Authentive转发了
Do services like Plaid store your password when used to connect to your bank account? It’s nuanced so let’s break it down. Account connection providers like Plaid, Finicity, MX and many others started with screen scrapping to use your password and 2FA codes to login into your account and share your data with the app you used. Once connected to your account, they store your password to maintain continuous access, as explained in Plaid https://bit.ly/plaid-pwd and Stripe docs https://bit.ly/stripe-pwd. Although institutions have gradually made APIs available over OAuth, Plaid still relies on passwords for 80% of US institutions and 99% of Canadian institutions they support. So, if the institution you connected supports OAuth, your password is not shared or stored. But for the rest, these services still collect and store your password. To know which institutions are integrated with OAuth or not, I put together a dashboard for easy lookup. Check it out: https://bit.ly/plaid-insts The good news is that CFPB has proposed new regulations to accelerate the shift to open banking to move away from these risky data collection practices. The not so good news is that it will take years to fully materialize. https://bit.ly/cfpb-ob #OpenBanking #Privacy