The quiet battle raging around open banking
sifted.eu
sifted.eu
"share their bank data with other parties"
What? Who wants to share their what now with whom? Why would they do that?
"Fintechs like Plaid, TrueLayer and Tink have founded their businesses on providing access to regulated banking data for a fee.."
What data? Aggregated? Individual banking? What regulated data? What regulations?
"Under current banking regulation, raw data must be provided for free to consumers via an official application programming interface (or API). As a result, the apps pick up the cost on behalf of their users."
What? My bank doesn't offer an API. I have no idea what that last sentance even means. What cost?
It really seems like the article assumes a lot of background knowledge. Anybody have an ELI5 link?
Barclays will send banking data directly to FreeAgent[1] which allows you to categorize the transactions and upload receipts. FreeAgent uses this information to calculate how much VAT and Corporation tax I owe to the government. Couldn't be simpler.
[1] https://support.freeagent.com/hc/en-gb/articles/360006470520...
They absolutely shouldn't be.
There are/were services like that here too, but what trust (or usefulness to be honest) they had will/has erode/d as a consequence.
Also you don't have to be a literal bank, the better (/with enough of an EU/UK focus) services like that will just offer the proper authentication method instead, now (since 2016 I think?) that it's available.
e.g. Monzo in the UK (&US?) offers a personal-use-only 'beta' API (it predated 'open' banking requirement, and they continue to say it's a developer API in beta, don't share access keys yet but one day, but basically it seems to be vapourware at this point). PSD2's 'open' banking is.. I don't know, it's something, but it's not what anybody here wants, or imagines it is from the name if they've not previously heard of it.
It might as well be a standardised Industry COBOL Interchange Specification, a copy is yours for just £25k today! Or join the 2022 edition working group for a mere £250k, and help define next year's mandatory update.
Do they pay me for making money from me?
Accounting and budgeting services are the most common examples.
As you can see it is sponsored by Nordigen, and they try to say that open banking has some ugly and bad aspects in everything that is not the particular points of their marketing offer.
Accounting or budgeting services for example.
> What data? Aggregated? Individual banking?
TrueLayer & Plaid are gateways that translate bank's individual APIs into a single common one, and their clients pay them for the privilege (typically a monthly fee per active account connected).
> What regulated data? What regulations?
There are EU regulations that force each bank to provide an API to any AISP (account information services provider) or PISP (payment initiation service provider). The (A|P)ISP can request the end-user's consent (typically via OAuth) to access this data.
> My bank doesn't offer an API.
This is why I dislike the name Open Banking. It's not actually open. You have to either to through tons of regulatory BS to become an AISP or go through a gatekeeper like TrueLayer or their competitors (which will happily "lend" you their AISP license). Fortunately, there are modern banks such as Monzo or Starling which allow the end-user to use the API to access their own account, but technically this has nothing to do with Open Banking (even though it's often the same API).
As others have pointed out, Plaid is service that lets people interface with your bank via one API, the Plaid API, Plaid deals with all the various banks. And Plaid mines your account advertising (as it says in their TOS/Privacy policy) and shares that info with whoever they want.
I also found out (and this is old info) that ANYONE can take money from your bank account without your permission. There might be repercussions for them later or maybe the bank has to trust them but I found this out because I signed up for Apple Pay and Apple Pay wants me to pay my bill via ACH.
https://en.wikipedia.org/wiki/Automated_clearing_house
What happened is I gave Apple my info (routing number and account number) and without the bank confirming with me that Apple had permission to take some money, Apple sucked money out of my bank account.
That's crazy to me. Those 2 numbers are on every check I've ever written.
I get that someone can charge money to me with my Credit Card info but AFAIK if it's fraud I'm only out max $50. Plus, it's not my money, it's the CCard company's money since it's effectively a loan and the fraud is their problem, not mine.
I'm sure someone with more knowledge can tell me why the ACH system is safe but I find it super scary ATM.
FWIW I think this is a slight misinterpretation of our privacy policy. The section on advertising basically just refers to our usage of cookies for advertising and analytics. Plaid does not share personal information without your explicit consent: https://plaid.com/how-we-handle-data/
You would imagine that with open banking I could write my own code to pay my bills, send out birthday gifts, or pay my employees...
I imagine I could enable a trusted third party to automatically switch my bank account from one that earns 0.1% interest to one that earns 1% interest... Or to detect that I was double billed for amazon prime and auto refund one. Or maybe it would let me create temporary bank accounts for a payment (so that I can't be overbilled).
Yet it turns out that it's not really more than a csv dump of your statement. It's read only, and has barely any more data than the pdf files available from the bank. Pretty much all you can do with it is draw pretty graphs that anyone could draw in excel in 5 minutes. Oh, and some evil companies demand to have access to your bank statement via openbanking to check if you are 'worthy' of a job/loan/school.
Open banking is meant to allow any third party to get your financial information if you agree, just like any app can implement social auth with Google/Twitter/GitHub.
But (pasting a comment I wrote here 2 years ago):
"By using Plaid or an Open Banking service from another party (e.g. Experian) you'll pay fees to get information you can get for free if you integrate directly with the banks.
Even though the open banking APIs are uniform, any company wishing to use them still has to register with each and every bank, and test the integration works with each one. Until you've done it once, it's hard to know whether it will be easy (you write the code once, and it works flawlessly for all banks) or you have edge cases (e.g. some banks have funny timeout issues). So if you're a developer on a deadline, you will likely prefer to use a single API."
It has a glass ceiling to it: the more popular it gets the more fraud there is going to be the less popular it is.
Thoughts on future settlement protocols: https://raw.githubusercontent.com/globalcitizen/ifex-protoco...
I'm planning to utilize the UK version to aggregate my transactions via a read only interface. That seems relatively safe & think I can wrangle the half a dozen accounts with python into some sort of coherent view.
Someone hacked together a bash version of it already:
Attackers will breach the weakest link. Right now there is only one link: your bank's website.
Most of these being done through screen scraping and by storing users bank credentials in some random 3rd parties database. Which is a huge and tempting target.
It’s gotten somewhat better in some cases now as they are at least using SSO type setups, so it’s a track able and expirable token instead of raw credentials at least some of the time - but yikes.
Without open banking APIs, these tools have to collect your authentication information and impersonate you on your banks' websites to collect your account balance information.
I would never go back to budgeting in Excel. Way too tedious.