• 1 Post
  • 43 Comments
Joined 1 year ago
cake
Cake day: June 21st, 2023

help-circle


















  • I’ve known some guys that are working for one of those “Financial data brokers” like the one Mint uses.

    I thought that there was something fancy to actually link your bank account and whatever budgeting app you want to use, like some Oauth or API token…

    In reality, you basically give your (plaintext) credentials to this entity which then uses them to open a session with your bank and parse the webpage. If there was some MFA used it forwarded the request back to you and if there was some robot check blocking the connection, they would have employees take control of the session and do the physical clicking on the webpage…

    Not saying that all Fin data brokers work like that, but I can confirm that’s the way one of the major ones did work internally 4-5 years back .