Sophos News

Barclays mulls letting customers check balances via Facebook

How safe do you feel when dealing with money online, whether that’s checking your balance, settling bills via your bank’s online platforms, going on a spree at Amazon or paying up on a parking fine?

How would you feel about using Facebook to do those things?

Because that’s one of the things that an EU directive passed a year ago has cleared the way for, and it’s what Barclays, one of the world’s biggest banks, is thinking of doing.

Speaking at a database conference in London this week – MongoDB Europe – Bala Chandrasekaran, Barclays’ director of data optimization and simplification, explained how moving to a NoSQL database has relieved the pressure on the bank’s mainframe infrastructure, which has on occasion failed.

The bank has created an operational data store (ODS) based on MongoDB’s NoSQL database, which sits between services such as online banking and the mainframe.  This creates a snapshot of data such as account balances and transaction history, which, it turns out, are the bulk of queries made by customers.

Moving to MongoDB means not only less strain on the mainframe, but also the ability to serve snapshots of transactions and balances to whichever channel the customer prefers – which could include third-party platforms such as Facebook, he said.

According to a writeup of the news in Diginomica, the EU PSD2 directive, passed a year ago, is opening the way for third-party platforms like Facebook to step in and do tasks such as present us with our bank balances.

Chandrasekaran explained:

Simply put … you just go to Facebook and say show me my balances, it brings up the data and shows you. [We would be] opening up the bank’s data and expose it out. Which means, it’s no longer people logging into our channels to ask for the data. It’s going to be people logging into something else, which is requesting the data.

His team is offloading processes out of the mainframe now, seeking to have the MongoDB switch from pressure-relief valve to instead handling the heavy burden of transactions. That could happen by the second quarter of 2017, he said.

Is it mad to trust a platform such as Facebook with more than read-only financial interactions with banks? Or even with something like your account balance, which might be tasty fodder for advertisers to gobble up and target-market you with?

I’ve asked Facebook how it might intend to use financial information for marketing purposes, if at all, and will update the story if I hear back.

From a security perspective, it might not be mad at all. True, we’ve seen bank accounts drained by online crooks, like the recent e-bank robbery of Tesco Bank.

But however you feel about Facebook, the company’s damn good at keeping the hackers at bay.

Beyond security, a possible move by Barclays to offer banking services via Facebook raises interesting questions about compliance with banking regulations. But the fact of the matter is that with the new PSD2 directive, the European Parliament has green-lit exactly this type of innovation, specifically as a means of improving the security of online payments.

These are some of the other changes the new rules introduce:

At any rate, this won’t be Facebook’s first push into the financial services space. It’s made moves that suggest it wouldn’t mind replacing PayPal or competing with its payment services brethren, such as Google Wallet.

Three years ago, Facebook was testing an “Autofill with Facebook” feature to autofill credit card information.

And in 2014, Facebook was rumored to be moving to establish migrant remittance services.

What do you think: will you trust Facebook with your bank balance? Or to conduct financial transactions, if that’s in the offing?

Let us know what you think in the comments section below.