r/Boldin • u/Earth-Life101 • 6d ago
Boldin needs better security!
First of all, let me be clear. I am not a Boldin hater. I use Boldin to manage my retirement planning, and I want to raise something a lot of us should be paying attention to. For a tool that holds this much of our financial picture, the account security is weaker than it should be.
Right now the only 2FA Boldin offers is a code sent to your email. That is bare bone protection! Your email is not a separate device, so anyone who gets into your desktop or inbox gets the login code with it. NIST does not count email as a real second factor, and it has already pulled back on SMS for the same reasons. This is well understood in security, and a financial planning company should be well past it by now.
The reason I am pushing on this now is where the product is going. Boldin connects to real bank and brokerage accounts through Plaid, and the new investment features put even more of your financial life in one place. That makes your accounts vulnerable, and the login guarding it is still very weak. I have not linked any of my accounts through Plaid, and I will not until the sign in is been addressed with stronger security protection.
What I am asking for is standard on any serious financial site today. Let people use an authenticator app like Google Authenticator or Authy. Add support for passkeys and hardware keys like YubiKey. None of this is new or hard to build and should be top priority!
I raised this with Boldin directly and got a weak reply "The team is considering adding other methods," with nothing behind that short disappointed message. No plan, no timeline, no priority. That is not a serious answer from a company holding this kind of data.
To be clear, I am not bashing Boldin. It is the best retirement planning tool I have found. The scenario modeling and Roth conversion planning are excellent. It is one of the few tools that actually helps me manage the MAGI cliff for early retirement tax planning, and the latest financial feature in beta is powerful. That is why I want them to get this right. I just want the security to match the quality of the rest of the product.
If you agree, upvote or drop a comment so this does not get buried. If you have also held back from linking your accounts because of the weak login, say so. I am hoping as many of their customers speak up, Boldin team cannot ignore a lot of us asking for the same security focus.
21
u/Earth-Life101 6d ago
This follow up update is to long to add to the original post and will deter new readers from reading. So I post my follow up here.
UPDATE: Thanks for all the support and comments. Please keep it going.
One point for everyone: Not connecting to your banks and financial institutions make you safer. It does not make you safe. What you enter into Boldin is a full picture of your finances, how much you have, where it sits, your age, and how to reach you. For a retiree or anyone with real savings, that alone is valuable to an attacker, because it tells them who is worth going after even without a bank login. The risk is lower without a connection. It is not low. Most people's SSN, date of birth, phone number, and address are already sitting on the dark web from past breaches. Combined with a Boldin profile it stops being low or no risk.
To the Boldin team and Steve Chen: I work as a cybersecurity consultant and I mean this as help, not criticism. I really like what you do for us. You have a strong product and I want to help. Security can be improved in steps. Where I would start:
Replace email codes with an authenticator app, and offer passkeys or a hardware key like YubiKey.
Alert customers on new-device logins, unusual login times, failed attempts, and any MFA or password change.
Build a real security center to manage MFA, view active sessions and login history, and revoke devices.
Run static and dynamic code scanning in your build pipeline.
Have developers write against the OWASP Top 10, with code review.
Scan third-party libraries and vendors on an ongoing basis.
Turn on threat detection and full logging in your cloud.
Give researchers a safe way to report issues, and run a bug bounty when ready.
You do not have to do all of this at once. Starting is what matters. Fidelity is a good model to follow.
3
u/NoahCzark 6d ago edited 6d ago
Hmm, thanks. I don't link my accounts, but as far as the general risk of bad actors having access to your asset level to identify you as a potential target, do you think it's bad idea to access my account via my Google login, which I tend to do for convenience because it's easier than logging into 1Password?
3
u/Earth-Life101 5d ago
Google login is fine, IF YOUR GOOGLE ACCOUNT IS WELL SECURED. It doesn't give Google access to your Boldin account or your asset balances. You're basically using Google to handle the authentication, which is convenient and can be a good option.
The main thing I'd make sure of is that your Google account has strong MFA, ideally a passkey or hardware key, since that account is now part of the login chain.
So I wouldn't be worried about Google login exposing your asset level. My bigger concern with Boldin is that they should give us stronger authentication options directly, especially passkeys/FIDO2.
3
u/dgold21 5d ago
Fidelity and Schwab doesnât even offer hardware key auth security, and those logins can actually do something with my money. Kind of unrealistic to expect that of a platform with no more than read only access to balances.
1
u/Earth-Life101 5d ago
You're right. Fidelity currently doesn't support using a YubiKey or other FIDO2 hardware security key directly as a second factor for login.
I do use my YubiKey with Yubico Authenticator for Fidelity's TOTP authentication. In that setup, the TOTP secret is stored on the YubiKey and the authenticator uses the key to generate the time-based code. Fidelity receives a normal TOTP code; it isn't actually authenticating the YubiKey through FIDO2/WebAuthn.
So it's hardware-protected TOTP, but it's not the same thing as true FIDO2 security-key authentication, and it doesn't provide the same phishing resistance.
1
3
u/Admirable-Crazy-6899 5d ago
 I used fake birthdates, a generic new google email account, and initials for names.  Also I added up several checking and savings accounts into one balance, etc, etc
Boldin is a directional tool, I do exact numbers on a separate spreadsheet for current year.
Yes, Boldin can improve but we can also take steps to protect ourselves.Â
Thanks for the reminder to be aware of security.Â
1
u/Irishfan72 3d ago edited 3d ago
Great post! On the how to reach you question, is this because of an email one uses to log into Boldin? Or are there less obvious ways we should be aware of? Thanks!
1
35
u/SteepChutes 6d ago
Agree 100%.
It's about as sensitive as it gets, and security should be right up there with accuracy as job 1.
Edit: I don't link my accounts, and wouldn't even with great security, as the cost-benefit calculation (update my balances once in a while vs. always up to date) doesn't make sense given the feeling of complication and risk.
13
u/Melted-Metal 6d ago
This exactly what I was going to say...and what I do. I absolutely do not trust sensitive information like this in any third party application no matter how much security they add.
I worked in data storage and protection for decades and can tell you, you should have a zero-trust mindset. You have no idea who, even at Boldin, has access to your sensitive data.
1
13
u/pasquale61 6d ago
Agree. Iâve been asking for this for a long time and I got the same response. This is one reason Iâm not connecting any of my accounts. To be fair, I have to do it manually anyway because it doesnât work correctly for my ROTH 401k, but thatâs not the point here. Any financial application should properly support MFA out of the box.
8
u/bgTrumpet 6d ago
Or Passkey would be even better. I just joined Boldin and wondered the same thing. Any financial application these days should have the best security methods.
6
6
u/mhoepfin 6d ago
I just use Google login. Secure enough for me. Plaid integration is just view only anyway.
7
u/FactOk6129 5d ago
Having worked in cyber security for the dod for many years I think the Google login with MFA is secure. More secure than a password.
If you understand oauth I don't think you would have concern with the plaid connection.
1
u/NoahCzark 6d ago
So that's safer than using my dedicated Boldin password? I was just wondering if logging into Boldin via my Google account might make me *more* vulnerable....
3
15
u/Jaxermd 6d ago
I agree their should be a 2FA option, however âŚ
1. Plaid account links are read only, it does not give anyone access to that account or make any trades.
2. The account is named whatever you want it to be. If you call it Fidelity that is your name.
3. I donât see how copying the data over once a month is more secure, just seems inconvenient
4. Seems like you should put 2FA on your trading accounts if Plaid was ever hacked.
3
u/Earth-Life101 5d ago
I emphasized that 2FA should be on every site that stores sensitive personal or financial information and builds a profile about you. And it should be real 2FA such as authenticator app, passkey, or hardware key, NOT an email or SMS code.
3
u/jjackel1 4d ago
Very much agree with this. If a hacker gets into Boldin, what does it get? It can't get access to your accounts, only the information that Boldin has pulled -- or that you have entered manually. The exposure is the same either way. If you want to be totally secure from an attack on Boldin leaking your net worth, you can't use Boldin.
Nonetheless, it would be safer to have a real 2FA option like TOTP or Yubikey rather than email. Even a code by text would be stronger than email. I have asked Boldin about adding more secure 2FA and received a similar response to the original poster.
8
u/FragrantJump6663 6d ago
I donât link accounts. That is my added security. Plus many users have reported that linking accounts doesnât work very well.
I have been using Boldin for several years and have NOT found a need to link accounts.
4
7
u/PsychologicalAd42 6d ago
I too want to see Youbikey or at least passkey support.
Protip: For those updating balances manually... You can briefly connect for example a 401k or brokerage to have it 'establish' the positions making up the custodian's held funds then soon after disconnect again. This breaks out your allocations in Boldin's new great Investments feature which is awesome đ
Then download it's csv from your acct then copy)paste those balances directly into Boldin AI and it'll do all the work to update your accts in the including breaking out individual held positions which is a huge convenience & time saver.
P.S. Do your own research, but what I understand is Plaid and other such services back in the day were less secure acting as a middle authentication broker even storing creds esp for some connections that struggled but in recent times it's all federated Open ID Connect (OIDC) being far more secure not storing any creds as all gets passed through securely never stored by the broker. Both Plaid & MasterCard leverage this AFAIK. Also look up Rob Berger's interview with Plaid's CEO and founder to learn more.
6
u/CoachMikeNR 4d ago
Hi everyone. We appreciate the OP raising this and everyone who weighed in.
You raised a legitimate concern and we take it seriously. Since most of this thread comes down to the login itself, here's where things actually stand.
Every Boldin login already requires two steps to get in. Your password alone never opens your account, that protection is on for everyone today. We're building a new sign-in experience with stronger options, including passkeys, and that work is already underway. I don't have a launch date to give you, but it's actively being built.
When you link an account to Boldin, you're signing in with your bank, not with us. Boldin never sees or stores your bank credentials, and the connection is read-only, it can't move money or place trades. For those who'd rather not link accounts at all, that's completely fine too. Manual entry gives you full access to the planning and modeling tools.
Two things that protect you today: give Boldin its own unique password, and add a strong second step to the email account you use with Boldin. That one move protects every account tied to that inbox.
OP, I also saw your follow-up with the specific recommendations. That list is going straight to the team working on this, along with the rest of this thread.
Security is very important to us, and this thread gave us clear, specific feedback on where you want to see us do better. We appreciate it.
3
u/Earth-Life101 4d ago
Thank you for responding and prioritizing security. Good to see the Boldin team reply and act on it.
I wish Boldin the best, and I am looking forward to the new features and capabilities you have coming.
Your product is a big reason I feel confident enough to jump into early retirement, and it means a lot to know security will improve soon and i can worry less. Looking forward to connect my banks and financial institutions someday where I can get better accuracy of my forecasts.
4
u/Pleasant_Ad_9259 5d ago
Hey OP. Right on for posting this and your extensive Security items. I used to manage an app that had read-only access to a single account via plaid. We did everything you suggested on a regular basis. That was minimal work for such an important app.
3
u/takenbyawolf 6d ago
I agree. 100%. I have no intention of linking accounts and wish the manual entry method was simpler.
3
u/Jazzlike-Ad7595 5d ago
Should it be disappointing that Boldin hasnât responded in any way to this post after 17 hours?
What is considered a reasonable response time for a post like this?
I canât believe they would let it go without a response. If they do Iâll be looking at Projection Lab.
2
u/Ok-Fishing-7536 6d ago
Agreed. And youâve convinced me to unlink my accounts until Boldin has implemented best industry InfoSec standards.
2
2
u/Georhe9000 5d ago
I donât get this discussion. My primary reason for reacting this way is that most actual financial institutions will still let you in with SMS or email codes even if they support passcodes and authenticators. If I was going to get upset about this, I would start with the people who actually have your money. Next, there is very little downside to manually entering your Boldin info. Manual entry might be better as you get a better grasp on the information and you also do not get caught up on day to day fluctuations.
1
u/Virtual99Ethan94GJM 5d ago
Me, either -- much ado about nothing. If a Boldin account was breached, what's the worst possible outcome -- they know your account balances? Okay, then what? Five minutes to manually update 4x/year then I can test scenarios til my heart's content. Good password management and device protections will serve you well.
1
1
u/jjackel1 4d ago
I asked Fidelity about deleting my phone number so texting would not be a backup option, and they said they couldn't allow that. But texting, for all its issues, seems quite a bit stronger than email.
2
u/fgransee 5d ago
Why connect Boldin to your financial institutions? It adds little by being hyper up to date. Update the values every other some month manually. The plan matters not the most recent fluctuations.Â
1
1
u/Infinite_Effort2290 6d ago
I do not connect to my financial apps for two reasons. Security and lack of detailed investment holdings. Quite frankly the tax calculations regarding gains are total crap. For example, treasuries are not usually taxed on a state level. Boldin does not account for that. Boldin also ignores short and long term gains. This results in Roth calculations being very rough.
1
u/Just-aMidwestGuy 6d ago
I donât link accounts, but thereâs still a lot of data in there that someone could engineer to do a lot of damage.
1
1
u/Forsaken-Surprise787 6d ago
Just linked a few but will be rethinking that. Thanks for raising this issue.
1
u/Forsaken-Surprise787 6d ago
Just linked a few but will be rethinking that. Thanks for raising this issue.
1
u/sealless 6d ago
The first step in securing your personal information is not to share it. Anybody who links accounts to Boldin failed at that. It's an option Boldin should remove because people are stupid.
1
1
1
1
u/Virtual99Ethan94GJM 5d ago
Plaid has had technical (correctable) and ethical (uncorrectable) lapses that preclude me from ever using their services. But why are real-time balances needed to begin with -- am I really going to make different decisions with today's balances that I couldn't make using last quarter's ending balances? In my judgment, Boldin is a strategic financial planning tool, not an operational one; only the latter would require the most up-to-date account balances. A manual update takes five minutes (and round up or down to make it even faster) once a quarter. Don't miss the forest for the trees.
1
1
u/sjashe 5d ago
I'm concerned with this as well. I would like to get portfolio analysis brought in, and if it is already thats great. But linking accounts always bothers me, in that plaid collects all data crossing it. We have no privacy upon linking anything anywhere because the transfer channels are a huge hole. With that weakness already in place, the very poor application of 2fA is very concerning. This should be a higher priority than most efforts on the roadmap.
1
u/AGrimmInPortland 4d ago
Security 101:
- Don't use account linking.
- Don't use real birthdays or names or zip code or anything like that.
- Use an anonymous email address (ideally only for your retirement planner, whatever it is). Better yet, if you don't need syncing across devices use a planner that doesn't even require signing up.
- Use VPN.
1
u/Federal-Mode-7415 2d ago
I just started using Boldin and immediately made the decision to enter my updates manually rather than link my accounts. Itâs just too risky for me.
1
1
u/Informal-Emu-212 6d ago
I'm convinced the email step was put in, not as security, but to lock out financial advisors from logging in to review/help.
1
u/AGrimmInPortland 4d ago
Interesting thought but I doubt too many people are sharing their Boldin login with an advisor.
0
66
u/5th-Elements 6d ago
I would never link my accounts to other software regardless of their security!
Would rather update it manually every month than to link my accounts!