Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

U2F Fails On vanguard.com #8267

Closed
linuxluser opened this issue Feb 15, 2020 · 4 comments
Closed

U2F Fails On vanguard.com #8267

linuxluser opened this issue Feb 15, 2020 · 4 comments
Labels
webcompat/not-shields-related Sites are breaking because of something other than Shields.

Comments

@linuxluser
Copy link

Description

Fail to use U2F authentication with Yubikey on https://personal.vanguard.com/us/AuthLogin.

Steps to Reproduce

  1. Go to https://investor.vanguard.com/my-account/log-on.
  2. Login with username/password.
  3. Try to use Yubikey on next screen as 2FA.

Actual result:

Get error message There was a problem issuing a challenge for this logon. Please use security codes to sign in.

vanguard-screenshot

Expected result:

No error message and website uses my Yubikey properly like it used to.

Reproduces how often:

Always.

Brave version (brave://version info)

----------|-------------
Brave | 1.3.115 Chromium: 80.0.3987.87 (Official Build) (64-bit)
Revision | 449cb163497b70dbf98d389f54e38e85d4c59b43-refs/branch-heads/3987@{#801}
OS | Linux

Version/Channel Information:

Stable.

  • Can you reproduce this issue with the current release? Yes.
  • Can you reproduce this issue with the beta channel? Don't know.
  • Can you reproduce this issue with the dev channel? Don't know.
  • Can you reproduce this issue with the nightly channel? Don't know.

Other Additional Information:

  • Does the issue resolve itself when disabling Brave Shields? No.
  • Does the issue resolve itself when disabling Brave Rewards? Don't known.
  • Is the issue reproducible on the latest version of Chrome? Yes.

Miscellaneous Information:

@bsclifton bsclifton added the webcompat/not-shields-related Sites are breaking because of something other than Shields. label Feb 17, 2020
@bsclifton
Copy link
Member

cc: @jumde for triage

@linuxluser
Copy link
Author

Probably worth noting that I can use U2F perfectly well on Yubico's test site https://demo.yubico.com/u2f/. Also, I successfully signed into my Google account (which uses the same Yubikey and U2F) in a private Brave window.

So, to my knowledge, the issue seems to be specifically with vanguard.com. I've sent a private message to Vanguard describing my issue and linking to this bug. I'll update here if they come back with anything useful/fix the issue.

@linuxluser
Copy link
Author

Vanguard got back to me. Their recommendation was to delete the security key from the account, flush the browser cache, log back in (with security CODE this time) and then re-enroll the security key again. After I did all of this, it started working again. PROBLEM SOLVED!

What I believe happened was that I got caught between their backend system upgrade. Late last year, I got a message that said I had to re-register my security key because they were upgrading their system and improving security. I re-registered my key on Jan 7, 2020, which was just a couple weeks before the deadline. According to their instructions, that should have been sufficient. Apparently it wasn't and my key never got registered with the new system.

Kind of all makes sense now. I probably should have thought to re-register as a first step. I'll close this out. At least others can find this now if they have the same issue.

@bsclifton
Copy link
Member

Thanks for following up and letting us know you're solved, @linuxluser 😄

@bbondy bbondy added this to the Closed / Invalid milestone Jun 3, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
webcompat/not-shields-related Sites are breaking because of something other than Shields.
Projects
None yet
Development

No branches or pull requests

3 participants