Wells Fargo's Bid to Vanquish Screen Scraping
americanbanker.com
americanbanker.com
APIs are good, as are OAuth-style permissions requests where users get to at least know what data a service is asking for. But they shouldn't be used as a way to kill off screen scraping. They should be a better option that allows screen scraping to die off normally. The aggregation industry that scrapes hates it even more than the banks do. It costs them a ton of man power to keep it working and each integration needs to be done as a one-off. If the banks provide a better solution, it will get used. Better yet, if they can come up with a single standard API that will work with most/all banks, that would be even better. But if the banks also take measures to prevent scraping, it is going to cause problems and not be a good thing for account holders.
Then I see further down: it's for the FUBAR tax return system in the US.
Here's a solution for you: fix your damned tax return system first (and watch Intuit go out of business in the process). Then you've solved many big problems, not just a small one.
Tax is not the only reason. How about data analysis services for your personal finances? e.g. mint.com.
Round here (Norway), your bank already does this analysis part. When I log into my bank's app or webpage, I get an instant overview of how much I spent last month on the mortgage, food, gas, insurance, clothes etc. And I can define custom categories, as well as change how the system sorts transactions into different categories.
The budgets for the next 12 months my wife and I keep in a shared Google Docs spreadsheet. Planning requires thought, so I'm skeptical that you can automate a budget and then have people follow it (unless it's a very lenient budget).
> Planning requires thought, so I'm skeptical that you can automate a budget and then have people follow it (unless it's a very lenient budget).
I agree with your point - your budget is specific to your situation, so you will still need to plan it yourself. But - once the budget is set up - don't you see some value in not having to update your spreadsheet and compare it to your bank statements? Or getting a notification on your phone that you are approaching the limit of your entertainment budget this month, because the system has tallied up how much you spent in the coffee shop?
Actually, banks are for aggregating capital. There is no institution in the Western financial system where you can just store money. The best you can do is put physical cash in a safe deposit box.
Security shouldn't be a premium feature.
"Security shouldn't be a premium feature."
Apply liberally.
I am Australian and at least one bank here does this. We used it for a book keeper in a former company. It was helpful for the book keeper to have the ability to access our financial data to do their job without having to hassle us for data exports or whatever. At the same time the don't want to be in possession of a big collection of bank log in details that could be used to steal money.
It let them log in, export the data they needed and that was all.
If you go to http://www.boq.com.au/ and go through to their log in screen this is why there are three text boxes instead of the usual two (a clunky solution to needing different login details from different people).
[1] https://community.commbank.com.au/t5/NetBank/How-to-set-up-a...
Call your bank.
Ask for these features.
What have you got to lose? They'll probably ignore you, but we have to start somewhere and asking them certainly won't make things worse.
It's not an API that anyone can hook into, just Xero.
Banks also depend on cast-iron control of the channel to cross-sell other products and services. The thing about 1st party bank APIs is they completely undermine all of this and that is why they haven't happened.
The end-of-days scenario for retail banking is a 3rd party coming along to build a superior banking experience atop of their APIs. The 3rd party starting from a market share of 0 has no choice but to align their incentives with the user in order to grow. This will manifest in apps that proactively warn users before their account incurs charges, notifies users when they do, and present products and services that compete with the banks but are better value for the user. A 3rd party will de facto end up owning the most important banking channel and this will ultimately devastate the bank's revenues. All of this is terrible for the bank but great for the user.
When you decompose things into underlying incentives it becomes clear why things have or have not happened and will or will not happen.
There are various initiatives to compel banks to provide open APIs, e.g. PSDII in Europe. However considering the aforementioned incentives it seems obvious that banks will not act in good faith and will find any excuse (vague hand-waving to security, fraud, etc) to subvert the UX of the API such that any service built on top of it is awful to use. A concrete example of this is the gestating RBS API, they require a 2FA SMS code before moving money over £30. This is something they do not do and will never do in their own private APIs that power their own mobile apps because users will not stand for it, but they can do this with a public API that has no users to speak of very easily.
Considering the current incentives 1st-party banking APIs (at least the ones we would wish to see) will not happen. The only way that can change that is through market forces, i.e. one bank has to provide the APIs that cause material customer churn at other banks. Given this it's clear screen-scraping is going nowhere anytime soon, in fact it will evolve, by directly hooking in to the private APIs that power the banks own APIs for more robust, and fully transactional APIs, i.e. payments and transfers.
Disclaimer: I have started a company that does this - https://teller.io/
Follow up questions:
1. Why is Wells Fargo doing this if it poses such a threat to their penalty-based-fees revenue stream?
2. Are there services currently doing the type of account alerting using screen scraping tech? If not, why not?
2. Not that I am aware of. I expect that is because the largest provider of screen-scraping feeds is prohibitively expensive (requires large up front fees and minimum commitments).
[1] http://www.americanbanker.com/news/bank-technology/why-banks...
For this very reason we've created Bankscrap, a Ruby gem to unlock those undocumented APIs. The main difference with the services behind apps like Mint is that:
A) We do not use screen scrapping.
B) It's all open source! Check it out:
We've been typing usernames and passwords for our very important _banking_ accounts into third parties like Mint (instead of using OAuth) for several years now.
However, it is disappointing that this is just a single bank and not a group of banks developing this - and especially, that a battle-tested standard was not adopted.
edit: in Germany, actually, there's for commercial use the DTA standard (https://de.wikipedia.org/wiki/Datentr%C3%A4geraustauschverfa...) since 1976 (!), which has been replaced only recently by SEPA/ISO20022. Meanwhile, US banks decide to follow xkcd #927 (https://xkcd.com/927/)...
Which unfortunately also makes them the perfect marks for being sold inappropriate tech solutions (see: blockchain mania).
I dunno.
http://fineract.incubator.apache.org/
Apache Fineract (\’fīn-,ә-,rakt\) is an open source
system for core banking as a platform. Fineract
provides a reliable, robust, and affordable solution
for entrepreneurs, financial institutions, and service
providers to offer financial services to the world’s
2 billion underbanked and unbanked.http://money.stackexchange.com/questions/2212/how-does-mint-...
Mint now uses an internal service (called FICDS, IIRC, but I'm no longer at Intuit) that still scrapes. That service also handles bank interactions for Quickbooks, TurboTax and Quicken, though the latter was sold off, so may be moving to something else. Additionally, that service allows the use of tokenization, which greatly reduces the chances that account credentials would leak based on a vulnerability in Mint or a rogue employee, since that team is pretty locked down and Mint, TurboTax and Quickbooks never store banking credentials.
As an aside, I wonder why Wells picked Xero to trial their API. It could have been a lot more impactful by doing a trial with Intuit, especially if they could have had it ready by tax season.
Also, here's a fun fact: For a number of years, Mint employees at Intuit could not see their own employee stock plans in Mint. Morgan Stanley's site was a Flash monstrosity that couldn't be scraped correctly. Asking them about it earned you a well-practiced eye roll.
Given Intuit's checkered past with QFX, If I were writing a nascent API for FX, I wouldn't want them anywhere near it.
Having your customer's data is a competitive advantage when it comes to cross-selling other services.
Banks move at speeds that make most glaciers jealous and Intuit has some financial incentives to keep the spec complicated so it's really no surprise we've been stuck with it so long.
A new open standard would have been nice, but I wouldn't hold my breath on other banks implementing it, so I can't really blame WF for going it alone here.
FWIW, we switched to Bank of America and can't complain. I can send wire transfers online without issue.