Thread regarding Wells Fargo & Co. layoffs

Wells Fargo Breach - Change RSA PIN Notification Window. All employees.

Wells Fargo Breach - Change RSA PIN Notification Window. All employees.

Impacting all of WF... Help desk hold times over an hour...

by
| 4897 views | | 31 replies (last January 19, 2024) | Reply
Post ID: @OP+1qB5kEn6

31 replies (most recent on top)

It’s a breach. If something is out of compliance, you come up with a procedure, test it, then schedule it to avoid overloading the system. You don’t throw something together and demand immediate action.

by
| | Reply
Post ID: @3net+1qB5kEn6

The decision to reset RSA pins and require password changes is part of a team-building exercise rather than a response to a technical or security concern. It's likely that Wells Fargo executive leadership recognize the importance of teamwork and communication within the organization by introducing the initiative to encourage employees to interact and collaborate with colleagues from different departments. The RSA pin reset and password change will become a symbolic component of this initiative, designed to create a shared experience among employees. #wearetogether #wearefargo

by
| | Reply
Post ID: @1rle+1qB5kEn6

I wonder how much “risk” was created by people not being able to login to their computers at the beginning of the week, I know of some who could not login at all yesterday.

None for people who RTO

by
| | Reply
Post ID: @1qww+1qB5kEn6

@1mji+1qB5kEn6

I've had a "PIN" for many years, and at least one letter and one number was always required in the past and still is now. Not sure what change you're talking about.

by
| | Reply
Post ID: @1qrt+1qB5kEn6

@1mji+1qB5kEn6 Oh great- no breach, just gross operational incompetence!

I wonder how much “risk” was created by people not being able to login to their computers at the beginning of the week, I know of some who could not login at all yesterday. All because the administrators made a mistake and then had to meet some arbitrary deadline.

by
| | Reply
Post ID: @1eig+1qB5kEn6

Again, it wasn’t related to a breach.

The policy on RSA token PINs was changed sometime ago, to use more than just one character type. But the ball was dropped on enforcement of this policy.

It was flagged and in order to meet a compliance deadline of 1/16, everyone was forced to change their PINs. The team who manages SecureID sc--wed up badly and would have started showing up on some reports for being out of compliance today had they not rushed that forced PIN change on everyone.

They had to provide evidence they were enforcing the new policy. They hadn’t been, so this caused their mad scramble.

by
| | Reply
Post ID: @1mji+1qB5kEn6

Who is gonna be held accountable for this gross negligence?

by
| | Reply
Post ID: @1nyo+1qB5kEn6

Also received the same notice 1/12. Me and another colleague have noticed that our pulse secure has been kicking us off numerous times throughout the day in the last few weeks suddenly… I wonder if the two are connected/related.

by
| | Reply
Post ID: @1xxz+1qB5kEn6

After several failed attempts, I was able to change my pin. At least, the web site reported success. Doesn’t work, but the old one still does. Tomorrow should be interesting for anyone needing to use 2fa

by
| | Reply
Post ID: @1wdv+1qB5kEn6

If it was just a compliance issue, the requirement would be scheduled to prevent overloading the RSA servers

by
| | Reply
Post ID: @1faf+1qB5kEn6

I got the email to change my RSA token PIN today...but I was in the office today...using my virtual desktop with no need to bring my laptop or RSA token. Seriously, no notice? Something is driving that urgency.

by
| | Reply
Post ID: @1aly+1qB5kEn6

If it’s cuz of the workers in India, I’ll be laughing my a-s off at Charlie and the board.

by
| | Reply
Post ID: @1lrl+1qB5kEn6

It’s a breach. If it wasn’t, the urgency wouldn’t be as severe so as to permit everyone involved a smooth transition.

by
| | Reply
Post ID: @1jqf+1qB5kEn6

Only thing breached was Charlie’s pants by the Federal Reserve.

by
| | Reply
Post ID: @1zas+1qB5kEn6

I thought I saw a notice this morning on MyIT that all WF India resources had to do a mandatory password reset also. Can anyone confirm?

If so, that's a heck of a co-winky-di-k.

by
| | Reply
Post ID: @1mwm+1qB5kEn6

Why does this stupid sht always happen on a Monday or the day after a holiday?

by
| | Reply
Post ID: @1sqn+1qB5kEn6

Who is charge of risk in this freagin circus and why do they still have a job?

by
| | Reply
Post ID: @1ahg+1qB5kEn6

Major security failure! You’ll see it in the headlines.

by
| | Reply
Post ID: @oji+1qB5kEn6

@zzb how many other "policies" has Wells enacted with a for day timeline from announcement to completion?

This is SOP for emergency patches, which the exploit appears to be treated as. It has nothing to do with updated policies.

by
| | Reply
Post ID: @crw+1qB5kEn6

There was no breach. You’ll hear about it later.

  • The Folks that did it.

Xoxo

by
| | Reply
Post ID: @yib+1qB5kEn6

The silence from our own internal news tells me they are working hard on concocting an explanation that will not to hurt any feelings.

by
| | Reply
Post ID: @rpl+1qB5kEn6

If no breach, then why the sense of urgency?

The POS tool to reset the PIN didn’t even work the first few times I tried it, but I guess they fixed it as I was finally able to change it just now.

Thank you, Wells Fargo. So much for efficiency.

by
| | Reply
Post ID: @cml+1qB5kEn6

@zzb+1qB5kEn6

The RSA password requirements haven't changed though. Also, India now has to change all their ADent pws. Something is smelling breachy.

by
| | Reply
Post ID: @sft+1qB5kEn6

@vll+1qB5kEn6
I’d guess there are more non-layoff post than there are layoffs.
But since you are playing role of admin please delete all non-layoffs post or contribute something useful

by
| | Reply
Post ID: @hte+1qB5kEn6

OP this has nothing to do with layoffs.

by
| | Reply
Post ID: @vll+1qB5kEn6

perhaps an email would have been better than a post on Teamworks with a due date of today

by
| | Reply
Post ID: @tzp+1qB5kEn6

There is no breach. It’s to force compliance on updated policies. Too many old PINs aren’t compliant with the newish policy.

by
| | Reply
Post ID: @zzb+1qB5kEn6

And it continues:)

by
| | Reply
Post ID: @sba+1qB5kEn6

Can’t change mine-“server error”

by
| | Reply
Post ID: @ddf+1qB5kEn6

Saw the Teamworks notice on Friday (1/12) and did it on the spot. Short notice considering the holiday weekend. Wonder what shenanigans were afoot?🧐

by
| | Reply
Post ID: @tbb+1qB5kEn6

Post a reply

: