Sorry for the late update. I don't use these forums much as I don't have the same insecure need as many to push my opinions on the community. I just wanted to warn people and have done so.
Here is the update:
EVGO refunded me quickly but failed to remove my CC data from their system. Their...
This is interesting as well as the Rivian Update release notes say "verify your vehicles VIN and complete enrolment" which would seem the VIN is somehow required. It also says "Once enrolled, you can plug in your vehicle to start a charging session". But apparently you cannot. You need to go to...
That seems pretty unlikely. Can you explain that behavior? If you select any location in the app and someone is plugging in at that time you can be charged?
I did read an FAQ on the EVgo site just now saying there are checks to combat that which also seems weird you would have to have that...
Hi COdogman,
Can you please stop commenting on this post? I checked your post history and you comment a lot and add very little value to the discussions as you are here. This is an awareness post for Rivian owners not a forum for you to bicker with people.
I assume an affiliation because you are strangely defending EVgo without even bothering to understand the issue.
Read the post again. I'm not complaining (primarily) about the annoying pre-authorizations. Someone is using my account to charge on the EVGO network when I am not there. EVgo is...
This is really a red-herring. It's not clear at all and doesn't explain the unauthorized charges. The fact that it worked for you one time on another vehicle is neither here nor there.
I'll address your points one by one becuase Dogman asked:
First, I haven't posted a 0-day exploit, only a warning to end users to not share their CC data with UVgo at risk of it being abused.
To your points:
1) "enrolling in autocharge+ is a two step process". - This may be the case but how that...
Sorry. They aren't actually valid and they are coming from a stance of an insider. Whether that's an EVgo employee or a Rivian employee. I can address each one but it basically amounts to user blaming. The fact is, MY CARD IS BEING CHARGED BY EVGO WHEN I AM NOT USING IT WITHOUT MY CONSENT. This...
Ps. The instructions on this page refer to a menu in the app that doesn't exist and the call center has already informed me that it 'can only be done by the back office'. The fact that it says it can be done AND you think it can be done only makes this worse.
A clear violation of section 8 of PCI DSS. I would recommend not sharing CC data with them. The fact that it cannot be removed is also of serious concern.
As a cybersecurity professional, I want to alert the community that EVGO, its app and chargers have some major security flaws and I would recommend not using them until these issues are addressed.
I was excited by the EVGO integration in the last update and signed up for an account. I...
They reported on Reddit that there is a bug in the Android version that causes it to download the 'what's new' video repeatedly. They've blocked it on the cloud somehow and are working on an update. Apple fanboys are unaffected.