logoalt Hacker News

robhltyesterday at 7:16 PM1 replyview on HN

Plaid requires your bank username and password, so they have full read-write access to your account. They can do anything you can do when logged in to the bank's website, and so can anyone else who gains access to Plaid's database.


Replies

lxgryesterday at 7:27 PM

> They can do anything you can do when logged in to the bank's website

Which is hopefully nothing beyond looking at transaction data without 2FA.

show 1 reply