Personal Finance

Accessing RBC bank account with Siri

  • Last Updated:
  • Mar 18th, 2020 11:55 am
[OP]
Deal Addict
Mar 10, 2010
1286 posts
285 upvotes

Accessing RBC bank account with Siri

I've heard this in the radio quite a bit recently where RBC is advertising *free* airpods when you open certain accounts. In their commercial they have a person asking Siri what their bank balance is and getting it over their earphones. I know I'm a bit of a dinosaur, but the idea of giving a 3rd party system access to my banking accounts seems asinine at best. Has anybody else heard these commercials? Wouldn't this violate TOS's about giving account access away?
5 replies
Deal Addict
Jan 2, 2015
1480 posts
485 upvotes
Toronto, ON
Unfortunately people just don't think about these things anymore.

There are people putting cameras in their homes, with video recorded in the cloud, and they just hope noone hacks their account. Are they using a password generator? Is it controlled by their smartphone?
Deal Fanatic
Nov 24, 2013
6059 posts
2794 upvotes
Kingston, ON
It’s not perfect for privacy but Apple is better than most (they’re not selling your data for marketing, for example). Here’s some info on the nature of the data Siri transmits to Apple:

https://www.apple.com/ca/newsroom/2019/ ... otections/

“ If you ask Siri to read your unread messages, Siri simply instructs your device to read aloud your unread messages. The contents of your messages aren’t transmitted to Siri’s servers, because that isn’t necessary to fulfill your request.
Siri uses a random identifier — a long string of letters and numbers associated with a single device — to keep track of data while it’s being processed, rather than tying it to your identity through your Apple ID or phone number — a process that we believe is unique among the digital assistants in use today. For further protection, after six months, the device’s data is disassociated from the random identifier.”

Basically your Apple phone is already accessing the information from RBC. RBC’s authenticated it’s you because you’ve transmitted them a password from a known device from a non-suspicious IP address. Your phone knows it’s you because you showed it your face, used your voice, or keyed in your passcode. Siri is just reading out info that’s already accessed on the phone, and at no point should that go to Apple.

I probably explained something wrong but hopefully someone in the tech field can explain better.
[OP]
Deal Addict
Mar 10, 2010
1286 posts
285 upvotes
But everything you've said here means that you've now granted access to your bank account to a 3rd party, which to my reading violates the banks TOS about keeping account confidentiality, so your bank wouldn't be liable for any fraud on your account. It would also mean that when (it's not an if) a third party is able to gain control of Siri on your device that they'd have full access to your bank account (or whatever you had authorized Siri to access). To me that too big of a risk for no discernible benefit. But again I'm a dinosaur when it comes to keeping my finances secure when possible.
Mike15 wrote: It’s not perfect for privacy but Apple is better than most (they’re not selling your data for marketing, for example). Here’s some info on the nature of the data Siri transmits to Apple:

https://www.apple.com/ca/newsroom/2019/ ... otections/

“ If you ask Siri to read your unread messages, Siri simply instructs your device to read aloud your unread messages. The contents of your messages aren’t transmitted to Siri’s servers, because that isn’t necessary to fulfill your request.
Siri uses a random identifier — a long string of letters and numbers associated with a single device — to keep track of data while it’s being processed, rather than tying it to your identity through your Apple ID or phone number — a process that we believe is unique among the digital assistants in use today. For further protection, after six months, the device’s data is disassociated from the random identifier.”

Basically your Apple phone is already accessing the information from RBC. RBC’s authenticated it’s you because you’ve transmitted them a password from a known device from a non-suspicious IP address. Your phone knows it’s you because you showed it your face, used your voice, or keyed in your passcode. Siri is just reading out info that’s already accessed on the phone, and at no point should that go to Apple.

I probably explained something wrong but hopefully someone in the tech field can explain better.
Deal Fanatic
Nov 24, 2013
6059 posts
2794 upvotes
Kingston, ON
Clacker wrote: But everything you've said here means that you've now granted access to your bank account to a 3rd party, which to my reading violates the banks TOS about keeping account confidentiality, so your bank wouldn't be liable for any fraud on your account. It would also mean that when (it's not an if) a third party is able to gain control of Siri on your device that they'd have full access to your bank account (or whatever you had authorized Siri to access). To me that too big of a risk for no discernible benefit. But again I'm a dinosaur when it comes to keeping my finances secure when possible.
Siri is built into Apple devices. You're asking it to check information available in apps installed on that device such as Telus to check your data use or RBC to check your bank balance. RBC has developed that app and supplied it to the App Store specifically including that feature. Nothing about this is granting 3rd party access to your online banking... the info is literally coming from the banking app on your phone (or iPad or iPod Touch or Apple Watch) that RBC designed and approved.
[OP]
Deal Addict
Mar 10, 2010
1286 posts
285 upvotes
So then any app on the phone with appropriate privileges can now access your bank information? That's a scary disregard for security. Oh well, not something I need to worry about as I don't let banking info touch my phone/tablet.
Mike15 wrote: Siri is built into Apple devices. You're asking it to check information available in apps installed on that device such as Telus to check your data use or RBC to check your bank balance. RBC has developed that app and supplied it to the App Store specifically including that feature. Nothing about this is granting 3rd party access to your online banking... the info is literally coming from the banking app on your phone (or iPad or iPod Touch or Apple Watch) that RBC designed and approved.

Top