It seems incredibly foolish to give this information to ANYONE over the internet. Why should I trust Datacoop with it? That's not a rhetorical question.
It seems incredibly foolish to give this information to ANYONE over the internet. Why should I trust Datacoop with it? That's not a rhetorical question.
My bank tries to drill it into me that I should NEVER, EVER give my password to any third party, including employees of the bank. This behaviour from Datacoup certainly seems like a big red flag to me.
They do say this, though:
"Datacoup neither sees nor stores any bank or credit card user login information such as username or password. The communication to the bank is hashed and the access point is tokenized, which means we cannot decipher a password even if we wanted to. Datacoup never sees nor stores account or routing numbers."
(http://datacoup.com/docs#security)
Did they redirect you first to a secure web page from the bank, and is it this page which asked for the credentials? If what they say above is true, then (I think) this is the only way in which this should happen.
I don't make any purchases with my debit card, so I would only link my credit card, which has pretty solid fraud protection. I'd probably be more way about cash accounts.
This space of personal data monetization is a huge trust exercise. The relationship has be developed with the user, almost at an individual level, for them to share their data from across platforms. Many of us are more willing to part, based on the knowledge that it's already happening and we should take part if we want something in return. While others are more hesitant and need to see the value (or other's adopting) before jumping in. And there are many others who it doesn't speak to at all - this includes folks who go out of their way to never post a photo of them online. To each their own :)
The path is evolving though, where users will have more control and gain an increasing amount of value from their data. But it's a longer term game - because the trust needed to get to the intimate information about users takes time to develop but is priceless once it's there.
Disclaimer: I am the co-founder of Powr of You (www.powrofyou.com), startup in the same space.
What DOES concern me as that the whole purpose of this service is to correlate data about you that is otherwise behind locked doors and explicitly keeping identity information intact. The services profit from your data and it's sale would far far out way any individuals.
I doubt if Datacoup would drain your accounts. More like a bad actor breaking into Datacoup's DB would drain your accounts.
By giving credentials AND cc numbers to a 3rd party (something credit card issuers say never to do), I'm in-effect condoning any actions that happen even if I don't make those actions.
Isn't it like handing the CC issuer a signed letter stating they need not worry about fraud protection, as I'm authorizing all transactions and will agree to cover them?
From an attack angle, now I have to trust that Datacoup will remain secure in all its interactions and that they will never suffer intrusions or decide to change their stance in the future (acquisition?).
I see nothing good coming of this request.