web site, your user name and password are encrypted and, depending on your financial institution's procedures, will be stored on our firewall-protected servers or in your Quicken software. Your financial information is transmitted using secure socket layer technology and is encrypted, so it is unreadable during transmission. It is then stored on our firewall-protected servers and is securely transmitted directly to your desktop computer when you initiate One Step Update. Your information is confidential and is not used for anything other than providing and maintaining the One Step Update service.
http://quicken.intuit.com/support/help/account-transaction-i...
The entire world of aggregation is simultaneously really interesting and rock-boring stupid. I'm surprised we don't see more fintech startups using it more aggressively, even as I am happy this made my former endeavor more acquirable.
Expand the "Express Web Connect / Quicken Connect - Details" section underneath the comparison matrix and you will see this:
* Your login credentials are stored on Intuit-hosted servers. This makes updates faster for you.
* Your financial data is stored on Intuit-hosted servers. This provides a more complete history of your financial transactions than is typical for data stored on financial institution servers.
* We use state-of-the-art security measures to protect your login credentials and your financial data.
----
This is half of why I pay $9.99/mo to use Direct Connect with my Wells Fargo account (that, and having bill pay within Quicken is pretty handy).
Sorry to nitpick, but the bank has a legal obligation, not right - they don't have a choice other than to make sure data is correct
If the latter is the real reason they are whining then I expect they will push for a fee than can charge people who access their account through an aggregator much like they charge people who access their account through Quickbooks.
As a bank, you are a commodity. You simply store the bits that say how many resources I can consume over a moving window of time.
They absolutely charge their aggregators. Most of the aggregators can't screenscrape without permission of the aggregators. Why on earth would you think they can't? Why do you think Mint doesn't need to do MFA for so many banks and can just get away with a user-pass challenge?
This is about holding control of their customer base, plain and simple. They know everyone else, even other banks, are eager to dis-intermediate their customer base. They're spending too much money maintaining branches and offering inferior savings products to compete digitally, so they would rather delay that as long as possible.
A big bonus of this approach is that I have complete control over the data, so if an import get screwed up somehow I can fix it manually. Mint's "black box" approach is good when everything works flawlessly, but you're stuck doing weird hacks if anything goes wrong or you want to do something it wasn't designed for.
Ledger, incidentally, is from the same one who is now maintaining Emacs, if I'm not mistaken.
[1] http://captin411.github.io/ofxclient/ [2] http://www.ledger-cli.org
Thanks for the link to your project, looks really useful!
Also, the first link I posted isn't my work, just a nice utility I found. I did roll my own Python for converting OFX to Ledger though, been meaning to clean that up and post it but haven't gotten around to it yet.
I'm pretty sure that doing that in the UK instantly nullifies any protection you have against fraud etc.
E.g. Barclays:
"You must memorise your PIN or password ... Never give them to someone else or let someone else use them, or do anything that would let someone else use them, such as writing them down in a way that might be recognised by someone else, keeping the letter carrying a PIN, or giving someone else access to a device like a mobile phone on which the relevant details are stored."
"If you have either deliberately or with gross negligence: • failed to keep your card, PIN, password, PINsentry or mobile PINsentry generated codes, device or equivalent secure, or • failed to tell us as soon as possible that you have lost your card (especially if you think someone else might have been able to ind it) we will not refund any payments made before you tell us that it’s been lost or compromised."
This does invite the question of why Mint isn't using (or even just offering) OFX read-only credentials... or do they?
I that's the sort of concerns that did in the start-up greplin. They would have access to all your password protected data for any service under the sun.
Customers will always want to extract their data.
The UK is moving in this direction. The ODI/Fingleton report into Data Sharing and Open Data for Banks[1] recommended creating a open banking API standard and suggested using OAuth, using Twitter as an example (see p24 of the report). Work has begun on defining the roadmap towards creating an API standard[2].
1: https://www.gov.uk/government/publications/data-sharing-and-...
2: http://theodi.org/news/open-banking-working-group-uk-experts...
It's absolutely true that offering data migration services decreases bank account stickiness, and that's something everyone is terrified of doing in the finance industry. Customer acquisition costs are so high, I doubt you'd believe me if I explained them to you.
Of course we would believe you. When you use a metric like "customer acquisition costs", you can say pretty much whatever you like.
I'd rather hear something like, "We have such little deployed value at the retail level that no one wishes to contract with us unless we spend a lot of money over here (legalized entrapment codes and marketing)."
But if you think that even pro consumer banks like Simple had better costs, think again.
It could actually be extended into a very compelling product; imagine being able to issue not only read-only tokens, but a token which authorizes the bearer to withdraw up to $100/month. Parents could issue such tokens to children for emergencies, or other such situations.
http://www.frontporchrepublic.com/wp-content/uploads/2011/09...
Using Bitcoin for its intended purpose is like gambling. Similarly for other, popular P2P. So, safe choice is better implementations of centralized model until stable alternatives exist in P2P space.
Note: Nice graphic but the best thing is looking at boards for interlock. Like Project Censored did in their nice Theory of Everything for global elites:
http://www.projectcensored.org/the-global-1-exposing-the-tra...
Now you know who they are. We've been able to figure ghe stuff out. Why still these problems? Cuz few give a shit or do anything. If that remains, we screwed in long-term. ;)
On the second half of the argument. Banks need address the fact that users needs are changing and they want access to their own data, that they own, not the bank. A bank could create an API service with API keys specifically for these types of aggregate services to use. This could be done at first for just read only access, whereby the API does not allow you to transfer funds, etc. It would be a secure interface to access your data from third trusted third parties or your own apps.
A secure standard API would be beneficial to customers, to third party services, and to the banks that offer them. Freeing information inside of hoarding it, when it doesn't belong to them in the first place.
Credit unions could have a major advantage here if they would start using modern tech.
As someone who collects these daily; I'd rather not collect them. The lengths I have to go to to ensure that they're not a major risk for our product? Significant. It's not a hard problem to solve, but the question is: "do banks want to solve it?" There's not much incentive for big banks to DECREASE account stickiness, and a lot of us waiting for great aggregation tools to totally dis-intermediate the big banks from their customers 8 ways till Tuesday.
But to be honest, financial data is all sort of like this. For example, once someone has your ACH routing and account numbers, the only thing that really stops them from building a fraud factory is the fact that it's difficult to get permission to interact with the ACH network. You need to handle those with at least as much care as bank login info.
And then, there was the MASSIVE fraud spree that everyone who didn't implement yellow path validation for ApplePay opened up. I personally had well over 80k stolen from my account in less than 1 day via that outrageous fraud loop. Thanks, Apple Stores and Chase, for pretending that someone else's fingerprint constitutes my biometric permission.
On the subject of Chase, everyone in the industry was completely shut down without warning at the worst possible time by Chase. We're all pretty spicy about how it was handled.
My capital one 360 account does this. I can generate an api key that I give to mint.
I mean, role specific credentials with limited rights seems like it would work perfectly fine with the existing OFX spec.
Is it? My bank requires multi-factor confirmation to set up a new payee for electronic transfers and sends several emails for any transfer. You couldn't actually steal any money just by having online banking credentials.
Sure, but it shouldn't be the bank's decision to keep me from accessing my own customer data because it's insecure.
If they actually wanted to fix this, it would be entirely possible to provide a read-only API.
In olden times, it might have been a pain. Now most automatic payments hit a credit card, so you aggregate the account changes at that level.
Last time I flipped to get a 1/4 point off my mortgage. I think I had to redirect my utility account and change a few online payment portals for AMEX, etc. Took about 30 minutes, and saved me about $20k over the life of the mortgage.
It has always been a variation on this same theme.
The last time I changed banks was in 2010.
I had made a mistake and I overdrew my account by $5 or so. That was obviously my fault and I should have been on the hook for one overdraft fee. My bank, reordered my transactions and caused me to incur 5 overdraft fees.
When I called in to complain, they "waived" two of them, leaving me to pay $90 when I should have only had to pay $30.
That was it for me. I opened an account at a Credit Union and left about $5 in the bank account so they'd have to keep paying to send me statements.
That went on for over a year until the bank implemented a $2/mo convenience fee for paper statements. In three months, my account was drained and the bank closed it.
People need to be willing to pick up and leave a bank if the relationship is no longer advantageous.
From the bank's perspective, it's always business and never personal. That's how you have to act in return.
One just has to handle it like any other transitional period.
You open a new account with a new bank or credit union and start funding it. You watch your existing bank account for recurring or auto payments coming out and work to switch them over to the new bank account. You have to maintain some money in the old bank account and possibly keep it open for several months or a year.
Treat the old account as a temporary savings account with enough money to cover any checks or auto payments that might get drawn against it. After you are certain all auto payments have been transferred or you feel safe and confident then you close the account with the old bank.
I primarily use a credit union but I do have a checking account with a regional bank that I use strictly for auto payments, this makes it easy to make sure there's enough money in the account and to transition away in the future should the bank displease me.
It doesn't benefit me so I don't do it.
They day after payday, I sit down and determine which bills are due and I pay them electronically. It doesn't matter which bank account I use because I handle them individually, every payday.
I could switch banks today and my process wouldn't be interrupted at all.
The disadvantage is "An outside entity can remove an arbitrary amount of money from my account at any time, keep it for an indeterminate amount of time, then return it without penalty."
I could see have a charge automatically applied to a credit card (where you're able to dispute it, if necessary). I cannot imagine why anyone would ever want to set up direct withdrawals.
A few tips to stay nimble and cover your bases during bank changes:
1) Don't use any bill payment services
2) Any automatic payments you do online, set them up for your credit card if you can (I'd recommend this anyway to take advantage of rewards)
3) Keep a detailed list of where your bank accounts details are stored for auto or manual deposits and withdrawals so when it comes time to change accounts, you have a good checklist to follow.
3) Think about setting up a permanent "home base" account that you can transfer money in and out of from other banks. The idea is that you'll always have this account, so it can be used to pay bills, write checks, day-to-day, etc. and you just funnel your direct deposits from other banks into this one.
Depends on what position you're in, and how you've previously organized your finances. If you still write checks, you have to leave the old account open with enough funds and wait for all of those to clear. If you have things pointing at your bank debit/credit card, you need to change those and wait for any outstanding charges to clear. If you have direct deposit of a paycheck, you'd need to change that. And any services hooked up to your bank account via the usual "tell us the number of pennies we just transferred in and back out of your account" need re-hooking.
The first three are paid from a dedicated account. The electric company pays me to do pay automatically, so I do. :)
* Always have recurring payments on a credit card, which you pay off monthly.
Bill payments and connected accounts should be minor.
(Then again, they also don't have things like paper checks anymore.)
What do you mean? I don't see how one would even conceivably bring an account number from bank to bank, let alone why it would be desirable.
In my experience, it's actually quite easy to switch banks. No more than 30 minutes tops (open account, change credit card autopay).
Yes, on the "banks should be required to provide a secure, open feed" (though good luck in the one chosen resembling any modern format).
But... securing information of this kind is not rocket science. Sharding secrets into multiple tokens split across minimal service machines, etc. It's just that best practices are so rarely followed.
Though I would imagine that encryption, by definition, is two-way (encrypt, decrypt).
As an aside, do merchant account API services provide a secure-token service to store credit card information? That is, I enter in my VISA credit-card, click "save" and Amazon.com gets a unique token back that identifies this credit card. When I later go to purchase an item, Amazon uses this token to with VISA to charge my card? IIRC, that is how Stripe works, but I wonder if each credit card manufacturer now supports this, as part of PCI compliance.
When a website stores the hash of your password on their servers for you to authenticate against they have no way to recover your plaintext password without brute-forcing the hash. They can verify that the password you sent them is correct but they can't tell you your password.
If, Mint say, encrypts your password on their servers with their own key then they still have the plaintext password because the process is reversible to them.
To do this right, Mint would be given a piece of information, say an OAuth token, which would allow them to authenticate to your bank without them knowing the password you use to log in.
They're not storing "plaintext." They're storing the "ciphertext." The fact that you can decrypt ciphertext to obtain plaintext, does not mean you are storing plaintext. You can certainly derive plaintext from it, but the actual plaintext, that is, the input to an encryption algorithm, is not stored.
If an attacker gets a database, but does not have access to the encryption key, they do not have your plaintext password.
-----
I agree, a more preferred way would be for MINT to use OAuth type data delegation. However, they're beholden to what the banks themselves support, and most do not support anything other than account impersonation via username/password.
I'm working on setting up my own 'mint' for the purpose of working with my expenses, and this is the service I'm looking into using.
Are these the same banks that used to charge "overdraft" fees of $35+ for a $1.50 overdraft? Where was the concern for customers then??
Any recommendations? I'd prefer an organization that was less culpable for the financial crisis.
I read "SF" to mean San Francisco.
Also, I usually have better luck overseas with my credit union visa card than I do with my credit card (since I know the PIN for my checkcard).