OAuth exists, Plaid should not.
Always use ACH.
OAuth exists, Plaid should not.
Always use ACH.
Credit card = your "password" is written on the card, and everyone thinks it's normal.
This is why scammers want people to buy gift cards or get banking details rather than just get them to hand over credit card numbers.
https://en.m.wikipedia.org/wiki/Strong_customer_authenticati...
Not only are there enormous protections with the mis-use of one's credit card, but the 'password'/card number is randomly generated and not used elsewhere.
A regular person is quite likely to reuse their favourite password for their bank login and therefore expose most of their other services when Plaid is inevitably hacked, or more likely, when someone pretends to be Plaid with typosquatting and the user has learned that giving passwords away is OK.
Not true. My mother got a free credit card that she never used and never even took out of her safe box, and a few weeks ago someone used that card to buy a Microsoft gift card. Luckily for her, she regularly checks the bank's statements.
I'm convinced there's a workaround to buy stuff using just the numbers, because that's how cards used to work a few decades ago.
I think it is the other way around, sorry.
The card number is visible in plain sight. The card number is reused everywhere. Merchant employees often have access to these numbers, and have reportedly used them illegally.
Yes, there are protections, but they often apply only after the fact, which can cause lots of problems, e.g. if you're traveling and reached your card limit. Also, not everyone checks their transactions at the end of the month, so many cases of fraud may go undetected.
Given modern security methods, credit card numbers are just plain silly, and yes, they may be even dangerous.
The number on your card is not a password to authorize payments - it is the account number to which merchants can send an invoice, but there's effectively no expectation that they'll receive the money if you don't agree to.
Granted, this gives Venmo a small amount of cash to theoretically make interest off-of, but to me it's worth not entangling it with the routing-numbers of any important accounts.
Many of the banks that own Zelle have it built into their banking apps, so if you use one of those you may have Zelle access without any extra credential entering.
The banks behind Zelle openly stated in Zelle's planning that one of the motivations behind it was liability shifting, away from the banks, on to consumers. Other benefits to the consumer are just to make the platform more appealing.