PSD2 – a directive that will change banking in Europe
evry.com
evry.com
1. It's better than what we have today. 2. PSD2 is standardizing and increasing access to financial data, making the entire ecosystem more competitive.
Regarding #1: I understand the concerns regarding privacy and security, but this injects a whole new range of improvement that quite honestly we don't have today. Unlike many countries that have rendered their bank account number useless, the US has not. Today, we all provide our bank account numbers to a variety of companies (our jobs for salary, rent, etc.) via a direct credit or debit authorization form to a third party. The proliferation of Private Account Numberss in the digital age is exactly what's makes them such a high-value target for criminals. A digital authentication and authorization approach allows us to set parameters around authorization, rotate keys, create programmatic constraints, inject real-time security, and a number of other consumer controls (e.g. remove authorization for that annoying magazine company that charges me every month for that Better Homes and Gardens magazine I never ordered). This can all be done without providing the level of access we and banks provide on our behalf every day.
Regarding #2: Banks are great at a number of things, like holding and securing our money. They're terrible at responding to market forces or consumer concerns. Instead, they use the mountains of red tape and regulation to fortify themselves from new market entrants. Greater, more open access to financial information levels the playing field; thus, increasing both innovation and better pricing for all.
TL;DR - this is way better than what we have today.
PSD2 will create a clear regulatory framework, will introduce consumer protection, oversight from competent authorities and ultimately will create a transparent liability model for all the actors involved in the flow (data and payments). I think this is a great outcome for consumers and market competition. PSD2 is not perfect but is shaking the industry quite a lot.
I'm working on TrueLayer (http://truelayer.com) which is a universal bank API platform in the context of PSD2. Email in profile if you want to chat about this topic.
Especially given the state of European banks (TLDR: who are going to need a bailout soonish).
Regarding the risks you (and other in this thread) mention: This really isn't something that has any impact on the system's exposure to risk. It's just a technical process for moving information and (limited amounts of) money between banks and financial service companies. If you're worried about a meltdown of the banking system, you have to look at the regulations on capital requirements, accounting standards, asset valuations etc.
What do you mean by this? I am not in the US, but I find the bank account number to be useful quite useful as it provides a way for people to send me money :-)
I am not familiar with US banking system.
If you're banking in an EU country there will be a process to stop your account from being continuously charged for a service you did not purchase. For instance, in UK banks this is usually a standind order or direct debit, which you can cancel at any time.
In any case it's hard to see how making your account information available to third parties is going to protect you against this kind of thing.
I do not see why I should entrust anybody but the bank with information about my wealth. This will get abused and I will probably get nudged into this, so that the company selling an unrelated product can sell my information.
If you want to do a product using my banking data, then do a product using FinTS (https://en.wikipedia.org/wiki/FinTS) and not as a service that grabs my data to you.
> PISP (Payment Initiation Service Provider) are the service providers initiating a payment on behalf of the user.
No thanks! Direct debit and wire transfer work good enough. This probably will open the door to insecure payments without 2 Factor Authentication.
> For banks, PSD2 poses substantial economical challenges.
They are already under stress to provide low-cost bank accounts with the low interest rates of today.
I am currently with a bank that I can trust (credit union) and I really do not see much of a need to change.
Believe or not, many people (consumers) do this. For example: every Mint.com user
PSD2 mandates "strong authentication", which is multi-factor, if the transaction is above 50 euros in value.
This will enable processors to initiate and verify payments for a fraction of the costs. 2% can really add up as more and more commerce moves online.
To clarify, this is presented as a good thing.
Of course, my bank doesn't have a "monopoly" on my account information: that information is not a commodity. More so, it is definitely not something that I would ever want to have change hands and be traded around. I entrust my money to the bank, very grudgingly, because it's a convenience, but I definitely, very very definitely, do not want it to share any information about the services it provides to me with third parties.
I really hope the article is misrepresenting the new directive, or that at the very least it will be a unique legistlative exception that somehow manages to provide adequate safeguards to my privacy, otherwise... OK, I don't know what, otherwise. This just sounds insanely stupid. In terms of protecting EU citizens' privacy it's a giant leap backwards.
For example, manually retyping my bank account transactions into my accounting software will hopefully become a thing of the past. And long overdue too!
This does in no way change the data-protection requirements. They can not share your data with third parties without your consent beyond what is currently allowed.
PSD2 is _not_ a carte blanche for every regulated PISP/AISP to consume Bank APIs for any arbitrary user. API access will be secured by the Account servicing PSP (ASPSP) security credentials. I.e. in order to initiate a payment the PISP will have to collect the users security credentials (password, mTAN or other OTP) issued by the ASPSP.
Same goes for AISPs, where the customer must be initially authenticated with ASPSP credentials and then authenticate again after 90 days.
* How do I know the PISP/AISP is going to do what they say, how are they accredited?
* If Spain has a very lax accreditation process then fraudulent PISP/AISP's will congregate there to scam other europeans - how do you stop this game of wack-a-mole when each country in the EU is defining their own system?
* There's hugely complicated Strong Customer Authentication regulation that's just been released in draft adding complexity to an already complex system
The problem is not _any_ arbitrary user that people are worried about, it's scams. If I approach 1000 people and 1 manage to scam one, I have access to all their financials
Here's a fun doc if you're interested: https://www.eba.europa.eu/documents/10180/1761863/Final+draf...
The article author is sadly uninformed on this one. In Germany, HBCI is employed since 2002 by 2000+ banks, approximately half of German banks (https://de.wikipedia.org/wiki/Homebanking_Computer_Interface).
Of course ever bank everywhere has, for the last 20 years+, offered some way for their customers to interact via an API.
Sorry, you're flat out wrong there. You can implement both an AISP and a PISP using HBCI.
An AISP needs only a bank that supports HKKAZ/HKEKA transactions (aka, fetch transaction records). A PISP needs HKAOM/HKAUB/HKCCS (aka, initiate transfer transaction) transaction support from the bank.
> Of course ever bank everywhere has, for the last 20 years+, offered some way for their customers to interact via an API.
In most cases only for professional customers. HBCI (in Germany, though) changed the table as it was explicitly intended for private/small business owners.
The underlying objective is the creation of a smooth and level market for payment services such that competition between European financial services companies increases, rather that being limited to banks which tend to be restricted to the country.
Actual text of directive: http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:320...
See also http://www.thebunker.net/blog-psd2-is-a-disruptive-game-chan...
and https://www.out-law.com/en/articles/2015/january/key-feature...
and https://www.starlingbank.com/explaining-psd2-without-tlas-to...
Every other nation in the world allows direct person-to-person transfer between any bank. You put in your friend's name, BSB and account number into your phone in Australia and the next day they have money. In Germany, you have additional 1-time use TAN numbers.
Only in the US must we use PayPal, Facebook or paper checks. In fact, paper checks are the only way to send money fee-free between banks. You can of course just display a check on a screen and have the other person take a photo of it with their phone, but that's still pretty ass backwards.
Banking should allow direct transfer at the state level, without third parties or fees.
In germany all SEPA transfers are free
I don't pay for SEPA transfers either. But they're not all free in my country.
Which my bank does.
SEPA (both intra-country and SEPA-wide) transfers cost money. FFS, even in-bank transfers cost money. €0.10-0.40, depending on transfer direction, bank and wether done online or in-person. But banks are happy to wave fees if you signup for a discount package (debit card + iban acc + free withdrawal + free transfers) or eligible for premium account for one reason or another.
Clarification: that is to say for the same originating party. Different banks can charge whatever they like, but always the same amount for any SEPA payment, regardless of the target bank.
It's more or less the same in whole SEPA area. Receiver's bank details (name + swift + address) are needed for international transfers though. I know for a fact that's all I needed to make payments to Poland and Germany. I received transfers from other EU countries with these credentials too.
Full message I've received: We thought you might like to know that we put https://news.ycombinator.com/item?id=13921072 in the second-chance pool, so it will get a random placement on the front page sometime in the next 24 hours.
This is part of an experiment in giving good HN submissions multiple chances at the front page. If you're curious, you can read about it at https://news.ycombinator.com/item?id=11662380 and other links there. And if you don't want these emails, sorry! Tell us and we won't do it again.
Thanks for posting good stories to Hacker News, Daniel (moderator)