Hacker News new | past | comments | ask | show | jobs | submit login

I expected the answer to always be "you have no money, I just took it all".



Through just your bank account number?!


In the US, all you need for an ACH transfer is the account number and bank's routing number (which is public info). If the transfer is unauthorized you should be able to get it reversed, but it's still pretty bad.


That is.... Absolutely ridiculous. Why is it like this?


It's a decades-old system originally built on the assumption of trusted participants. It still uses nightly batch jobs to process transfers. Various hacks have been applied to improve it (banks require you to demonstrate some level of trustworthiness before they give you access to make ACH transfers) but that can only do so much.


This is part of the reason why Donald Knuth stopped sending out his reward checks and instead sends a certificate from the fictional Bank of San Serriffe. People were posting pictures of their reward checks, because getting one is pretty cool, which resulted in his account number being published.


A bank account number is all you need to initiate an ACH transaction for any amount to any other account (in the US).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: