Sponsored

godfodder0901

Well-Known Member
First Name
Jared
Joined
Mar 12, 2019
Threads
27
Messages
5,749
Reaction score
10,139
Location
Washington
Vehicles
2022 Rivian R1T LE
You might want to browse the dark web as password hashes are compromised by the millions due to poor server configurations and security. Don't assume that there aren't Rivian owners here with degrees in computer science. There are plenty of examples of companies losing plain text passwords and hacking stores that bypass hashes. We have no way of knowing as users on our end how business is conducted.

Coincidentally came across this morning and it is pertinent to this thread since 2fa is often sim based.
https://www.zdnet.com/article/fbi-c...essaging-apps-in-wake-of-massive-cyberattack/
I'm plenty aware of the kinds of breaches you mention. Poorly configured servers do not obviate the need for secure passwords, but highlight their usefulness.

And don't assume you're the only Rivian owner with a CS degree... ?
Sponsored

 

Electrified Outdoors

Well-Known Member
First Name
Ken
Joined
Jan 30, 2023
Threads
63
Messages
3,683
Reaction score
3,980
Location
Mount Airy, Maryland
Website
EVoutdoors.org
Vehicles
2024 Rivian R1S Quad, 2024 Silverado EV RST First Edition
Occupation
Real Estate
Clubs
 
I’m surprised they haven’t required it before now especially since they don’t have a Pin to drive feature.

I would argue that text and email are not enough and that an authentication app the generates rolling codeis better

I have several connections I use DIMO, ElectraFi, and Recurrent though I have a special account just for that in case there is a polling issue. Also more secure than using the owner acct..
 

HaveBlue

Well-Known Member
Joined
Nov 22, 2022
Threads
41
Messages
2,926
Reaction score
2,234
Location
91107
Vehicles
R1S DMP Max, Lifted GX470, APR Audi A7, BMW 325Ci
Clubs
 

fxstein

Well-Known Member
First Name
Oliver
Joined
Sep 17, 2024
Threads
10
Messages
126
Reaction score
249
Location
California
Vehicles
2023 R1T Quad Adventure
Clubs
 
No. Many work with MFA. I have it set and still use the HA integration.
Same. Works just fine. MFA should be mandatory on any website we use. Really a no brainer.
 

Sponsored

schlosrat

Well-Known Member
First Name
Steve
Joined
Jun 23, 2024
Threads
6
Messages
191
Reaction score
179
Location
Vancouver, WA
Vehicles
2024 R1T Dual Large
Occupation
Engineer
I agree with your assessment right up until the point you let AI insinuate that email/SMS 2FA is less secure than no 2FA. This simply isn't true. Are there significantly better/more secure ways to implement 2FA? No doubt. But is it somehow less secure than not having it? Absolutely not.
So you agree up to the point he happened to use AI to neatly summarize all the real sources he also supplied? If he'd based his whole argument on what AI summarized for him, you'd have a fair point perhaps - but he didn't do that, did he?
 

godfodder0901

Well-Known Member
First Name
Jared
Joined
Mar 12, 2019
Threads
27
Messages
5,749
Reaction score
10,139
Location
Washington
Vehicles
2022 Rivian R1T LE
So you agree up to the point he happened to use AI to neatly summarize all the real sources he also supplied? If he'd based his whole argument on what AI summarized for him, you'd have a fair point perhaps - but he didn't do that, did he?
Um.. Yes, he did? He also gave a biased prompt to AI in order to get the answer he wanted, instead of a correct answer... Gemini had no choice but to corroborate his false claim with the prompt "why 2fa sms is worse than no 2fa".

You know what he didn't do? Read any of the articles he referenced. They clearly state:
Do I even need two-factor authentication if SMS is so vulnerable?
Yes! In addition to creating strong passwords and using different passwords for each of your accounts, setting up 2FA is the best move you can make to secure your online accounts -- even if you insist on receiving codes via SMS. Two-step verification via SMS is better than one-step verification where a hacker needs only to obtain or guess your password in order to gain access to your data. Don't be the low-hanging fruit with an account that is the easiest target for hackers.
Second, using SMS for 2FA is much, much more secure than using no 2FA at all.
While SMS 2FA is considered a relatively secure form of 2FA, it’s not without its flaws.
 

schlosrat

Well-Known Member
First Name
Steve
Joined
Jun 23, 2024
Threads
6
Messages
191
Reaction score
179
Location
Vancouver, WA
Vehicles
2024 R1T Dual Large
Occupation
Engineer
Um.. Yes, he did? He also gave a biased prompt to AI in order to get the answer he wanted, instead of a correct answer... Gemini had no choice but to corroborate his false claim with the prompt "why 2fa sms is worse than no 2fa".

You know what he didn't do? Read any of the articles he referenced. They clearly state:
See, now this is a cogent reply. Thanks for taking the time to pull it together.
 

iforbes

Well-Known Member
First Name
Ian
Joined
Oct 24, 2022
Threads
9
Messages
515
Reaction score
883
Location
Connecticut
Vehicles
R1T
Occupation
APRN
Clubs
 
Hi all,

I got the electrafi email stating that “Token Authorization Expired For Account”. I recently switched to F2A, I can no longer log in to my Rivian account from the electrafi account to get new tokens. Anyone else having this issue?

I placed a ticket with electrafi but haven’t heard anything back yet.
 
OP
OP
tate16t

tate16t

Well-Known Member
First Name
Robert
Joined
Apr 7, 2022
Threads
64
Messages
1,396
Reaction score
1,181
Location
NY
Vehicles
2023 El Cap Granite R1S
Occupation
Car Enthusiast
Hi all,

I got the electrafi email stating that “Token Authorization Expired For Account”. I recently switched to F2A, I can no longer log in to my Rivian account from the electrafi account to get new tokens. Anyone else having this issue?

I placed a ticket with electrafi but haven’t heard anything back yet.
Did you try disabling 2FA on the Rivian account, logging into Electrafi, and then reenabling 2FA after? The problem will be after Rivian enforces 2FA this approach will no longer work since disabling will not be an option. I’m pretty sure when I initially setup Electrafi I took this approach.
 

Sponsored

dleepnw

Well-Known Member
Joined
May 13, 2021
Threads
148
Messages
3,011
Reaction score
3,417
Location
WA
Vehicles
Rivian, Toyota, Lexus
Clubs
 
Is this Rivian's way (at least) to try kill third party tools?
They've always had two-factor authentication. Do you mean they are making it mandatory?
 

iforbes

Well-Known Member
First Name
Ian
Joined
Oct 24, 2022
Threads
9
Messages
515
Reaction score
883
Location
Connecticut
Vehicles
R1T
Occupation
APRN
Clubs
 
Did you try disabling 2FA on the Rivian account, logging into Electrafi, and then reenabling 2FA after? The problem will be after Rivian enforces 2FA this approach will no longer work since disabling will not be an option. I’m pretty sure when I initially setup Electrafi I took this approach.
Good work-around (for now lol). I’ll try it later. I think I assumed once I went F2A, that I couldn’t go back.
 
OP
OP
tate16t

tate16t

Well-Known Member
First Name
Robert
Joined
Apr 7, 2022
Threads
64
Messages
1,396
Reaction score
1,181
Location
NY
Vehicles
2023 El Cap Granite R1S
Occupation
Car Enthusiast
Good work-around (for now lol). I’ll try it later. I think I assumed once I went F2A, that I couldn’t go back.
That will be the case starting Dec 13th, hurry ?
 

iforbes

Well-Known Member
First Name
Ian
Joined
Oct 24, 2022
Threads
9
Messages
515
Reaction score
883
Location
Connecticut
Vehicles
R1T
Occupation
APRN
Clubs
 
That will be the case starting Dec 13th, hurry ?
Hopefully electrafi updates their “get-a-new-token” script to allow for the new requirements. Sooner rather than later.
 

HammerFLA

Active Member
First Name
Walter
Joined
Nov 14, 2024
Threads
2
Messages
25
Reaction score
29
Location
Orlando, FL
Vehicles
2025 R1T (on order) 2018 Model 3 Tesla, 1973 VW THING, 2007 Honda VTX 1300
Occupation
Aircraft Mechanic
I hate 2FA! Can someone tell me what secret info I have on my account that cant be easily found on the internet? Name, address, email, etc I have no Credit card info saved on my account!
Sponsored

 
 








Top