FWIW, YNAB never receives or touches your bank credentials — sign-in happens through MX and Plaid, which hands back a token to YNAB to use[1]. For banks that support it, the process goes through OAuth and you sign in directly with your bank, so even MX and Plaid never see your credentials. The whole process is end-to-end encrypted, with no credentials stored at rest (unless necessary on the MX/Plaid side, but they handle that).
Not trying to change your usage or habits, just wanted to clarify.
Thanks for clarifying! I understand the architecture but perhaps didn't explain it properly in my comment.
It does honestly strike me as the best approach given the constraints, but here in Canada almost none of my banks are supported with OAuth flow last time I checked so giving the 3rd party providers my credentials and having them log into the bank both violates the TOS of my bank and is also far less secure than I'm comfortable with. Storing my financial details in YNAB / their partners is one thing, storing credentials that can be used to actually move or spend my money is another.
It's honestly not a huge deal for me personally. Entering the transactions manually is a good habit as I can see the balances update and mobile app is easy to use right on the spot.
Totally fair and reasonable! Too many banks here in the US too that both make it against TOS to get external access to your data and also refuse to offer anything secure like OAuth — extremely frustrating :/ At best you can try to pressure your bank to support OAuth but... we're just small fries.
Yeah banking is stuck in decade old technology in north america. Heck I'd settle for TOTP (or any 2FA in some cases) or getting rid of those harmful security images.
Not trying to change your usage or habits, just wanted to clarify.
[1]: https://www.youneedabudget.com/security/#direct-import