Monzo Labs: Connected Credit Cards

New Observation

I’m not sure what’s going on in the background but the app is now reporting 14 hours since the last balance update which implies that 2 of the 6 hourly updates may have been missed. (Note: I haven’t spent anything on the card since Friday so I can’t tell if the balance is stale or just the timer.)

3 Likes

Hey all - small update . We found an issue in our scheduler that has resulted in some people’s cards being disconnected from Monzo. This won’t have any impact on your Barclaycard account itself, but will mean you’ll need to reconnect your card again.

Sorry for the inconvenience caused!

4 Likes

We are working our way through all the bugs and issues causing this sort of thing to happen and we’ll make sure its as solid as possible before we take it out of labs. Thanks for your patience!

5 Likes

This has removed it for me also.

I disabled and reenabled it in labs and re set up my account and still not showing? :thinking:

Also force closed the app

EDIT: now showing after a delay of around 10 minutes :blush:, maybe you could do a notification or feed item to alert people there might be a delay like this?

In other news, here’s an update on what we’re working on next, based on your feedback:

  • We’re going to test connections with other credit card providers internally with Staff, to see how consistently they behave compared to Barclaycard. We want to make sure all works as intended before enabling more providers for public testers.

  • We’re going to try and make the post-connection flow smoother. Right now it’s not clear immediately after you connect that things have worked and that it’ll take a few minutes for your card to appear. People are force-closing the app to try and make their card appear. You shouldn’t need to do that.

  • We’re going to build and test a basic shortcut to send payments to your credit card provider, to pay off some of your balance.

26 Likes

Nationwide? :pray: :grin:

2 Likes

I feel a poll coming on…

3 Likes

Excellent - thanks for building this - it’s exactly why I like monzo.

2 Likes

Awesome :+1: Really, really looking forward to seeing it for Amex! Wish you guys had a alpha lab so I could try all the buggy stuff out :stuck_out_tongue:

6 Likes

AMEX & Tandem - Think a lot of people run this combo for cashback :pray:

5 Likes

Sorry if already mentioned, but it would be great to see my APR and active offers on these linked credit cards. If that’s not something that can be pulled then I’d like to be able to add it manually (if I had a spreadsheet of all my credit cards this would be the most important information to include). I can then decide which card to use or pay off.

Having this information within Monzo also opens up the window for card providers to use your data (with opt in, obvs) to offer you a better deal and give Monzo a partnership revenue stream.

10 Likes

This really concerns me too. I think the statement that you’re granting them read-only access is very misleading. You’re granting them complete access to your account but they’re promising only to read data from it.

It’s also incredibly poor security practice to ask for and to store customer banking credentials. As there’s no API access to BarclayCard, TrueLayer must be storing (in plaintext or reversibly encrypted form) your password and other authentication data. No-one should be storing this sort of data, regardless how secure they promise their systems are. I’m sure that none of the sites on this list of data breaches https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/ thought they would be hacked either (including Equifax, who’s main purpose was to securely hold (and sell) data about individuals - they lost 143,000,000 customer records).

(Anyone with a software engineering or security background will also know that even your bank should only be storing hashed and salted version of your credentials and should never be able to transform what they’ve stored back into plaintext).

It’s also teaching end-users really poor security practice - it’s telling them that it’s OK to share their banking credentials. We should be doing the exact opposite and telling them to NEVER give out their login details (for banking or any other service).

Facebook have just been through the wringer for asking users to share their email passwords in order to validate their address. After the backlash today, they’ve cancelled that experiment and admitted it was a bad idea (see discussion at https://news.ycombinator.com/item?id=19559617).

And just as concerning is that we’re handing our data across to a third party, who’s terms and conditions are subject to change. When was the last time most users read a “We’ve updated your terms” email in full? I’m just as concerned about my transaction data being monetised as I am about sharing my credentials.

I think this is a really bad idea and flies in the face of security best practice (which is so important when it comes to financial services).

2 Likes

I agree open banking would be better as presumably it’ll involve exchanging revokable tokens instead of storing credentials. I imagine this is the long term plan for this sort of feature and they have chosen truelayer as a stopgap - see the comment from Jami above about APIs.

2 Likes

5 Likes

Anyone else’s Barclaycard disappeared from Monzo? Mine’s legged it.

1 Like

From a purest perspective, and in principle, I would probably agree.

My understanding, and I’m willing to be corrected here, though is that screen scraping is allowed under current regulations. But it looks like it will become forbidden soon, with a mandatory migration to open banking APIs:

The play for companies like Truelayer will be to make the migration seamless, and to have one endpoint that aggregates all the others, I imagine.

As you say, the benefit for the user is greater security.

For the meantime, I think it’s fair that users proceed according to their own risk appetite (and knowing that Monzo and Truelayer will both have conducted their own due diligence).

2 Likes

Some people reported it and it has now been fixed:

2 Likes

Ah cheers. I didn’t scroll up far enough to see if anyone else had trouble.

1 Like

@hdwrng Bro. I just want to say I love your Hawkguy avatar, Bro.

1 Like

If only if was fixed :disappointed: disappeared for the third time this week sometime this afternoon :man_shrugging:t2:

Some feedback for monzo though - even if it does disconnect, it shouldn’t just “vanish” without a trace silently. It stores credentials, I have no idea if I now need to clear/change/reset them - or if doing that will cause this service to then lock my barclaycard logon out trying with the old password. Really needs an in-app banner/notification email (like ifttt does with a connected service) and retain the last data it did pull down and display the card as offline to let me delete/reconnect it.