Wait, in what century do you live that your online banking transaction overview doesn't have up to date data ? Also, your bank allows you to log in with just a username/password ?
The online banking CRUD interface might have up-to-date data, but it isn't an API, and being behind some weird proprietary single-sign-on setup makes it pretty hard to scrape, too.
> Also, your bank allows you to log in with just a username/password ?
Yes, this is common in the US (and here in Canada, too.) We sometimes get asked for "security questions", but support for 2FA is extremely rare, and I don't think there's any bank in North America that requires 2FA to login to your online banking. (The "government or bank issues you a smart card that can be used for session encryption; bank issues you an adapter to plug it into your computer" thing doesn't happen here.)
That’a why they also provide an API. They are required by law to do so (https://en.wikipedia.org/wiki/Payment_Services_Directive)
> I don't think there's any bank in North America that requires 2FA to login to your online banking.
This is required by the same law.
I'm pretty certain it's the same way with every other major US bank.
> This is required by the same law.
FYI: no bank has to follow EU laws in North America.
Trivia: this is used by a Mint-like company in Brazil called GuiaBolso - you give them just the "read-only password".
I do agree that the DB could be removed from the system, adding the transaction directly from the SES-triggered event, and that would work for most cases.