Bank credential security gone bad

Опубликовано: 28 Март 2026
на канале: Kevin Giszewski
3,939
31

The FinTech industry is handling your user credentials and doesn't provide a true OAuth solution for the thousands of banks (in just the United States).

This video will show you how to get around having to provide your username and password to these 3rd party companies.

Just because they 'can' doesn't mean they 'should'. Please don't be duped by handing your credentials to the man in the middle.

Plaid appears to be a great service for vendors but extremely risky for the unsuspecting end-user.

Just to be clear here. If Plaid has any sort of relationship with the banks, then the user should be directed to a page that the bank controls. For example if a Chase user were to try to login, it take users to a foo.chase.com page. If Chase then wants to send anything to Plaid, it does so behind the scenes and assumes the liability.

Banks might look the other way on Plaid since it shifts liability to Plaid. Plaid can easily sell this product to companies like Coinbase because it does shim the slow-moving bank industry. However it does so at the risk of unsuspecting users providing credentials to a 3rd-party.

This means that 3rd party can store you personal banking information and you have no way to revoke it unless you change your password. Most users won't even know they've given this control to Plaid.

Plaid: https://plaid.com/legal/

Even Coinbase suggests you may want to change your password after using Plaid: https://support.coinbase.com/customer...