1) Ask users for their plaintext login details to financial institutions
2) Store those details unhashed because they'll be used to authenticate directly with said institutions because they're not implementing some sort of reasonable Oauth flow
3) If users have 2fa enabled and the 3rd party doesn't allow app-specific passwords ask users to disable 2fa JUST so the user can use Plaid???
It seems like the product goes against every single good practice that websites have been trying to train into their users for years i.e. `Don't type your password for abc.com unless you literally see abc.com in the URL bar`. Not to mention they masquerade as an Oauth flow with plaid.js on sites that support it.
Can somebody explain ANY way in which Plaid is a net good for users/security/etc??