Plaid co-founder William Hockey is leaving
medium.com
medium.com
What does Plaid do better? Is it just a more modern stable variant, or does the end user experience something more akin to "one plaid account for all my plaid connected services." Do I have to type my bank account number in twice if I sign up for two services that utilize plaid?
Dwolla isn't even in the same business as either.
Essentially, the problem is so hard that the quality of the solution really matters. While there are barriers to entry to supplying an account aggregation service (imagine building 15,000 web scrapers), there's a lot of demand for product improvement, which only happens when there's market competition.
From the perspective of a new startup, Plaid also has a much more modern API and treats documentation as a much higher priority than most of their competitors - you can get up and running in an afternoon, which is absolutely not the case for every provider in the space.
Plaid also had much better support, at least in the early days - level 1 support was a native English speaker with deep technical knowledge of the product, level 2 support was a founder of the company.
Let's say, for sake of argument, one day a Plaid user logs on to their bank account and discovers missing funds. Does the bank get to say Plaid users automatically lost consumer protections under e.g. Reg E and similar by sharing account credentials? Not an expert but it seems to me the answer is probably yes.
Banking in the US is so horrible at the moment. there’s an immense opportunity for someone to come through and give a better consumer experience, but I fear the barriers to entry are far too high. I had high hopes for Simple.com, but they ended up destroying about every useful feature they had and falling way short of the mark...
There was a clever hack someone posted here a while ago about using the email alerts feature to essentially get a read-only feed of transactions from a bank account. It does require you to parse the email and build your own system, so it wouldn't work for most people.
That's why Europe's move to require a modern, unified API for banks, planned to start this fall, is such a great thing. https://www.openbankingeurope.eu/ Most banks' incentives are not aligned with giving data to third parties ever. This is a case where hands-on regulation to compel banks to participate, and thereby clearly assigning legal liabilities, is such a great thing. Otherwise, we know for a fact that providers like plaid will fill that gap in functionality, kindof like the economics of black markets.
1) Ask users for their plaintext login details to financial institutions
2) Store those details unhashed because they'll be used to authenticate directly with said institutions because they're not implementing some sort of reasonable Oauth flow
3) If users have 2fa enabled and the 3rd party doesn't allow app-specific passwords ask users to disable 2fa JUST so the user can use Plaid???
It seems like the product goes against every single good practice that websites have been trying to train into their users for years i.e. `Don't type your password for abc.com unless you literally see abc.com in the URL bar`. Not to mention they masquerade as an Oauth flow with plaid.js on sites that support it.
Can somebody explain ANY way in which Plaid is a net good for users/security/etc??
How most of the world works. The fact plaid is needed is a gigantic hack and a disgrace but it's not like US banks are any good at APIs.
Plaid solves the problem of people wanting to give third-parties access to their financial data. The fact that in some cases it's a kludge to work around this and not secure end-to-end (although I do think Plaid natively supports 2FA now, at least for some banks) is due to the banks not making this easy.
At the end of the day people are going to get what they want, and many many many people prefer convenience (in this case, the ability to use third-party services like Truebill, Mint, etc etc) over perfect end-to-end security.
The end of _that_ day is when all of their credentials are leaked from a data compromise.
I would agree that most people prefer convenience to security (and that they are two opposite points on the same line), but people only learn what security means when it's too late.
I don't disagree, but banking is not an arena where "creative disruption" that has harmful side effects should be welcomed. The reason you can't send money from one bank to another efficiently in the US but can in the UK is purely due to regulation. Or why there isn't an Open Banking Initiative in the US but there is in the UK. Once again, regulation.
The private market isn't making the solution better in this case because their implementation is reckless and potentially harmful.
You could make this same argument about the existence of online banking. At some point utility supercedes risk. Personally, I feel fortunate to live in a society where I am able to make that decision for myself rather than the government making it for me.
How so? If I'm using Wells Fargo and I find out they have a breach, I can happily switch to another bank because they're clearly being incompetent. If a software provider that I'm using uses Plaid and Plaid gets hacked, then my banking data is potentially compromised. The bank has zero control over that, so there is no impetus for me to change banks, yet it's their data that has been compromised.
> Personally, I feel fortunate to live in a society where I am able to make that decision for myself rather than the government making it for me.
For most things, yes I agree. Do you think it's any coincidence that the banks haven't adopted modern/secure API access even though their consumers demand it? That's not the definition of a free market and is at odds with "having a free choice is better than having the government do it for me".
OFX (Open Financial eXchange) was designed in the late 90's to address this need.
Many banks implemented OFX, but not all.
Hence, we end up with screen scraping services like Yodlee and Plaid.
(I don't know the specifics of Plaids infra. It's possible they store revocable oauth tokens instead of passwords)
Now I am wondering could it been Plaid? I read that they are mimicking bank's page design. there was no URL in the app to verify where I am putting my credential in.
now that I am thinking about it, it was super stupid of me.
I recently dealt with one and it was so refreshing to have someone who consciously knew their job was to be my guide and educator through the process.