The Consumer Financial Protection Bureau (CFPB) plans to propose a new open banking rule in 2023 requiring financial institutions to share consumer data upon consumers’ requests. Along with the new parameters come fresh opportunities for exploitation of data from bad actors — and financial institutions should remain aware of gaps in the rule that fraudsters could take advantage by implementing authentication processes to secure consumer data.
“The unknowns are unknown,” Seth Ruden, director of global advisory, Americas, at fintech BioCatch, tells Bank Automation News in this episode of “The Buzz” podcast.
“I have some concern that this could lead to an outcome where we may not necessarily have created controls in alignment with market needs,” he says.
Listen as Ruden discusses how financial institutions can best prepare their institutions for the new open banking rule.
Bank Automation Summit US 2023, taking place March 2-3 in Charlotte, is a crucial event on automation and automation technology in banking. Learn more and register for Bank Automation Summit US 2023.
Subscribe to The Buzz Podcast on iTunes, Spotify, Google podcasts, or download the episode.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Hello, and welcome to the bus, a bank automation news podcast. My name is Whitney McDonald and I’m the deputy editor of bank automation news. Joining me today is Seth Ruden Biocatch Director of Global Advisory in North America. He discusses the CFPB, his new open banking rule, and its potential unintended consequences.Seth Ruden 0:28
Okay, well, I think this new rule is intended to allow for third parties to create pathways on ramps to be able to acquire access to financial institutions, customers accounts, and allow them to create opportunities for those customers to bring their accounts from one institution to another. And to include the information that an individual has relative to accounts payable relative to automated payments, allowing them to automate more of their account migration from one institution to another, which essentially allows for consumers to have more choice and reduces the potential that they are reticent to migrate from one institution to another, because of the challenges and inherent complications of setting up new accounts and creating the relationships on the counterparty.Whitney McDonald 1:38
I think it’s also imperative that we talk through what risks come along with this new rule. Can you share a little bit about the unintended consequences that we’re seeing here?Seth Ruden 1:49
Well, yeah, you know, we’re not seeing anything. Yeah, I think that the problem is that we don’t know what we don’t know. It’s, it’s the unknown unknowns that tend to bite us. And people are going to create some interesting new products and new pathways for this information to be utilized. And they may do so with all of the best intentions. And those new pathways and services might help to facilitate the ease of of that migration. But it also might create potential opportunities for exploitation by bad actors, fraudsters have a unique and really unusually strong capacity for understanding how they can undermine exploits, or otherwise take advantage of financial services and the pathways that they occupy. And we are, you know, consistently seeing that aggregators have been undermined in this capacity for many years. I managed through a handful of events in my career, where an aggregator was the point of abuse and an aggregator was a area where a fraudster was able to acquire information about an account and leverage that information for performing fraud. And some of that had occurred within aggregators, acquiring account logs, you know, just information about deposits and account balances. And that allows the attacker to perform account takeover, compromise that data and link other accounts, you know, really take advantage of, of these services in ways that the developers of these technologies never anticipated. And so I think that’s really what I want to drive home as the potential opportunity of exploitation that exists here. I think it’s really important that financial aggregators recognize and realize that they’re building a trust model, and that that trust model can be exploited. And if an aggregator is providing easier access to a good or service by relaxing security controls, as in trusted ecosystem participants, then they have an opportunity for exploitation. And as a result of that, it’s important for them to be looking at the exposure that they’re bringing to the table. And if there’s good or service has abuse in it, then that trusted that trust model may be losing some of its advantage. And as a result of that. It’s important for that aggregator to be looking at creating the right kind of security controls and demonstrating that to market participant And, and maybe that’s an opportunity for them to put security as a competitive advantage ahead of just adoption, you know, we do need to be looking at the reliability of the service. Because if the service finds that it is introducing new risk to the counterparty, then that service has the potential for being declined as a trusted participant in that model. And I think that’s maybe one of the ways that we articulate to, to the market. This is the reason why you need to be focusing on controls, and not just adaption and looking at how their exploitation opportunities can be a core component of an effective business model.
Whitney McDonald 5:51
Now, I know that you just said, of course, you don’t necessarily know what those gaps are going to be, is there any way that banks can prepare themselves any way to avoid unknown gaps like that, or anything that they can do on the tech side to put something in place? And that
Seth Ruden 6:11
depends on who the developers are? And I think the real question is, if you are a developer, and you’re providing this kind of access to a third party, how are you developing the controls and rigor around understanding who the consumer claims they are? Right, I think that’s one of the areas that that we have some degree of confidence that we can be able to understand the areas of risk that we may be exposed to, historically have, have sometimes suggested this is sanitizing the point of entry, right? Putting a little bit of sunlight on the front door, understanding what the potential risk is. So one of the things that we don’t really do well, in the United States at this moment is identity, verification, it’s very difficult right now. And a good example of that, is that when we went through the pandemic, a lot of stimulus was generated, and the amount of stimulus that was stolen by that actors was at a record height, I don’t even want to share some of the figures that I’ve heard, because they’re just eye popping. Now, that said, it begs the question, Well, how did that happen? And I think the answer is, well, you know, we’ve had so many different merchant breaches, and so many different health care, compromises, and so many different areas where our personal information has been compromised. And as a result of that, there is enough information floating around about me and you and all of us, where we get A a warning from a major organization, telling us, you know, we’re very sorry, we’re going to offer you credit warnings and services, we’re going to, you know, tell you all of these things that happened. And we at this point, probably just neglect them. Right, and we don’t have a lot of time to put into, well, what’s the potential, you know, impact to me, and I’ll tell you what it is, unfortunately, identity theft now is, is peeking, you know, we’re seeing so much impact of identity theft at this moment, that it’s so common that you could just acquire enough information about somebody’s identity. And this would be, you know, public information, as well as nonpublic personal information, and be able to use that to apply for credit products, government safety net services, and the example of, of paycheck Protection Program, or unemployment insurance is that great example. And when you have this kind of thing that occurs here, this allows for bad actors to exploit that information, and use that to their advantage. So you know, knowledge based authentication, the ability for bad actors to leverage that information to exploit individuals is, you know, essentially at an all time high right now, and because we’re doing everything, and everybody has the expectation that we’re going to be doing everything remotely. Now we’ve got this abuse that occurs, and it’s scalable for bad actors. And I think that’s the area that we might have some concerns at this moment about the potential opportunity for exploitation here. And the other thing that I want to suggest is that some of the controls that we’ve been using lately multi factor authentication and relative to using SMS, or text messaging, as one of those areas has been heavily exploited by bad actors lately as well. And so if if that’s one of those primary controls, or they’re using email, which also has the ability for exploitation and abuse, via social engineering, via malware, you know, we start to see where our controls aren’t necessarily always up to the task. And I think those areas of identity abuse and, and, essentially, front door exposure is where we’ll see some opportunities for exploitation. And I’m not sure that as many institutions have an idea of what is necessary to begin to create those kinds of controls to remediate the abuse potential that exists there. So I think that’s where we’re going to see, if I’m looking at my crystal ball, that’s where we’re going to see most of the opportunity for bad actors to exploit this new, this new opportunity for acquiring data and acquiring services.
Whitney McDonald 11:20
Now, I know we’ve talked about the risks and preparing for that the best that you can, of course, without knowing exactly what those are going to entail, can we shift a little bit and talk about what those macroeconomic advantages of open banking might be?
Seth Ruden 11:35
We know that the push to open banking creates some efficiency gains, it can create opportunities where competition is making a better marketplace, creating better products and services for consumers. That may reduce prices for consumers, it may increase the speed that goods and services are acquired. And at scale, if entities are paid sooner, they can leverage the capital that’s available to them. economies can grow faster, they they’re pushed closer to, you know that that collegiate term that I love to use, which is their efficiency frontier. And that’s one of those examples where financial engineering can tangibly grow markets, you know that better products and services serve people in in new and interesting ways. And that can have the effect of reducing prices, speed up payments, distribution of of those goods and services, and create more efficient markets. And you know, that that’s the the economics one on one framework, I think something happened in Europe over the last few years. It was called a PSD to payment services directive, second iteration. And what this was, is an opportunity to create greater open banking opportunities within the UK that are I’m sorry, within the EU, I should say, which allowed for your least cost routing of of goods and services and payments and in association for those goods and services. So essentially, you would be able to make a payment to a payee via any mechanism you want it to, you weren’t limited to, you know, one channel specifically. And what was built into that was a very interesting framework for managing fraud and risk, which was secure customer authentication. And what it said was that if you were leveraging a specific platform and you had low fraud rates, then you would have low points of friction. However, if your fraud rate started to trickle up, then there would be some automatic capacity for greater friction to be initiated within the channel. And I think what’s really interesting about that, was that it automated so back to the automation question. It automated the controls, and the responsibility for engineering, those automations and those escalation of controls once a specific threshold was reached, but it also mandated additional fraud controls and additional authentication friction in areas where the Europeans understood that this would be an effective way to increase reliability within their framework. And I think that’s maybe one thing that might be concerning for me, relative to this rule is that I’m not confident yet that we have thought about all of those controls that are necessary, and that we’re going to be taking the existing framework of controls that we have here in this country and Saying that might be good enough. So there’s an opportunity for some market participants to comment on this and to give some insight into what those controls or, you know, rules should look like. And if the impetus of market participants is to make money at this, it’s unlikely that they’re going to put emphasis on on controls that could create additional friction, or create additional cost relative to implementing this rule. And I have some concerns that this could lead to a an outcome where we may not necessarily have created controls in alignment with market needs, and just suggested that what we have today is good enough. And, again, what I’ve seen in in my time is that there is still abuse within the system. And that existing controls may not be sufficient always to create the right kind of deterrence to bad actors. And that’s where I have some hesitation here and think that there might be a better approach leveraging the models that exist across the pond.
Whitney McDonald 16:26
You’ve been listening to the buzz, a bank automation news podcast, please follow us on Twitter and LinkedIn. And as a reminder, you can rate this podcast on your platform of choice. Thank you for your time, and be sure to visit us at Bank automation news.com For more automation news,
The Consumer Financial Protection Bureau (CFPB) plans to propose a new open banking rule in 2023 requiring financial institutions to share consumer data upon consumers’ requests. Along with the new parameters come fresh opportunities for exploitation of data from bad actors — and financial institutions should remain aware of gaps in the rule that fraudsters could take advantage by implementing authentication processes to secure consumer data.
“The unknowns are unknown,” Seth Ruden, director of global advisory, Americas, at fintech BioCatch, tells Bank Automation News in this episode of “The Buzz” podcast.
“I have some concern that this could lead to an outcome where we may not necessarily have created controls in alignment with market needs,” he says.
Listen as Ruden discusses how financial institutions can best prepare their institutions for the new open banking rule.
Bank Automation Summit US 2023, taking place March 2-3 in Charlotte, is a crucial event on automation and automation technology in banking. Learn more and register for Bank Automation Summit US 2023.
Subscribe to The Buzz Podcast on iTunes, Spotify, Google podcasts, or download the episode.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Hello, and welcome to the bus, a bank automation news podcast. My name is Whitney McDonald and I’m the deputy editor of bank automation news. Joining me today is Seth Ruden Biocatch Director of Global Advisory in North America. He discusses the CFPB, his new open banking rule, and its potential unintended consequences.Seth Ruden 0:28
Okay, well, I think this new rule is intended to allow for third parties to create pathways on ramps to be able to acquire access to financial institutions, customers accounts, and allow them to create opportunities for those customers to bring their accounts from one institution to another. And to include the information that an individual has relative to accounts payable relative to automated payments, allowing them to automate more of their account migration from one institution to another, which essentially allows for consumers to have more choice and reduces the potential that they are reticent to migrate from one institution to another, because of the challenges and inherent complications of setting up new accounts and creating the relationships on the counterparty.Whitney McDonald 1:38
I think it’s also imperative that we talk through what risks come along with this new rule. Can you share a little bit about the unintended consequences that we’re seeing here?Seth Ruden 1:49
Well, yeah, you know, we’re not seeing anything. Yeah, I think that the problem is that we don’t know what we don’t know. It’s, it’s the unknown unknowns that tend to bite us. And people are going to create some interesting new products and new pathways for this information to be utilized. And they may do so with all of the best intentions. And those new pathways and services might help to facilitate the ease of of that migration. But it also might create potential opportunities for exploitation by bad actors, fraudsters have a unique and really unusually strong capacity for understanding how they can undermine exploits, or otherwise take advantage of financial services and the pathways that they occupy. And we are, you know, consistently seeing that aggregators have been undermined in this capacity for many years. I managed through a handful of events in my career, where an aggregator was the point of abuse and an aggregator was a area where a fraudster was able to acquire information about an account and leverage that information for performing fraud. And some of that had occurred within aggregators, acquiring account logs, you know, just information about deposits and account balances. And that allows the attacker to perform account takeover, compromise that data and link other accounts, you know, really take advantage of, of these services in ways that the developers of these technologies never anticipated. And so I think that’s really what I want to drive home as the potential opportunity of exploitation that exists here. I think it’s really important that financial aggregators recognize and realize that they’re building a trust model, and that that trust model can be exploited. And if an aggregator is providing easier access to a good or service by relaxing security controls, as in trusted ecosystem participants, then they have an opportunity for exploitation. And as a result of that, it’s important for them to be looking at the exposure that they’re bringing to the table. And if there’s good or service has abuse in it, then that trusted that trust model may be losing some of its advantage. And as a result of that. It’s important for that aggregator to be looking at creating the right kind of security controls and demonstrating that to market participant And, and maybe that’s an opportunity for them to put security as a competitive advantage ahead of just adoption, you know, we do need to be looking at the reliability of the service. Because if the service finds that it is introducing new risk to the counterparty, then that service has the potential for being declined as a trusted participant in that model. And I think that’s maybe one of the ways that we articulate to, to the market. This is the reason why you need to be focusing on controls, and not just adaption and looking at how their exploitation opportunities can be a core component of an effective business model.
Whitney McDonald 5:51
Now, I know that you just said, of course, you don’t necessarily know what those gaps are going to be, is there any way that banks can prepare themselves any way to avoid unknown gaps like that, or anything that they can do on the tech side to put something in place? And that
Seth Ruden 6:11
depends on who the developers are? And I think the real question is, if you are a developer, and you’re providing this kind of access to a third party, how are you developing the controls and rigor around understanding who the consumer claims they are? Right, I think that’s one of the areas that that we have some degree of confidence that we can be able to understand the areas of risk that we may be exposed to, historically have, have sometimes suggested this is sanitizing the point of entry, right? Putting a little bit of sunlight on the front door, understanding what the potential risk is. So one of the things that we don’t really do well, in the United States at this moment is identity, verification, it’s very difficult right now. And a good example of that, is that when we went through the pandemic, a lot of stimulus was generated, and the amount of stimulus that was stolen by that actors was at a record height, I don’t even want to share some of the figures that I’ve heard, because they’re just eye popping. Now, that said, it begs the question, Well, how did that happen? And I think the answer is, well, you know, we’ve had so many different merchant breaches, and so many different health care, compromises, and so many different areas where our personal information has been compromised. And as a result of that, there is enough information floating around about me and you and all of us, where we get A a warning from a major organization, telling us, you know, we’re very sorry, we’re going to offer you credit warnings and services, we’re going to, you know, tell you all of these things that happened. And we at this point, probably just neglect them. Right, and we don’t have a lot of time to put into, well, what’s the potential, you know, impact to me, and I’ll tell you what it is, unfortunately, identity theft now is, is peeking, you know, we’re seeing so much impact of identity theft at this moment, that it’s so common that you could just acquire enough information about somebody’s identity. And this would be, you know, public information, as well as nonpublic personal information, and be able to use that to apply for credit products, government safety net services, and the example of, of paycheck Protection Program, or unemployment insurance is that great example. And when you have this kind of thing that occurs here, this allows for bad actors to exploit that information, and use that to their advantage. So you know, knowledge based authentication, the ability for bad actors to leverage that information to exploit individuals is, you know, essentially at an all time high right now, and because we’re doing everything, and everybody has the expectation that we’re going to be doing everything remotely. Now we’ve got this abuse that occurs, and it’s scalable for bad actors. And I think that’s the area that we might have some concerns at this moment about the potential opportunity for exploitation here. And the other thing that I want to suggest is that some of the controls that we’ve been using lately multi factor authentication and relative to using SMS, or text messaging, as one of those areas has been heavily exploited by bad actors lately as well. And so if if that’s one of those primary controls, or they’re using email, which also has the ability for exploitation and abuse, via social engineering, via malware, you know, we start to see where our controls aren’t necessarily always up to the task. And I think those areas of identity abuse and, and, essentially, front door exposure is where we’ll see some opportunities for exploitation. And I’m not sure that as many institutions have an idea of what is necessary to begin to create those kinds of controls to remediate the abuse potential that exists there. So I think that’s where we’re going to see, if I’m looking at my crystal ball, that’s where we’re going to see most of the opportunity for bad actors to exploit this new, this new opportunity for acquiring data and acquiring services.
Whitney McDonald 11:20
Now, I know we’ve talked about the risks and preparing for that the best that you can, of course, without knowing exactly what those are going to entail, can we shift a little bit and talk about what those macroeconomic advantages of open banking might be?
Seth Ruden 11:35
We know that the push to open banking creates some efficiency gains, it can create opportunities where competition is making a better marketplace, creating better products and services for consumers. That may reduce prices for consumers, it may increase the speed that goods and services are acquired. And at scale, if entities are paid sooner, they can leverage the capital that’s available to them. economies can grow faster, they they’re pushed closer to, you know that that collegiate term that I love to use, which is their efficiency frontier. And that’s one of those examples where financial engineering can tangibly grow markets, you know that better products and services serve people in in new and interesting ways. And that can have the effect of reducing prices, speed up payments, distribution of of those goods and services, and create more efficient markets. And you know, that that’s the the economics one on one framework, I think something happened in Europe over the last few years. It was called a PSD to payment services directive, second iteration. And what this was, is an opportunity to create greater open banking opportunities within the UK that are I’m sorry, within the EU, I should say, which allowed for your least cost routing of of goods and services and payments and in association for those goods and services. So essentially, you would be able to make a payment to a payee via any mechanism you want it to, you weren’t limited to, you know, one channel specifically. And what was built into that was a very interesting framework for managing fraud and risk, which was secure customer authentication. And what it said was that if you were leveraging a specific platform and you had low fraud rates, then you would have low points of friction. However, if your fraud rate started to trickle up, then there would be some automatic capacity for greater friction to be initiated within the channel. And I think what’s really interesting about that, was that it automated so back to the automation question. It automated the controls, and the responsibility for engineering, those automations and those escalation of controls once a specific threshold was reached, but it also mandated additional fraud controls and additional authentication friction in areas where the Europeans understood that this would be an effective way to increase reliability within their framework. And I think that’s maybe one thing that might be concerning for me, relative to this rule is that I’m not confident yet that we have thought about all of those controls that are necessary, and that we’re going to be taking the existing framework of controls that we have here in this country and Saying that might be good enough. So there’s an opportunity for some market participants to comment on this and to give some insight into what those controls or, you know, rules should look like. And if the impetus of market participants is to make money at this, it’s unlikely that they’re going to put emphasis on on controls that could create additional friction, or create additional cost relative to implementing this rule. And I have some concerns that this could lead to a an outcome where we may not necessarily have created controls in alignment with market needs, and just suggested that what we have today is good enough. And, again, what I’ve seen in in my time is that there is still abuse within the system. And that existing controls may not be sufficient always to create the right kind of deterrence to bad actors. And that’s where I have some hesitation here and think that there might be a better approach leveraging the models that exist across the pond.
Whitney McDonald 16:26
You’ve been listening to the buzz, a bank automation news podcast, please follow us on Twitter and LinkedIn. And as a reminder, you can rate this podcast on your platform of choice. Thank you for your time, and be sure to visit us at Bank automation news.com For more automation news,






