Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You trust Dropbox. You could presumably trust Zapier.

That you don't isn't really an argument for them changing their practices.

For example Mint.com keeps your banking passwords in order to do offline-logins, but people still trust Mint not to steal their money.

If many people don't trust a startup, I think they likely need to change their presentation style and not their practices.



The difference is Dropbox specializes in files. They have years of practice designing their technology and organization to not spy on their users.

Zapler does not have as much practice so screw-ups are more likely.


Indeed. And it's not just about spying.

The Zapier people are probably decent and honest etc, however that's not the point. It introduces a new security threat and attack vectors unnecessarily

It violates the principle of needing just enough access, to perform a task.


IIRC Mint uses a read-only API run by Yodlee


To expand on that Mint never stores your account passwords. Yodlee does and provides the data back to Mint. Here are their security claims: http://www.yodlee.com/security.html

As one data point, my credit union specifically recognizes accesses to my account from Yodlee, due to my Mint usage.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: