Banks are equally (if not more) innovative in all the creative ingenious ways to thoroughly enshitify a service while still retaining loyal patrons who accept it, lick their boots, and stay over the long haul to experience new developments in enshitification techniques.
Enshitification is the most abusive when it is forced on you. Banking is one such case in many regions.
In my futile attempt to capture it all, I began with a list of categories so the various varieties of shit can be anatomized and classified into a taxonomy of shit:
- Direct snooping and overcollection of data
- Indirect snooping, outsourcing, info sharing, digital footprint maximization across actors
- Anti-competition (e.g. “relationship banking”; all war on cash actions are anti-competition)
- Protectionism
- Dark patterns with money
- Tech incompetence
- Tech-driven exclusivity and discrimination / forced use of shitty tech
- Discrimination against who you are and your demographic
- Diffusion of responsibilty (i.e. finger pointing mechanisms)
- Suppression of info (e.g. outsourced entities, reporting thresholds)
- Reduced protection of data at rest
- Data breach “compensation” without remuneration that enlarges consumers’ digital footprint (and lost opt-out letters)
- Reduction of services
- Automated decision making logic without human intervention
- Penalization of enshitification avoidance
Of course the problem is immediately evident: most instances of enshitification fit into multiple categories. I cannot think of a useful way to reduce and broaden the categories to a point where instances of enshitification can each map to just one single category.
The itemized list enshitification instances is crazy long:
(EC → Enshitification Category)
Walk-in service without appointment is going away (EC 7,15) Some banks insist on an appointment; some have even dropped the appointment option and you simply cannot meet in person.
Banks are gradually removing services from their website (EC 7,13) This is to force more people to use their dodgy app.
All banks with apps impose closed-source software (EC 10)
Most banks with apps impose Google or Apple patronage just to obtain the app (EC 2) You must share sensitive info with surveillance advertisers in a country without privacy safeguards, and disclose to those untrustworthy corps where you bank.
Some banks have shutdown their website and closed their doors (EC 2,13) Thus making a dodgy app the exclusive means of access to your acct.
Some banks plainly write in their ToS that they log your IP; some don’t tell you (EC 1,10) When the ToS mentions this, it sometimes admits the purpose is to track your whereabouts.
Some banks refuse you an account if they discover you are US-born (EC 8) [outside the US] The ones that do not refuse an account still give adversely discriminatory treatment.
Banks outsource and share your personal data w/the supplier to repudiate fault in data breaches (EC 2,9,10) This is extra insideous in the US because if you get breached from a 3rd party, the 3rd party has no legal obligation to disclose to you which of your banks hired them, and the bank has no obliation to disclose their partners to you.
Banks loosely share your personal data to minimize quanitifiable breach damages (EC 2,9) It’s hard to attribute damages to a specific breach if your data was previously “legitimately” shared all over the place anyway.
Credit bureaus break the law requiring disclosure of their sources (EC 2) [US] Credit bureaus conceal from people /who/ reported their addresses (physical and email) to them. It’s illegal but there is no penalty so the law is just ignored. Consequently, banks share that info freely.
Cash withdrawal limits are shrinking (3,4) There are daily limits and monthly limits. As they shrink, you lose the ability to escape as quickly as you one day might want to.
Reduction of ATMs (EC 3,13) Europe
ATM consortium monopolies forming (EC 2,3,9) Netherlands, Belgium. Many banks have removed all their own ATMs and joined a consortium. Competition is gone. Netherlands has whole cities that have only one exclusive ATM operator (“Geldmaat”). If it gives you bad service, you’re fucked.
Reduced ATM services (EC 3,13) Balance inquiry service is either being stripped away or limited to clients of a specific bank
Elimination of ATM receipts (EC 13) Germany
Elimination of larger banknotes from ATMs (EC 13) Netherlands and France
ATM arbitrary denial of service (EC 3,8,9,10,14) Unlawful use of automated decision making logic without human intervention and without disclosure of /why/ a transaction is denied. ATM messaging always faults the card or the issuing bank even when the ATM internally denies a transaction.
Undisclosed ATM withdrawal limits (EC 3,10,13) ATMs have different withdrawal limits depending on whether a card is foreign or domestic. They never disclose the limit.
ATMs that eat cards if PIN entry is wrong (and conceal the confiscation risk) (EC 3,5,10,14) Netherlands
ATMs that eat cards if “fraud” is suspected (and conceal the confiscation risk) (EC 3,5,10,14) Netherlands
ATMs that eat cards if it cannot read the EMV chip (and conceal the confiscation risk) (EC 3,5,10,14) Netherlands
ATMs that take a fee without disclosure or consent (EC 3,5,10) Germany
Some banks disable your card after ~3 ATM refusals (EC 3,14) They think it’s “suspicious” if ATMs refuse you in as few as 3 times consequetively despite you having to guess at what the undisclosed ATM limit is for foreign cards when visiting a foreign country.
Some banks freeze your account if your ID card on file expires (EC 1,5,10) It’s a way of communicating with customers. Instead of making the effort to inform you that your ID docs will expire, they just set the machinery to block access to your money on ID card expiry (even if that lands on a Friday and the bank is not open until Monday). It’s comparable to the method of communication used in Office Space to tell Marvin he was fired (no paycheck).
Some banks send an annual “welcome” letter (EC 1,5) It’s a sneaky way to check whether you still live at your current address. They send a useless letter periodically at your expense. If the letter is returned, they know you moved without telling them your new address.
Some banks charge extra for analog operations like paper statements (EC 15) To avoid enshitified digital platforms you naturally must switch to analog operations. But that’s not gratis at shitty banks. Penalties for avoiding enshitification is in itself an instance of enshitification.
Some banks simply outright refuse to send a paper statement (EC 1,15) Digital banks simply break the law requiring them to issue periodic statements. If you’re not on their digital platform, they will not communicate with you despite legal obligations. Tagged in cat.1 because forcing you onto their digital platform entails excessive data collection (IP address).
Some banks refuse cash deposits (EC 1,3,13) It’s a blunt refusal at some banks, and at others cash deposits impose an intrusive process of submitting proof of source (or be refused)
Some banks refuse cash withdrawals (EC 1,2,3,4,13,15)
Some banks report cash withdrawals to the police (EC 2,3,4) [Europe] Someone tried to simply withdraw a few thousand euros from her own account. The bank called the police to detained her for interrogation.
Some banks block Tor (EC 1,13) Banks can justify blocking Tor if they lack the competence to securely handle Tor connections -- but can they justify the incompetence? It’s enshitification nonetheless.
Some banks let you login over Tor, then instantly close your account (EC 1,5,13,14) [US] Some banks go to the insideous extreme of allowing customers to reach the login page over Tor only for the fucked up undisclosed purpose of discovering which of their customers use Tor. Then they close the account instantly and irreversably. To recover from this, you must open a whole new account from scratch.
Some banks refuse cash payments on a mortgage (EC 1,2,3,4)
Relationship banking→ forced account opening (EC 3,8) [Europe] Banks refuse to give you a mortgage unless you open other types of accounts. If the bank refuses you an asset account on the basis of where you were born, then they also refuse you a mortgage for not having your asset account with them. It amounts to discrimination in a housing transaction on the basis of national origin (a human rights violation). US banks do not take relationship banking to this extreme, which gives a strange inversion of what you would expect between the US and Europe.
Alcohol purchases tracked for mortgage denial (EC 1,4,8) [Europe] Some Scandinavian banks track your alcohol purchases, assume you’re drinking alone, and tag you as having a drinking a problem which then leads to mortgage denials. This showcases the stupidity of cashless bars in Netherlands.
All debits processed first in daily batches (EC 5) [US] Regardless of the sequence of your credits and debits throughout the day, at the end of the day the bank processes all debits first, then all credits. This increases the number of overdrafts, thus bank fees.
Credit cards send a paper check to refund a credit (EC 5) [US] The credit line is more profitable for banks if you are in debt. To increase debt (thus fees and interest) they disallow accounts from carrying a credit by sending a paper check and zeroing the balance. At the same time the customer’s money is inaccessible while traveling as a paper check.
Some banks send malformed email (EC 6) They assume everyone uses a graphical mail client. Many banks do not send a plaintext MIME part. And worse, some obnoxious and incompetent banks send a plaintext MIME part that says “your mail client has a problem” or ”get a better mail client”.
Some banks embed tracker pixels in email (EC 1,5) Tracker pixels are injected into email so when you open it the bank gets a signal that tells them that ① your email address is valid and you read it, ② when you read it, and ③ your IP address (which reveals other sensitive info)
Some digital banks surreptitiously use Microsoft or Google for email (EC 2,5,6) And worse: they often make it the sole means of communication.
Some banks share your email address with others (EC 2) E.g. credit bureaus
Some banks reject email forwarding addresses (EC 1,10) If supplying an email address to a bank, it’s a good practice to use a unique address just for that bank. If the address is leaked and/or abused, it enables you to trace the malpractice to the bank. For that self-defense reason, some banks reject such addresses.
Many credit unions surreptitiously expose all your most sensitive data to Cloudlare (EC 2,6,7,9,10,14) CF sees your unhashed username and pw without your knowledge. At the same time, the ToS shifts responsibility for credential leaks onto the customer.
Most CUs outsource billpay (EC 2,6,9) And the service is “free” with free postage on mailed checks. Don’t ask how it’s paid for. The few giant suppliers obviously see all the transactions they handle.
Most CUs outsource e-statements and statement printing (EC 2,6,9) The few giant suppliers obviously see all the transactions they handle.
Most CUs outsource their webservices (EC 2,6,9) The few giant suppliers obviously see all the transactions they handle.
Most CUs outsource their phone apps (EC 6)
All banks and CUs have increasingly become KYC over-achievers (EC 1) [US] They collect much more information than legally required.
Some banks close your account if they suspect you are working in the sex trade or marijuana trade (EC 8)
Some banks close your account if they suspect you buy or sell a competing financial instrument (like cryptocurrency) (EC 3,4)
Amid the non-stop increasing enshitification of banks, Bruce Schneier said: “cryptocurrency is a solution looking for a problem”. Really, Schneier? You can’t find any problems with banks and credit unions?
The ultimate refuge from enshitification (of any kind) is non-participation. Boycotts. But forced-banking has quietly become reality in some regions, like Europe. Enshitification is therefore forced. There is no right to boycott. Even living off-grid and self-employed does not solve the problem when the gov’s tax regime refuses cash payments and requires bank transfers.
EDIT: please mention any instances of enshitification not mentioned in my list. Would be nice to have a comprehensive overview in one place.