tortor
Active Member
- Thread starter
- #1
Backgroud: I order the mach e online on 7/31, delivered to dealer on 11/9, the dealer told me to add $10K markup. I told them I need to talk to ford first. Since it is 7PM on 11/9, I talked to ford rep on 11/10 and they could not do anything. 11/11 (today) the dealer (Fremont Ford, Newark, CA) told me it was sold. See the link for details (https://www.macheforum.com/site/thr...r-10k-markup-on-my-mach-e-online-order.11287/)
The security hole: I do a online checkout the car on 11/9 right after I received the notification and was prompt to download the fordpass App and activate the car.
Today(11/11) for the curiosity, I open the app, I found that I could control the car. Note: I never got the chance to touch the car!!!!
Here is the snap shot of the App.
Advices: Be carefully about your mach e. I suspect if someone have the vin#, they could potentially control the car.
(I will leave the app as for ford to debug the issue. For whoever have bought my mach e, if you see the message, pls DM me).
Update
11/13) I correct the typo of the dates. For unknown reason, the thread was not open for further replies. Tried to email the webmaster but no response. I assume the webmaster/ford doesnt want the publicity here, but I think the owner/public need to aware this.
Becasue I believe it is not every one with a vin could gain access to any mach e, I disclosed it publicly at the same time to the ford.
Also need to clarify that I did not ever see the key and inside the car and gain the access to the car through the app. Also I didnt initiate to set the phone as the key to the car since I am not the owner of the car and did not want to get into troubles. I only could see the status of the car, the location of the car, startup the car and setup etc. I have not tried any of action that could casue change to the status of the car and leave the app as is at the moment for ford to debug it.
Currently, I believe the process need to be hardened at least
1) multi factor auth
2) prevent any man in the middle hijack.
For the least, any phone gain access to the car at least a auth code to the phone and entered into the car, along with the physical presence of the key, phone and car at the same time. It's up to the ford developer to investigate and improve the security of this process.
The security hole: I do a online checkout the car on 11/9 right after I received the notification and was prompt to download the fordpass App and activate the car.
Today(11/11) for the curiosity, I open the app, I found that I could control the car. Note: I never got the chance to touch the car!!!!
Here is the snap shot of the App.
Advices: Be carefully about your mach e. I suspect if someone have the vin#, they could potentially control the car.
(I will leave the app as for ford to debug the issue. For whoever have bought my mach e, if you see the message, pls DM me).
Update
Becasue I believe it is not every one with a vin could gain access to any mach e, I disclosed it publicly at the same time to the ford.
Also need to clarify that I did not ever see the key and inside the car and gain the access to the car through the app. Also I didnt initiate to set the phone as the key to the car since I am not the owner of the car and did not want to get into troubles. I only could see the status of the car, the location of the car, startup the car and setup etc. I have not tried any of action that could casue change to the status of the car and leave the app as is at the moment for ford to debug it.
Currently, I believe the process need to be hardened at least
1) multi factor auth
2) prevent any man in the middle hijack.
For the least, any phone gain access to the car at least a auth code to the phone and entered into the car, along with the physical presence of the key, phone and car at the same time. It's up to the ford developer to investigate and improve the security of this process.
Sponsored
Last edited: