TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Plaid paid people $500 for their employer payroll logins

92 点作者 tony101大约 4 年前

10 条评论

KingMachiavelli大约 4 年前
&gt; <a href="https:&#x2F;&#x2F;www.eff.org&#x2F;cases&#x2F;facebook-v-power-ventures" rel="nofollow">https:&#x2F;&#x2F;www.eff.org&#x2F;cases&#x2F;facebook-v-power-ventures</a><p>While it is bad and unethical to encourage sharing credentials, I really hope we don&#x27;t <i>continue</i> to criminalize intermediary services that act on the user&#x27;s behalf. User&#x27;s should be able to use whatever product and services they want. If you don&#x27;t want consumer&#x27;s to use third party tools then either improve your own tools or implement better security.<p>On the bright side it sounds like in the Power Venture&#x27;s case they did a few other things to sort of &#x27;impersonate&#x27; Facebook in order to encourage user&#x27;s to use their product. So maybe things haven&#x27;t escalated too far yet... the outcome of this &amp; Plaid will certainly be interesting.
评论 #27127175 未加载
评论 #27128198 未加载
评论 #27127240 未加载
评论 #27127014 未加载
tehwebguy大约 4 年前
On the consumer side I can’t imagine ever giving my bank credentials to Plaid or any other company. Super unnerving that this is even a thing, it’s like the number one rule of passwords.
评论 #27126821 未加载
评论 #27126786 未加载
评论 #27126911 未加载
评论 #27126733 未加载
评论 #27127235 未加载
dzdt大约 4 年前
So this sounds like Plaid wanted to learn how to interface with the client-facing web interface of these payroll systems. So it paid people who have their own payroll on the system for access to that individual&#x27;s login to study the user interface in order to develop a system that can interoperate with it. This sounds... not so bad?
评论 #27126679 未加载
评论 #27126606 未加载
smnrchrds大约 4 年前
I thought duping customers [0] to think they were entering their credentials at their bank website while they were giving them to Plaid was bad. But this is some next level malice. How are they still in business?<p>[0] <a href="https:&#x2F;&#x2F;www.ctvnews.ca&#x2F;business&#x2F;td-bank-files-lawsuit-against-plaid-accusing-it-of-trying-to-dupe-consumers-1.5145326" rel="nofollow">https:&#x2F;&#x2F;www.ctvnews.ca&#x2F;business&#x2F;td-bank-files-lawsuit-agains...</a>
评论 #27126844 未加载
评论 #27126492 未加载
yonran大约 4 年前
I bet many banks have similar language prohibiting sharing logins, so you could make the argument that the core business of Plaid could be considered hacking under CFAA. I hope that the legitimate use of tools to do things on the Internet will be normalized before this argument is tried in court.
评论 #27126478 未加载
评论 #27127312 未加载
hahaxdxd123大约 4 年前
The fact that Plaid even exists, and that their core business will probably continue to thrive for another decade makes me almost certain that the US will lose its stranglehold on innovation soon.<p>In the US, I have to pass through so many rent seekers to move some digits over (Plaid, Stripe, and Visa&#x2F;MasterCard). Meanwhile Europe has PSD2 now and China AliPay&#x2F;WeChat Pay. Even India, which in the past 3 months has unfortunately proven dysfunctional has UPI, which is orders of magnitude better than what we have.<p>When has the US recently passed legislation or standards that fosters innovation? (this is a serious good faith question - there seems to be a lot of govt grants for stuff like basic research, but a whiff of money churns out stuff like repealing net neutrality).
评论 #27126720 未加载
评论 #27127425 未加载
评论 #27126952 未加载
评论 #27126973 未加载
评论 #27129327 未加载
评论 #27127540 未加载
评论 #27127005 未加载
评论 #27127676 未加载
评论 #27126817 未加载
评论 #27126968 未加载
评论 #27126803 未加载
helsinkiandrew大约 4 年前
It&#x27;s hard to differentiate Plaids behaviour in getting user account details from those used by Amazon Refund Scams [1].<p>Their motive may be different but their actions just help make this sort of behaviour on the vulnerable (ie. non technically&#x2F;security literate) easier to repeat by the more unscrupulous.<p>[1] <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=le71yVPh4uk" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=le71yVPh4uk</a>
beervirus大约 4 年前
But people are fine with giving Plaid their bank credentials for some reason.
eloff大约 4 年前
&gt; this was part of a pilot program to build &quot;consumer-permissioned tools that make it easier for consumers to securely share their information digitally.&quot;<p>What a useless statement. That could mean anything.
nly大约 4 年前
Probably why my employers payroll system is only available internally &#x2F; via a VPN