Investing - Theory, News & General • Re: Vanguard App vs website
As I mentioned above, I still have Security Codes turned on in my Vanguard security profile. As a further safeguard, should I turned Security Codes off now that I have Yubikeys working? Opinions?
Probably more than you asked for but:
With your household's mobile phones, the first thing to do is go to your carrier's website and lock down the phone from phone number port outs and SIM swaps. How this is done varies, but you'll need PINs or passcodes. That's the first layer of defense on SMS fraud. Put maximal security on the mobile phone carrier website (2FA).
Second, for every phone make sure there is a PIN or passcode or biometric ID to access the phone. Make sure that SMS text messages are not displayed on the lock screen. Set it to relock very quickly (1 minute max). If the phone is stolen you don't want the bad guy to see your texts.
Third, put 2FA on all email accounts including spouses. If Google use Advanced Protection. Google has an easy to use passkey set up, you can use the Yubikeys or passkeys set up on your phones and Windows Hello if you have PCs.
After that's done, you can consider taking SMS off the Vanguard account for 2nd factor login authentication. They will still text message you a PIN if they call you. The first three steps are arguably more important than this one. To some degree 1-3 (compromise of phone and email) have happened first to get to the point where someone is able to commit SMS fraud against your Vanguard account. Taking SMS off Vanguard is not a big deal from recovery perspective because they have a well staffed call center to restore your access under any scenario. I'd be much more careful about taking SMS off Social Security or IRS (login.gov or id.me now) that does not have well staffed IT support. Any time you take away a recovery method you have to be 100% sure you have a fallback, not 99.9% sure.
Statistics: Posted by stan1 — Sun Jul 26, 2026 8:59 am