Needs to be a LOT more overt about where your keys to your specific financial institution live, and what permissions you overtly and covertly gave them in this.
Sure, the front-end promise is "read only" but can you explain how the back-end API to the fintech side enforces that? Where is the contract over this being RO in that side, not on the front side?
I don't think all the money machines hand out "this is a read only token" automatically. So I worry the surface promise is papering over a risk.
holding a hash means that .. what? I have to manage the actual tokens in my edge device and your route to the event is through me?
ggm•27m ago
Sure, the front-end promise is "read only" but can you explain how the back-end API to the fintech side enforces that? Where is the contract over this being RO in that side, not on the front side?
I don't think all the money machines hand out "this is a read only token" automatically. So I worry the surface promise is papering over a risk.
holding a hash means that .. what? I have to manage the actual tokens in my edge device and your route to the event is through me?