TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Fintech Firm Plaid Raises $44M

137 pointsby soroushjpalmost 9 years ago

13 comments

marco1almost 9 years ago
Note that there are <i>two</i> major security flaws in Plaid when it comes to authentication:<p>Since banks don&#x27;t provide secure mechanisms for third-party authentication and authorization, e.g. OAuth, Plaid receives you credentials in plain text and will then use them to communicate with the bank. So you really have to <i>trust</i> Plaid.<p>The second weakness is even more dangerous: Apps implementing the Plaid authentication flow will show the Plaid &quot;login page&quot; with bank selection in an overlay on their own sites. Since this is <i>not</i> a redirect again, you don&#x27;t even see whether your credentials are transferred to Plaid or the third-party app. That is, you have to trust your bank (sure!), Plaid (okay!) <i>and</i> the app using the auth flow (dangerous!).<p>You should fix this!
评论 #11942369 未加载
评论 #11942848 未加载
jc4palmost 9 years ago
This is really good news. Plaid has an amazing API, it makes it very easy to get your own financial data. I&#x27;m trying to analyze my own spending habits &#x2F; make a budget-allocator using my own patterns, so it&#x27;s been insanely helpful. My big fear with all small SaaS&#x27;s if they just suddenly shutter, so a new round of fundraising is always good news :)
评论 #11940022 未加载
评论 #11939933 未加载
Rainymoodalmost 9 years ago
I&#x27;m going to be really rude here (forgive me) but I feel like every time a security question comes up you dodge the question really hard.<p>I want to know one thing: If I log into your service with my bank credentials. Do you store these as plaintext files (or &quot;encrypted&quot; files of which you have the encryption key)? Yes&#x2F;No.<p>Furthermore, congratulations! I&#x27;ve been trying to start something up like this in Europe but I feel like there are way more restrictions in Europe on banking data and this kind of third-party aggregation. Sorry for being so rude.
icualmost 9 years ago
For those interested in a European perspective, the Revised Payment Services Directive (aka PSD2) will in a similar fashion to Plaid&#x27;s API, force banks to offer APIs for not only client information but payment. If implemented it will probably create radical change and opportunity in FinTech across the EU.
评论 #11939823 未加载
gwintrobalmost 9 years ago
Congrats Plaid! Opening up banking data via API is a great enabler for fintech startups to create valuable apps. I interviewed them a couple months back: <a href="https:&#x2F;&#x2F;medium.com&#x2F;get-put-post&#x2F;how-plaid-s-api-brings-finance-into-the-21st-century-efc174028f09#.si7lqyoik" rel="nofollow">https:&#x2F;&#x2F;medium.com&#x2F;get-put-post&#x2F;how-plaid-s-api-brings-finan...</a>
swansonalmost 9 years ago
Was just looking at Plaid this weekend, seems really slick. The only thing that gave me brief pause was no public pricing (or indication of order of magnitude).
评论 #11940765 未加载
tommynicholasalmost 9 years ago
Badass team and product - I don&#x27;t think people realize how difficult what they&#x27;re doing is. Super pumped for them!
评论 #11939393 未加载
tbrooksalmost 9 years ago
Played around with the API a little bit.<p>Cool discovery: if you search for a financial institution, they return logos as Base64.<p>Super rad.
findjashuaalmost 9 years ago
Seems like the auth flow doesn&#x27;t redirect to the bank&#x27;s website. Does that mean that my bank credentials are sent to Plaid?
评论 #11940232 未加载
评论 #11939739 未加载
meangreenalmost 9 years ago
Awesome news! Does anyone have a detailed and unbiased pros&#x2F;cons of Plaid vs. Yodlee - thinking about integrating with one for my startup. I think the one area I&#x27;m most interested to learn about is the data quality &#x2F; depth &#x2F; breadth - do they offer the same? Which one is better? Why?
评论 #11942112 未加载
评论 #11942134 未加载
wasdalmost 9 years ago
Hey Plaid, interested user here! I&#x27;m curious why you don&#x27;t have any pricing on your web page. I&#x27;m just trying to do a back of the envelope calculation on how much it would cost to use your service.
评论 #11940780 未加载
评论 #11940297 未加载
georgeglue1almost 9 years ago
Does Plaid have billing data? Ostensibly, that was the motivation for Intuit&#x27;s Check acquisition.<p>It&#x27;s also interesting that Intuit runs their own massive aggregation effort that they haven&#x27;t attempted to product-ize...
评论 #11942604 未加载
panlanaalmost 9 years ago
As a future consumer of your services, I&#x27;m excited to hear this, congrats!