An open letter to mint.com: Stop storing my credentials
peebs.org
peebs.org
I could be wrong about any of this, but I believe this was what allowed Mint to say, among other things, that they could provide your financial information without even knowing your name, and that no possible compromise of their servers could result in bank transfers.
Mint's current privacy info is insufficiently detailed to know if they still use this approach. They say "your bank login credentials are encrypted", suggestive that they retain 'login' abilities, but that might be a simplification or fallback (when the read-only delegation is unavailable).
Unfortunately, describing security in more detail often confuses and unnerves customers more than just saying the magic words that make people feel safe. So most companies, whether they are good or bad at security, oversimplify in their descriptions. (That is: the public descriptions that are most true and useful to knowledgeable users won't win an A/B test, maximizing either conversions or feelings of trust, with most customers.)
Update: Here's an old thread where I had questions, and a link provided by timf contributed to my understanding above: http://news.ycombinator.com/item?id=412715
Mint has switched to Intuit's backend (there was a thread on Quora about this) but I doubt their approach is any different since a lot of banks just don't offer any OFX/other APIs.
For one, don't use Mint if you are concerned about their system arechetecture. Wesabe stored passwords locally and did the scraping from your client side. Unfortunately Mint killed Wesabe in the market but maybe there are similar products out there.
For two, the real fault lies with the banks. Issuing that banks simply need to move to oauth is a joke. There is nothing simple about updating and/or unifying every banks online systems. Many banks run custom software and much of this is very old (but very well tested). Making any changes is a massive undertaking that most banks have explicitly rejected doing. If it ain't broke, don't fix it.
Finally, it's strange to fear getting hacked and losing money because of a non-FDIC insured account in mint. Who is using such banks in general let alone in mint?
As a software engineer, I'm always in awe of how well mint works. They have unified a massive number of disparate services. As a end user I love the value mint provides. As a hacker, putting passwords in makes me uneasy, but I'm confident in the banking institutions I use, and Mint's security.
I have accounts in several banks (Europe) and all of them use either a token with pin that generates a one time password or token which you slide your debit card into, enter your pin and generate one time password.
You have to go through the same process for every transaction you make also.
Mint.com is very useful. He wants to use it, but he wants it to use OAuth or similar systems to communicate with banks via an access token and APIs, not stored passwords and screen scraping.
Knowing how backwards even the big banks are, I doubt this'll come for about 50 more years. Nothing Mint can do...
But, they own up to the one security hole that really bothers me. As a sysadmin, I know there is always a way for employees to get sensitive data. If a program can see it, so can a programmer.
Their security faq says: "Can Mint employees view my bank account numbers or credit card numbers? Your bank account and credit card numbers are stored securely. Your information may be seen by technical personnel in accordance with specified procedures and safeguards governing access in order to operate, develop and improve the Service."