TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Plaid settled $58M lawsuit over alleged consumer data sharing

256 点作者 exotree将近 4 年前

21 条评论

akarma将近 4 年前
I actually mentioned in a thread about Plaid in 2018 that they sold transaction history to third parties, and the cofounder came onto HN to explicitly deny that [1]. I actually felt convinced they didn&#x27;t afterwards, as I couldn&#x27;t imagine such a direct and clear refutation if it were true.<p>[1] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=18655417" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=18655417</a>
评论 #28201649 未加载
评论 #28201314 未加载
评论 #28201342 未加载
评论 #28201449 未加载
评论 #28201388 未加载
评论 #28201597 未加载
ve55将近 4 年前
It is particularly sad how common scenarios this are for users, especially in the US. I have known how terrible applications like Plaid (and alternatives) were, but at various points have been required to use them to do something like pay my rent (this is also a very common theme in my life: I strongly dislike a certain company or app, but find myself required to use them regardless, even knowing that my usage and information will be abused).<p>Giving my full credentials <i>and my security question answer</i> in plaintext to a third party in order to &#x27;link my bank accounts&#x27;, and then having them scrape every bit of information they can from my personal banking statements and sell it is... nothing short of a nightmare scenario, from many standpoints (user security, user privacy, user education, anti-phishing, and so on).<p>I guess it&#x27;s nice to see this class-action lawsuit, but that it amounts to an average of $0.60 per affected user is, well, not particularly inspiring with respect to my hope that things will ever get better here.<p>Plaid is used by many industry leaders including Venmo, Robinhood, and Coinbase. When it&#x27;s not used, usually a similar alternative is. Perhaps the most frustrating part of this is that placing blame on these companies is difficult, as there&#x27;s no interoperability or open banking APIs that can be used as an alternative.
评论 #28200796 未加载
评论 #28200803 未加载
评论 #28202420 未加载
评论 #28202180 未加载
评论 #28201404 未加载
评论 #28201037 未加载
评论 #28204688 未加载
a-priori将近 4 年前
I just read the settlement document, and it looks like this is being reported incorrectly or at least ambiguously.<p>The allegation is NOT that they shared&#x2F;sold data to any third parties but that their Plaid Link user interface, where people enter their banking information to add it to Plaid, looks like the customer&#x27;s financial institution (i.e, uses the bank&#x27;s branding colours and logo).<p>Because of this branding, people can reasonably assume that they are sending that data directly to their bank without knowledge, and therefore consent, to share their information with Plaid itself.<p>If that understanding is correct then this isn&#x27;t a business practice or security issue, but a user consent issue. That&#x27;s a problem that definitely needs to be fixed, and the injunctive relief requires them to change the branding and disclosure to make it clearer that people are interacting with Plaid rather than their bank.<p>But to me it&#x27;s definitely not a reason to cancel your account or boycott Plaid or whatever.<p><a href="https:&#x2F;&#x2F;newmedialaw.proskauer.com&#x2F;wp-content&#x2F;uploads&#x2F;sites&#x2F;22&#x2F;2021&#x2F;08&#x2F;Plaid-Memorandum-of-Points-for-Prelimary-Settlement.pdf" rel="nofollow">https:&#x2F;&#x2F;newmedialaw.proskauer.com&#x2F;wp-content&#x2F;uploads&#x2F;sites&#x2F;2...</a>
评论 #28203140 未加载
评论 #28201934 未加载
cmer将近 4 年前
It is absolutely crazy that in 2021, banks still don&#x27;t have proper secure APIs for other software to interface with. Plaid is a major disaster waiting to happen.<p>Are there any banks moving in that direction? I know of exactly zero in Canada.
评论 #28200789 未加载
评论 #28200797 未加载
评论 #28200837 未加载
评论 #28329680 未加载
评论 #28200814 未加载
评论 #28203564 未加载
评论 #28200922 未加载
bananapub将近 4 年前
it&#x27;s so frustrating that this sort of shit keeps happening.<p>1. banks create gap in market by not providing useful access to their customer&#x27;s data by...their customers<p>2. regulators don&#x27;t step in to fix this market failure<p>3. some company steps in! yay!<p>4. company decides that charging customers for providing a good and&#x2F;or service is insufficient, they need to do something creepy with selling off the customers data<p>5. lawsuit after the fact to maybe stop them being dickheads and definitely enriching a lot of lawyers<p>why hasn&#x27;t the FTC or something stepped in to make banks provide some secure read-only access?
评论 #28200980 未加载
prepend将近 4 年前
Plaids terms are really concerning to me as a user and I’m not willing to give them my bank credentials. My main fear is that they get hacked and my credentials are used to drain my accounts. Plaid waives any liability and my bank doesn’t do much if my credentials are used to do stuff like initiate wire transfers.<p>Venmo is doing this weird thing where for some transactions they are saying they require plaid to get my bank credentials to log in and “verify.” Of course that breaks my first issue. But it also allows them to suck up and use all of my bank transactions forever.<p>Seems like a shitty tradeoff just to Venmo money to people.
评论 #28200741 未加载
评论 #28200939 未加载
w4llstr33t将近 4 年前
I think companies should still provide a way to link accounts via small deposits. It takes a few days, but at least you don&#x27;t have to share your credentials. (This applies to US accounts, maybe there are better solutions elsewhere.)<p>If you use Plaid, I think it should only be if there&#x27;s no other option and you change your credentials after. I&#x27;ve always thought giving away your credentials to a screen scraping company like Plaid was crazy.<p>In terms of the class action lawsuit, the only one who will see a meaningful payout from this are the lawyers.
评论 #28200820 未加载
评论 #28201292 未加载
paws将近 4 年前
I recently received a helpful reply about liability from an HN user who says they&#x27;re a Plaid employee. Thanks @phoenixy!<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=27982516" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=27982516</a><p>While I&#x27;m still trying to understand the bigger picture implications, maybe you will find this helpful too.
tehwebguy将近 4 年前
I say this basically every time it comes up but I cannot imagine handing my bank login + password over to Plaid or pretty much any third party ever for pretty much any reason.
评论 #28201474 未加载
walrus01将近 4 年前
The &quot;Current&quot; online-only bank insists on using Plaid if you want to transfer money from an existing account to Current. No thanks.<p><a href="https:&#x2F;&#x2F;www.google.com&#x2F;search?client=firefox-b-1-d&amp;q=current+online+bank" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;search?client=firefox-b-1-d&amp;q=current...</a><p>Also apparently if you want to use Plaid with many different online banking portals, you need to permanently disable 2FA, also no thanks.
评论 #28203407 未加载
meowtimemania将近 4 年前
I’ve used Plaid to login to my bank account. How do I delete all my data from Plaid??
评论 #28201826 未加载
评论 #28201679 未加载
评论 #28201857 未加载
dmitrygr将近 4 年前
Can we, for a moment, talk about how evil the very concept of Plaid is? We are literally <i>TRAINING</i> people to turn <i>OFF</i> 2FA on their bank accounts and give someone else their passwords! Yes, you read that right!<p>And then we wonder why phishing works so well, and why 2FA is not widely used...<p>I already advised everyone I know against Plaid, and am working with my bank&#x27;s local branch to disable any and all access from their IPs, and force anyone whose passwords have been compromised (make no mistake, giving your password away is a compromise) to change their passwords and enable 2FA.
fasteddie将近 4 年前
I&#x27;m a bit confused reading this. Is the lawsuit that users signing up for e.g. Venmo didn&#x27;t know that they were also giving their transaction history&#x2F;whatever to Venmo, or that Plaid was then taking the data passed to Venmo and reselling to, I don&#x27;t know, a hedge fund?<p>If it&#x27;s the former -- I certainly think services need to clearly state what&#x2F;why&#x2F;how they are using the data, but it&#x27;s on the services (like Venmo) and not Plaid.
xyst将近 4 年前
Personally, services that ask for your bank account credentials are a “no go” for me. The passwords themselves are likely stored securely, but the fact they are stored at all is concerning.<p>All it takes is a bad actor within the company to re-write the screen scraping to then impersonate the users and have them wire out money to a foreign bank account. Some anti-fraud systems might catch this activity but for people that use the wire system on a frequent basis it might go unnoticed.<p>Or they may screen scrape the information and sell it on the black market. Wouldn’t be too hard to target a specific group (elderly, retired) since you already have their bank credentials which subsequently has reliable&#x2F;verified demographic information and account balances.
echopom将近 4 年前
&gt; If all 98 million people were to file a claim, each would receive just 60 cents.<p>Thank you court of California to incentive startups and GAFA to use our data knowing their risk nothing.<p>Just to be clear , Plaid has raised 600+ Millions in it&#x27;s lifetime , this is nothing for them.
tommoor将近 4 年前
Top tip: If you don&#x27;t want to give Plaid your banking credentials and all of your purchase history (you really shouldn&#x27;t, irregardless of this lawsuit), just search for jibberish in the &quot;search for bank&quot; option in any app that implements Plaid to get the option to &quot;link manually&quot;…
root_axis将近 4 年前
The bottom line is that users aren&#x27;t aware that they&#x27;re giving up 6 months of past and future transaction history to the Plaid integrator when they login using Plaid. This is obviously deceptive.
jqpabc123将近 4 年前
Just don&#x27;t ever give your banking login credentials to anyone ... ever. Just don&#x27;t do it. You knew it was a bad idea when you did it --- so don&#x27;t repeat the mistake for any reason.
hamburgerwah将近 4 年前
Modern business in the US: 1) Make big profit doing bad thing that harms consumers 2) Pay fine for doing bad thing that is 10% or less of the ill-gotten profit 3) Repeat
zaptheimpaler将近 4 年前
98M customer accounts for $58M so 60c a piece. Sounds like they got a great bargain! Justice is served!
vmception将近 4 年前
The worst thing about Plaid is the alternatives to Plaid that I&#x27;ve never heard of<p>There is no secure way to &quot;connect your bank account&quot; in an app. No matter how fancy it looks, or what logo they put up, you are really just giving your username and password to a random person. A random person who may or may not be malicious, but is absolutely a giant target for malicious people.<p>As for the rebuttals, be nice if there was a way for users to to verify.