This is totally and completely insane. If a site gets hacked and your money is stolen there's no way the bank is going to indemnify you when you willingly turned over your credentials to a third party.
Do they have to have all kinds of specialized fraud detection in place to prevent unknown IPs from transferring more than a certain dollar amount? It also just occurred to me that you probably can't have 2-factor enabled on your bank account.
This same procedure is used in the United States with startup darlings like Coinbase. No debit card or one-time-password required, please give your real bank account password.
I had heard good things about mint, and I liked the 'dashboard' screenshots and such. Then I looked at how it worked, particularly "provide your bank credentials" part.
It didn't take long to realize how incredibly dangerous that was, and leave.
Banks should provide API access for services like this because it mitigates significant security issues.
The second factor is the one time password. You get ~200 by snail mail and need one for each transaction. So you only give up control for one transfer. But yes, indeed, this is insane.
Generally, as the bank also tracks the rate at which your passwords get invalidated (by being used), they will automatically send you a new sheet when there are only ~20 remaining on your current sheet.
There isn't actually anything you can do with the login + password. Sure, you can look at the transactions, so I guess it's a privacy problem.
But any transaction or change usually requires generating a single use pin with your debit card and a small card reader. Some also use your mobile phone.
Some banks dont require a code at all for known contacts.
Some banks dont require a code at all for small amounts (under 50).
Some banks send you a plain SMS with a one-time-password.
Some banks send you an SMS with some additional information (receiver, amount) and a one-time-password.
Some banks ask for a one-time-password from a dongle.
Some banks ask for a one-time-password by entering a challenge code into your dongle and then the dongle generates the new one-time-password.
etc.
What I am trying to say is, there is no real standard. The best method I've come across so far is a device in which you insert your debit card, enter your pin, then scan a QR code on the computerscreen and the device will actually show you the receiving IBAN + amount. After pressing OK you get a challenge that you have to enter on the website.
Also in the Netherlands the banks have an API they can use called iDEAL which does the same as "SOFORT" but instead of having "SOFORT" log in to your account, your actual bank immediately transfers the funds and sends an OK to the vendor.
It makes me really angry that bank security isnt standardized and that good systems like iDEAL dont find international adoption. Luxembourg is trying to develope its own version of iDEAL e.g.
Do they have to have all kinds of specialized fraud detection in place to prevent unknown IPs from transferring more than a certain dollar amount? It also just occurred to me that you probably can't have 2-factor enabled on your bank account.