Security of account aggregators flawed

national-australia-bank/chief-executive/

9 February 2001
| By Jason |

Most account aggregators are offering a flawed product while they remain in the middle of the relationship between clients and service providers, according to eWise.com.au chief executive Alex Grinberg.

Grinberg says the placement of third parties in the process, who hold password information and collect the data for the clients, is a security flaw which can be exploited by those outside the relationship.

"If there is unauthorized access to the third party account aggregator from outside there is access to all the data of any clients held by the aggregator," Grinberg says.

eWise.com.au is also an account aggregator but Grinberg says the it does not hold any data on behalf of clients but rather, works as a conduit for information with all details held offsite.

"Anyone breaking into the eWise.com.au system will not find any useful data as there is nothing there in terms of user passwords or financial data. All account information needed to access account data is held on each client's own computer," Grinberg says.

These details are encrypted on the user's computer and are not seen by eWise.com.au at all, nor does it need access to them to provide service according to Grinberg.

Grinberg says account aggregation also breaches the terms of services of many financial institutions which prohibit the handing over of account information to a third party. As a result of this liability issues may arise with some banks actively seeking to bar account aggregation.

Other features of the eWise.com.au service include a bill scheduling, reminder and payment services as well as the ability to perform transactions with the customers' nominated institutions.

The service the only one to provide access to National Australia Bank and St George Bank accounts and is rebadged and in use by a number of third parties. Grinberg says discussions are under way with at least a dozen other financial services groups and online providers to further roll out the service.

Read more about:

AUTHOR

Recommended for you

sub-bgsidebar subscription

Never miss the latest news and developments in wealth management industry

MARKET INSIGHTS

So we are now underwriting criminal scams?...

4 months 3 weeks ago

Glad to see the back of you Steve. You made financial more expensive, not more affordable as you claim, and presided ...

4 months 3 weeks ago

Completely agree Peter. The definition of 'significant change is circumstances relevant to the scope of the advice' is s...

6 months 3 weeks ago

Commonwealth Bank has formally dropped to zero advisers following LGT Crestone’s acquisition of its advice arm – some six years on from the Hayne royal commission. ...

2 weeks 5 days ago

The FSCP has issued a written direction to an adviser who charged clients “extraordinary fees” for inappropriate and conflicted advice, as well as encouraged them to swit...

2 days 2 hours ago

ASIC has cancelled the AFSL of an advice firm associated with Shield and First Guardian collapses, and permanently banned its responsible manager. ...

1 week 5 days ago

TOP PERFORMING FUNDS

ACS FIXED INT - AUSTRALIA/GLOBAL BOND
Fund name
3y(%)pa
1
DomaCom DFS Mortgage
92.15 3 y p.a(%)
3