Mondo
Member
- Thread starter
- #1
As a cybersecurity professional, I want to alert the community that EVGO, its app and chargers have some major security flaws and I would recommend not using them until these issues are addressed.
I was excited by the EVGO integration in the last update and signed up for an account. I registered my R1S's VIN on the account and entered my credit card details.
When I arrived at the charger, I plugged in but the autocharge+ feature didn't work. I tried several times and located the charger in the app and tried to start it from there. After several attempts as well as trying to use a credit card, it eventually started. I went for lunch. When I returned and hour later I checked my CC account and there were several charges and 2 separate charging charges - 1 for 10.70 and 1 for 44.22. Both were from the exact same time period (overlapping). Today, back at home, with the car in my garage, I got a charge on the CC that I was charging again (150 miles away). I opened the app to see the charge ongoing.
When I called EVGO they were very apologetic but the rep could not really do anything but stop the existing session and open a ticket with their 'backoffice'.
Some things that concern me coming from a cybersecurity perspective:
1) The chargers did not recognize my car even though it was registered as they claim it should have.
2) There is a non-interactive UI at the chargers so you don't know what is happening and can only control it from the app which is largely unresponsive.
3) The app has extremely poor UX and apparently can get miss-synced with or hijacked by another vehicle without warning or notice. I still cannot see what car is using my account. The claimed 'VIN recognition' is clearly not real.
4) The app does not have strong authentication and no option for MFA.
5) Others have claimed on the web that accounts are easily hijacked with just username and email. I haven't tested this as it would be a crime but beware.
6) Multiple CC charges are made frequently instead of just for the usage (see attached). This is confusing for users and you can miss an overcharge.
7) You cannot leave the service, remove your Credit Card, or close your account even if you call them. Apparently 'only the backoffice' can do any of these.
For now, until they get these issues resolved, I would avoid this app and service. I will give them a week to resolve the charges and then contact my credit card company.
I was excited by the EVGO integration in the last update and signed up for an account. I registered my R1S's VIN on the account and entered my credit card details.
When I arrived at the charger, I plugged in but the autocharge+ feature didn't work. I tried several times and located the charger in the app and tried to start it from there. After several attempts as well as trying to use a credit card, it eventually started. I went for lunch. When I returned and hour later I checked my CC account and there were several charges and 2 separate charging charges - 1 for 10.70 and 1 for 44.22. Both were from the exact same time period (overlapping). Today, back at home, with the car in my garage, I got a charge on the CC that I was charging again (150 miles away). I opened the app to see the charge ongoing.
When I called EVGO they were very apologetic but the rep could not really do anything but stop the existing session and open a ticket with their 'backoffice'.
Some things that concern me coming from a cybersecurity perspective:
1) The chargers did not recognize my car even though it was registered as they claim it should have.
2) There is a non-interactive UI at the chargers so you don't know what is happening and can only control it from the app which is largely unresponsive.
3) The app has extremely poor UX and apparently can get miss-synced with or hijacked by another vehicle without warning or notice. I still cannot see what car is using my account. The claimed 'VIN recognition' is clearly not real.
4) The app does not have strong authentication and no option for MFA.
5) Others have claimed on the web that accounts are easily hijacked with just username and email. I haven't tested this as it would be a crime but beware.
6) Multiple CC charges are made frequently instead of just for the usage (see attached). This is confusing for users and you can miss an overcharge.
7) You cannot leave the service, remove your Credit Card, or close your account even if you call them. Apparently 'only the backoffice' can do any of these.
For now, until they get these issues resolved, I would avoid this app and service. I will give them a week to resolve the charges and then contact my credit card company.
Sponsored