For banks that do not expose a read API (and this is, in itself, a part of the problem), Mint does direct log in on your behalf with your bank credentials. By no means am I saying that Mint will use the credentials to be a part of some mischief, but by giving your confidential credentials to a third-party, you are inherently increasing the potential attack surface on your financial assets. In some cases, things that are posted on the bank site will only be posted on Mint in 3-4 days (especially when it came to bank deposits).