logoalt Hacker News

gavinsyanceyyesterday at 5:35 PM1 replyview on HN

The same info is also on checks, and there's an established story around fraud there -- if I didn't authorize an ACH withdrawal then my bank is legally required to make me whole. If I hand over my username+password to a third party, I'm on my own.

Also, the routing+account numbers just let them deposit/withdraw money, not snoop on all my transactions and harvest my data...


Replies

phoenixy1yesterday at 6:30 PM

This is a common belief, but the CFPB has stated your bank is still legally required to make you whole in the event of fraud even if you handed over your username and password to a third party, and that any bank TOS stating otherwise are not valid. This is covered on the CFPB Electronic Fund Transfers FAQ, under the Error Resolution: Unauthorized EFTs, Question 8: https://www.consumerfinance.gov/compliance/compliance-resour...

show 1 reply