Sponsored

Multi-factor auth

mikehmb

Well-Known Member
First Name
Mike
Joined
Jan 12, 2022
Threads
154
Messages
2,303
Reaction score
5,223
Location
SF Bay Area
Vehicles
My name is Mike, and I have a (car) problem
Ok, through a series of questionable life and career decisions, I'm a security person, by choice. You can decide if it was a good or bad choice, but I have less hair and a twitch in my left eye after many years of this stuff.

I'm intrigued by MFA in the truck's new SW update. It's a clever implementation, and I'm sure it will prevent all sorts of bad behavior, theft, and bring peace of mind to the paranoid among us.

But ... has no one ever dealt with a lost or dead phone before? I carry a key card in my wallet (when I bring my wallet) for backup in the event phone goes missing.

What was wrong with PIN? I would really like that as an option, despite the obvious security shortcomings of a simple 4 or 6 digit code.

What's the backup retrieval / startup method if your phone is dead/gone?
Sponsored

 

portdirect

Well-Known Member
Joined
Jun 15, 2023
Threads
16
Messages
928
Reaction score
1,372
Location
Missouri
Vehicles
R1T (2023 QM - RIP, 2025 Tri Max), R1S (2024 DM Large)
Occupation
Blinkenlight Hearder
I’m inclined to agree, it seems like a reasonable (though gated) TOTP - but in a place no one really asked for one. I suspect they built it for fleet use, and ā€˜recycled’ it to make the claim of most secure system in a consumer vehicle. Thankfully you can turn it off, but I’d take a pin any day over this for most practical usage. Security is a balance between strength and usability - here they possibly went too far, which will result in a low uptake and hence not really improve the posture as much as it could have.

Re your questions, all I can offer is /shrug, doesn’t seem to be documented anywhere obvious (though I’ve not scoured for it).
 

VandalSibs

Well-Known Member
First Name
Andrew
Joined
Dec 27, 2023
Threads
15
Messages
1,379
Reaction score
2,387
Location
Eastern Washington State
Website
www.sibulskymusic.com
Vehicles
R1T Dual Motor Large Pack
Occupation
Composer, IT Service Desk Analyst
Clubs
 
I rarely carry my phone. Give me a key to start the car then. This is one of the dumbest things I have heard of. Will they buy my truck back.
Overreacting much? You don't have to use the feature.
 

COdogman

Well-Known Member
First Name
Brian
Joined
Jan 21, 2022
Threads
33
Messages
11,641
Reaction score
34,494
Location
CO
Vehicles
2023 R1T
Occupation
Cyber defender
Clubs
 
Ok, through a series of questionable life and career decisions, I'm a security person, by choice. You can decide if it was a good or bad choice, but I have less hair and a twitch in my left eye after many years of this stuff.

I'm intrigued by MFA in the truck's new SW update. It's a clever implementation, and I'm sure it will prevent all sorts of bad behavior, theft, and bring peace of mind to the paranoid among us.

But ... has no one ever dealt with a lost or dead phone before? I carry a key card in my wallet (when I bring my wallet) for backup in the event phone goes missing.

What was wrong with PIN? I would really like that as an option, despite the obvious security shortcomings of a simple 4 or 6 digit code.

What's the backup retrieval / startup method if your phone is dead/gone?
I blame your kids and dog for the eye twitch. The hair is genetic!

I actually chose cybersecurity at middle age after years of being a business owner, so that is how crazy I am :CWL:

One thing I have learned so far is that tools and policies are useless if people won’t use them for whatever reason. I like what they are doing by offering TOTP but if no one adopts it, the PIN would be a nice backup to have.…
 

Sponsored

godfodder0901

Well-Known Member
First Name
Jared
Joined
Mar 12, 2019
Threads
27
Messages
5,749
Reaction score
10,139
Location
Washington
Vehicles
2022 Rivian R1T LE
I blame your kids and dog for the eye twitch. The hair is genetic!

I actually chose cybersecurity at middle age after years of being a business owner, so that is how crazy I am :CWL:

One thing I have learned so far is that tools and policies are useless if people won’t use them for whatever reason. I like what they are doing by offering TOTP but if no one adopts it, the PIN would be a nice backup to have.…
Yep. Finding the balance between security and usability is an art.
 

ThumprMN

Well-Known Member
First Name
Simon
Joined
Dec 17, 2019
Threads
3
Messages
427
Reaction score
1,119
Location
Richfield, MN
Vehicles
Rivian R1T
Occupation
IT Professional
Clubs
 
I rarely carry my phone. Give me a key to start the car then. This is one of the dumbest things I have heard of. Will they buy my truck back.
I just called Rivian, they said they’ll trade you your truck for a 2002 Camry with an actual key and zero software updates. Win-win?

šŸ›» šŸ‘šŸ¼
 

tate16t

Well-Known Member
First Name
Robert
Joined
Apr 7, 2022
Threads
64
Messages
1,396
Reaction score
1,181
Location
NY
Vehicles
2023 El Cap Granite R1S
Occupation
Car Enthusiast
The way Rivian implemented this definitely will not work. If you lose your phone, your shit out of luck. Even if you have your key card or keyfob, you’re still shit out of luck because you need your phone if you have MFD enabled.
 

ohseedee

Well-Known Member
Joined
Mar 1, 2022
Threads
15
Messages
735
Reaction score
1,728
Location
California
Vehicles
R1T
Even worse, early Rivian owners remember when some server issue took out phone as a key for everyone for several hours. I was out of town and my card was left in the truck and couldn’t get in for hours. I’d rather risk someone hacking and stealing my car than get stranded by some MFA issue. I’ll pass.
 

Singletracker

Well-Known Member
Joined
Mar 10, 2022
Threads
39
Messages
1,303
Reaction score
1,274
Location
NV
Vehicles
2023 R1T QM w/20ā€ A/T’s
Not everybody chooses to carry or has their phone with them, ALL the time. Count me as one of those people. I use the fob. However, I do have an Apple Watch, which I understand may do the trick. Even so, IMHO, Rivian way over thought this one, to the point that people probably won’t use it. They should have implemented a driver selected, reusable PIN, just like a phone. KISS
 

Sponsored

CANCERDOC

Well-Known Member
First Name
Eric
Joined
Oct 26, 2023
Threads
14
Messages
735
Reaction score
1,126
Location
Southern California
Vehicles
2024 R1S PDM
Occupation
Healthcare
I thought the phone was the primary two factor but if the phone is not confirmed there was an option for an on screen code. I guess not?
 

Taco

Well-Known Member
Joined
Dec 29, 2021
Threads
19
Messages
326
Reaction score
504
Location
Parker, CO
Vehicles
R1T R1S
Yep PIN to drive is the way for MFA.

Although I wouldn't be against using your phone as MFA for when you assign a PIN.

1st attempt, happy they have done something but hopefully the data says "a bit too much, let's make some adjustments"
 

godfodder0901

Well-Known Member
First Name
Jared
Joined
Mar 12, 2019
Threads
27
Messages
5,749
Reaction score
10,139
Location
Washington
Vehicles
2022 Rivian R1T LE
I thought the phone was the primary two factor but if the phone is not confirmed there was an option for an on screen code. I guess not?
The phone or watch are the only options. You can input a TOTP instead of the push notification, but that code is generated in the Rivian app on your phone.
 

Tim-in-CA

Well-Known Member
Joined
Sep 30, 2021
Threads
46
Messages
1,791
Reaction score
3,429
Location
So Cal
Vehicles
Gen 1 R1S, Lucid Air, T-Bird
The way Rivian implemented this definitely will not work. If you lose your phone, your shit out of luck. Even if you have your key card or keyfob, you’re still shit out of luck because you need your phone if you have MFD enabled.
I wonder if customer service has the ability to remotely override for those that get into this situation?
 

dleepnw

Well-Known Member
Joined
May 13, 2021
Threads
148
Messages
3,011
Reaction score
3,417
Location
WA
Vehicles
Rivian, Toyota, Lexus
Clubs
 
MFA better be optional. Not sure how this is being implemented but I can see issues with this if we have problems with coverage, connectivity, software glitch, phone/watch dead/broken, etc.
Sponsored

 
 








Top