Wells Fargo Security Weakness Identified

Wells Fargo security has never really been in question but I noticed a security weakness concerning its online banking today. More specifically, there seems to be a weakness with its password verification.

wells fargo loginLike any bank, Wells Fargo allows online banking via an username and password. What’s interesting is that you can actually get into the system without the correct password (as of March 16, 2009)!

All you have to do is type your username correctly and the Wells Fargo system will let you through if the password you type includes the correct password at the front.

For example, let’s say your password is “123abc” (without the quotes). If you put in the correct username and put in any string that starts with 123abc as the password, the Wells Fargo security system will let you through. So:

  • 123abc1 will work
  • 123abc2 will also work
  • 123abc41 will work as well

Hopefully, there are additional checks that I’m not seeing right now but either way, it’s much more convenient but so much less secure.

So one advice to Wells Fargo Security.  Fix it please!

{ 1 trackback }

Personal Finance Buzz
March 16, 2009 at 4:34 pm

{ 4 comments… read them below or add one }

Mary Jane Allen August 17, 2011 at 10:54 am

I just want to be able to check my accounts !!!!! Have done it for years and now there is no where to sign in at!!!!!!!

Reply

harry e cook September 20, 2011 at 2:43 am

Can’t check my account information, none of it o, help

Reply

patriciatague October 3, 2011 at 2:02 pm

I cannot get into my account at all. Please help me correct this.

Reply

elizabeth8512 February 28, 2012 at 9:43 am

I’m having difficulty getting acess to my account

Reply

Leave a Comment