how to register yubikey at VG

Questions on how we spend our money and our time - consumer goods and services, home and vehicle, leisure and recreational activities
Post Reply
Topic Author
nspen
Posts: 30
Joined: Thu Jan 09, 2020 6:29 pm

how to register yubikey at VG

Post by nspen »

We have hit a snag, trying to register a yubikey at VG.
Desktop operating system: Linux 20.2 Uma
We installed libu2-udev by running "sudo apt install libu2f-udev"
Firefox: 109.0.1

Logged into my acct, made my way down to "Set up your key"
Give key a name, then click continue.

It then opens a small boxed window saying:
personal1.vanguard.com wants to register an account with
one of your security keys. You can connect and authorize one
now, or cancel.
BUT the only option available we see is CANCEL.
What am I missing?
Any help appreciated.
Pops1860
Moderator
Posts: 1830
Joined: Thu Mar 14, 2013 4:05 pm

Re: how to register yubikey at VG

Post by Pops1860 »

This thread has been moved to the “Personal Consumer Issues” forum (computer issue, not investing per se). Moderator Pops1860
The power of accurate observation is often called cynicism by those who do not have it. ~George Bernard Shaw
jryan
Posts: 64
Joined: Mon Jun 09, 2014 9:54 pm

Re: how to register yubikey at VG

Post by jryan »

Hi nspen,

I assume that after you provided a name for your security key and clicked on "Continue", Firefox displayed a window that contained "personal1.vanguard.com is requesting extended information about your security key, which may affect your privacy." and you clicked on "Proceed".

At this point is when I believe that you saw the window that contains "personal1.vanguard.com want to register an account with one of your security keys. You can connect and authorized one now, or cancel." with only a "Cancel" button available to click on.

If you haven't already, please plug in the security key that you would like to register and you should be able to touch the YubiKey to complete the registration process (I have a Security Key NFC and it starts blinking to let me know when I'm expected to take action).

Good luck!
Topic Author
nspen
Posts: 30
Joined: Thu Jan 09, 2020 6:29 pm

Re: how to register yubikey at VG

Post by nspen »

Thanks, we will try that.
Topic Author
nspen
Posts: 30
Joined: Thu Jan 09, 2020 6:29 pm

Re: how to register yubikey at VG

Post by nspen »

jryan wrote: Sat Feb 18, 2023 6:34 pm Hi nspen,

I assume that after you provided a name for your security key and clicked on "Continue", Firefox displayed a window that contained "personal1.vanguard.com is requesting extended information about your security key, which may affect your privacy." and you clicked on "Proceed".

At this point is when I believe that you saw the window that contains "personal1.vanguard.com want to register an account with one of your security keys. You can connect and authorized one now, or cancel." with only a "Cancel" button available to click on.

If you haven't already, please plug in the security key that you would like to register and you should be able to touch the YubiKey to complete the registration process (I have a Security Key NFC and it starts blinking to let me know when I'm expected to take action).

Good luck!
Thanks, jryan, you were spot on. It worked.

We tried logging in again. Worked with yubikey as expected.
Looks like they could have put an instruction in there, to insert key, then touch when blinking.

Now, next couple of questions.
then tried logging in again without yubikey. It sent me a text code and we logged in as before, without a yubikey.
So, I presume if we want yubikey security, we have to do away with the text code option, which we will need to know how.
Also, what if this computer were to break down. Can we use the yubikey to log in from another computer? Would hate to get locked out of my account.
MGBMartin
Posts: 1145
Joined: Thu Nov 04, 2021 11:09 am

Re: how to register yubikey at VG

Post by MGBMartin »

I’ve just purchased 2 Yubikeys and I am going through this process myself.
I haven’t done our Vanguard accounts yet but with the accounts I have done I am able to log on from different devices like laptop and tablet using my Yubikey(s). I expect Vanguard will be the same as the key is the identifier not the laptop or tablet.
Bad spellers of the world untie | Autocorrect is my worst enema
otinkyad
Posts: 486
Joined: Wed Jun 01, 2016 5:35 pm

Re: how to register yubikey at VG

Post by otinkyad »

nspen wrote: Sun Feb 19, 2023 7:35 pm Now, next couple of questions.
then tried logging in again without yubikey. It sent me a text code and we logged in as before, without a yubikey.
So, I presume if we want yubikey security, we have to do away with the text code option, which we will need to know how.
Also, what if this computer were to break down. Can we use the yubikey to log in from another computer? Would hate to get locked out of my account.
Welcome to the quirky world of Vanguard 2FA. First, there are conflicting reports about whether having two security keys allows you to turn off SMS security codes, but due to a misfeature in the mobile app, you don’t want to do that anyway. I live with this, and take the phishing protection the security keys offer, but others switch to using a Google Voice number for SMS for more security.

Second, you don’t want to allow access only from recognized devices. There are reports that this interacts badly with security keys and blocks all access.
jryan
Posts: 64
Joined: Mon Jun 09, 2014 9:54 pm

Re: how to register yubikey at VG

Post by jryan »

nspen wrote: Sun Feb 19, 2023 7:35 pm Thanks, jryan, you were spot on. It worked.

[snip]

Now, next couple of questions.
then tried logging in again without yubikey. It sent me a text code and we logged in as before, without a yubikey.
So, I presume if we want yubikey security, we have to do away with the text code option, which we will need to know how.
Also, what if this computer were to break down. Can we use the yubikey to log in from another computer? Would hate to get locked out of my account.
Excellent!

I don't know that I've tried all of the permutations, but as otinkyad observes, given that the Vanguard mobile app (at least the iPhone version) will allow you to access your account using only password authentication if you disable SMS authentication, someone with your username and password could install the app and access your account. :-(

For the moment, I'm leaving SMS authentication enabled, but as otinkyad suggests, perhaps using a Google Voice number is the best we can do for now.

It would seem that Vanguard has a hole big enough to drive the tractor from Duel through.

What a mess!

If Vanguard enables the app to use a YubiKey (and no other holes are discovered), you should be able to disable SMS authentication via Profile & account settings -> Security -> Security code -> Disable.

MGBMartin is correct: As long as you have a YubiKey with you, you should be able to access your account using any device that supports the YubiKey (which should now include iPhones).

For what is is worth, you mentioned that you installed libu2f-udev, but based on Debian bug #951201, it may be the case that this package being installed is no longer required for many current Linux distributions. (I deleted it from my Debian GNU/Linux 11 ("Bullseye") system and all is well.)

Thanks for the update!
PersonalFinanceJam
Posts: 693
Joined: Tue Aug 24, 2021 8:32 am

Re: how to register yubikey at VG

Post by PersonalFinanceJam »

Don’t mean to hijack this thread but just tried this at Vanguard with success so I thought I’d contribute to the discussion instead of creating a new thread. If you have an up to date smart phone it looks like you no longer need the Yubikey and can register with the PassKey support in your phone. On my Mac running safari when I went register, in the browser box which popped up prompting me to select the type of device I wanted to register, I selected other/phone device. A QR code was shown which I scanned with my iPhone and generated the key. This was then synced via iCloud Keychain to the rest of my devices. Since the key is synced, when I log in again with safari from my Mac, it offers to use the synced key. If I go to a different computer which doesn’t have the synced key, a QR code is shown which can be scanned with the iPhone and then the phone supplies the key.

I’m in the Apple ecosystem, but my understanding is if you use Android/Chrome/Google password manager, the experience should be similar. Gives me hope that we will see more of this type of support in the future. You may still want a Yubikey for other security reasons, but I’m pretty ok with getting some of the benefits in software and having the key sync so I don’t lose it.
pdbaaxk
Posts: 3
Joined: Sun Dec 15, 2013 1:27 pm

Re: how to register yubikey at VG

Post by pdbaaxk »

Can you register passkey if you already have yubikey registered?
Northern Flicker
Posts: 15363
Joined: Fri Apr 10, 2015 12:29 am

Re: how to register yubikey at VG

Post by Northern Flicker »

If a passkey is registered, will the Vanguard phone app make use of it and require it for login?
Post Reply