Wells Fargo Password Restrictions are Useless as Tits on a Frog
Let me explain.
On March 10, 2024, I attempted to log in to our joint checking account at Wells Fargo. I needed to download our statements to do our taxes.
I received a message stating I had made too many failed attempts to log in and would have to change my password. I haven’t accessed this account in the last year, as I never need to until tax time. My previous password was 13 characters with a combination of upper case, lower case, numbers and 2 special characters. So I added two new characters to this one, updating my spreadsheet and saving it immediately.
The online form would not accept my changes.

The message it gave me was:
Your new password must:
- be between 8 and 32 characters
- have at least 1 number and 1 letter
Don’t use your SSN, email, username, or previous passwords
I want you to look at that second bullet point again.
The ONLY restriction is ONE number and ONE letter.
No uppercase
No special characters
In the 21st century this is ridiculously horrible security for a financial institution.
Now my only option is to call Wells Fargo, which I do. The first person I reach is Omar, who tells me the password restriction is 14 characters, not 32. I can hardly believe my ears, because again, this is horrible security. I tell him to email me a password reset link. He says they will assign a temporary password and send the email. We hang up.
I get the email and try this again. Still using my Firefox browser. Same problem. I am now trying to create a new password again and it won’t accept my choice.
So I switch to Chrome, because I know that some sites don’t play well with Firefox.
No joy.
So I call Wells Fargo again, this time reaching Fritz. We go through some attempts and he says “remove the special characters”. I have a minus sign and a hashtag in the password currently.
I remove the hashtag.
No joy.
I remove the minus sign too. Now I have no special characters.
The dialog box now accepts my password.
And I am able to access my statements.

They are all PDF files.
I click on one to download it and am redirected to the Adobe site to use Acrobat. Not to a new tab.
I am directed AWAY from Wells Fargo. After I download a statement I have go BACK to Wells Fargo and select another one.

This is not acceptable security for a financial institution. Basic HTML code allows you to specify the action of clicking on any given link. You should never be redirected AWAY from their site without a warning to that effect.
I tell Fritz this is hideously bad security for a financial institution. I tell him I want a supervisor.
I am transferred to Anthony. I tell him the history of my experience and how horrible this is.
I tell him in no uncertain terms that this is entirely unacceptable and someone needs to do a security audit and pronto. The server audit logs need to be checked to find out when the password requirements were loosened and by whom.






Leave a Reply
You must be logged in to post a comment.