1 comments

  • ggm an hour ago

    Needs to be a LOT more overt about where your keys to your specific financial institution live, and what permissions you overtly and covertly gave them in this.

    Sure, the front-end promise is "read only" but can you explain how the back-end API to the fintech side enforces that? Where is the contract over this being RO in that side, not on the front side?

    I don't think all the money machines hand out "this is a read only token" automatically. So I worry the surface promise is papering over a risk.

    holding a hash means that .. what? I have to manage the actual tokens in my edge device and your route to the event is through me?