Sponsored

EVGO Warning - insecure service

Zoidz

Well-Known Member
First Name
Gil
Joined
Feb 28, 2021
Threads
226
Messages
5,185
Reaction score
11,687
Location
PA
Vehicles
23 R1S Adv, Avalanche, BMWs-X3,330cic,K1200RS bike
Occupation
Engineer
EVGo says they have protection against "impossible charges" where if one is initiated somewhere you couldn't possibly drive to in time, then it flags it. Of course I have never heard of this being demonstrated.

Devices like Keysight's SL1556A do exist, and I believe it's possible to use an inductive coupler over the entire cable to sniff the data due to the way PLC works.
I'm not sure how they could they reliably accomplish that "drive to in time" feature? I can see that working if there was a transaction in Pennsylvania and then 20 minutes later one in Colorado. But if someone is collecting multiple MACS and using them once a week at the same or nearby chargers within 20 - 50 miles, I think the odds are pretty good it might go undetected. Oh snap, AI will certainly solve that problem, lol. AI is the solution to everything, right?
Sponsored

 

connoisseurr

Well-Known Member
First Name
Connor
Joined
Oct 1, 2022
Threads
25
Messages
926
Reaction score
1,322
Location
Northern VA
Vehicles
22 R1T, 23 MYP
Occupation
I encrypt PDFs for Boomers
Clubs
 
Didn't know DCFCs are based on AI and had emotions... you know, being insecure about how unsecure they are...

Title needs to be updated: unsecure, not insecure.
 

Electrified Outdoors

Well-Known Member
First Name
Ken
Joined
Jan 30, 2023
Threads
63
Messages
3,683
Reaction score
3,980
Location
Mount Airy, Maryland
Website
EVoutdoors.org
Vehicles
2024 Rivian R1S Quad, 2024 Silverado EV RST First Edition
Occupation
Real Estate
Clubs
 
Man that's not good! Hopefully they are refunding you. Sounds like you may need to close that account and open a new one.

I wonder if it would be better to use a virtual credit card instead of your real card number? VCC are nice because you can set limits and turn them off and on easily to prevent fraudulent charges.
 

Christopher

Well-Known Member
First Name
Christopher
Joined
May 31, 2022
Threads
34
Messages
583
Reaction score
573
Location
South Florida
Vehicles
R1T
Occupation
Tech
Clubs
 
I'm not tracking how this relates to being a vulnerability or not PCI compliant.

Sure there may be a bug with the EVgo app but somebody calling this a vulnerability??
 

Oldsmobile_Mike

Well-Known Member
First Name
Mike
Joined
Mar 24, 2022
Threads
62
Messages
2,406
Reaction score
3,869
Location
Manassas Park, VA
Vehicles
FG/FE R1T recv'd 3/31/2023
Occupation
I build stuff
Clubs
 
Ah. The EVgo employee has arrived. My post is only to warn users of the risks. Blaming the users for your insecure service is a bad look.
I was going to say the same thing after reading their first couple sentences. What a shill. ?
 

Sponsored

Zoidz

Well-Known Member
First Name
Gil
Joined
Feb 28, 2021
Threads
226
Messages
5,185
Reaction score
11,687
Location
PA
Vehicles
23 R1S Adv, Avalanche, BMWs-X3,330cic,K1200RS bike
Occupation
Engineer
Didn't know DCFCs are based on AI and had emotions... you know, being insecure about how unsecure they are...

Title needs to be updated: unsecure, not insecure.
Sorry, I could not resist this one...
Rivian R1T R1S EVGO Warning - insecure service 1693233110646
 

shandel

Well-Known Member
Joined
Jul 20, 2022
Threads
6
Messages
252
Reaction score
201
Location
Half Moon Bay, CA
Vehicles
R1S FG/FE Adventure 20, Audi e-tron, Jeep Wrangler
Clubs
 
I had a similarly strange experience with an EA charger in South Lake Tahoe this weekend. I pulled up to the 350kwh charger and tried to get set up for charging. The charger said initiating charge but never started. Another Rivian pulled into the other 350kwh charger and got plugged in. I tried unplugging and plugging in and initiating the charge again. It's didn't work. In the meantime, his did start charging. I moved my Rivian over to the 150kwh charger next to his and tried to get set up there. I then noticed the screen where he was charging said "Hi, [my name]". I looked in my app and it said I was charging. I stopped the charge from my app and his Rivian stopped charging.

So, there is either something very screwed up at that local EA charger where the terminals are somehow miswired or they have some other bigger issue. Either way, there is a similar problem to what is described here with evGo.
 

prestapost

Well-Known Member
Joined
Mar 28, 2021
Threads
18
Messages
236
Reaction score
433
Location
Pullman, WA
Vehicles
2019 RAM 1500, 2022 Rivian R1T
Ah. The EVgo employee has arrived. My post is only to warn users of the risks. Blaming the users for your insecure service is a bad look.
Honestly, if we are wondering who is the shill… one of you has started 25 threads and posted 4500 times. The other has one thread. Maybe you work for an EVgo competitor?!? ;)
 

Zoidz

Well-Known Member
First Name
Gil
Joined
Feb 28, 2021
Threads
226
Messages
5,185
Reaction score
11,687
Location
PA
Vehicles
23 R1S Adv, Avalanche, BMWs-X3,330cic,K1200RS bike
Occupation
Engineer
I'm not tracking how this relates to being a vulnerability or not PCI compliant.

Sure there may be a bug with the EVgo app but somebody calling this a vulnerability??
I had similar experiences with their support and the fact that the “backoffice” had to fix things, but I’ve yet to hear about it. I was scouting an EVGO charger *on their website* that was 100s of miles away for an upcoming roadtrip and noticed it said “autocharge, learn more”. I clicked that and it immediately said “plug in your vehicle to activate autocharge” with no way to cancel out of it. Well…as you can guess, someone plugged in during that time and their car got paired to my account. I’ve spent a collective total of two hours on the phone with their crappy support trying to get the car unpaired (which still isn’t done) and their charges refunded. This should **never** be allowed to happen. It’s poorly designed.
I guess it could be argued it's not a vulnerability per se, but IMO it is subject to PCI scrutiny because they allow the association of an unknown/unverified network device with the user account data. Some sort of MFA would prevent this.

Rivian R1T R1S EVGO Warning - insecure service 1693233334388


Rivian R1T R1S EVGO Warning - insecure service 1693234225266
 

HaveBlue

Well-Known Member
Joined
Nov 22, 2022
Threads
41
Messages
2,926
Reaction score
2,234
Location
91107
Vehicles
R1S DMP Max, Lifted GX470, APR Audi A7, BMW 325Ci
Clubs
 
Always good to have a separate throw away cc that you don't mind cancelling since there is no way to control how a third party will handle the info.
 

Sponsored

Throwdown

Well-Known Member
Joined
Mar 14, 2023
Threads
0
Messages
422
Reaction score
487
Location
Colorado
Vehicles
R1t launch edition#2650
Occupation
Technician
I would only use them in general if there were no others, they are the priciest stations I've ever been to. Last one I was at was .50 per kwh with a $9.99 session fee, no thanks
 

UnsungZero_OldTimeAdMan

Well-Known Member
First Name
Barnum
Joined
Mar 20, 2023
Threads
66
Messages
8,541
Reaction score
11,727
Location
SoCal
Vehicles
'23 GW Quad-Large R1T "Ghost"
Occupation
Advertising Circus
I would only use them in general if there were no others, they are the priciest stations I've ever been to. Last one I was at was .50 per kwh with a $9.99 session fee, no thanks
Can't believe I'm saying this... they make EA look good.
 

RivianMatt

Well-Known Member
First Name
Matt
Joined
Feb 1, 2023
Threads
21
Messages
147
Reaction score
274
Location
Marin County, CA
Vehicles
2025 Rivian R1S, 2012 BMW 528i and 2026 Tesla M3
Occupation
Banking
Clubs
 
As someone who will have his very first EV (an R1S) hopefully within two weeks, so I don't have any experience with the charging network yet. But relative to the security of credit card numbers, I would hope that the charging networks are set up to accept systems such as ApplePay, by which the merchant doesn't actually ever get our specific credit card numbers. Is that not the case?
 

azbill

Well-Known Member
First Name
Bill
Joined
Jun 8, 2020
Threads
17
Messages
1,695
Reaction score
1,976
Location
Arizona
Vehicles
Escalade IQ, Mach E, Hummer EV SUT
Occupation
Retired
I had a similarly strange experience with an EA charger in South Lake Tahoe this weekend. I pulled up to the 350kwh charger and tried to get set up for charging. The charger said initiating charge but never started. Another Rivian pulled into the other 350kwh charger and got plugged in. I tried unplugging and plugging in and initiating the charge again. It's didn't work. In the meantime, his did start charging. I moved my Rivian over to the 150kwh charger next to his and tried to get set up there. I then noticed the screen where he was charging said "Hi, [my name]". I looked in my app and it said I was charging. I stopped the charge from my app and his Rivian stopped charging.

So, there is either something very screwed up at that local EA charger where the terminals are somehow miswired or they have some other bigger issue. Either way, there is a similar problem to what is described here with evGo.
I charged at that site several times last week, including Saturday, with no issues. Are you 100% sure you did not select the wrong charger number in the app? I always swipe the app first, then wait for the charger screen to tell me to plug in. EA told me a long time ago to do that way, even though the stupid screen states "plug in first".
 

prestapost

Well-Known Member
Joined
Mar 28, 2021
Threads
18
Messages
236
Reaction score
433
Location
Pullman, WA
Vehicles
2019 RAM 1500, 2022 Rivian R1T
The problem with charging networks isn’t credit card theft, despite the unhinged post that started this thread. The problem is inconsistency in how they work, likelihood of user error, and broken chargers.

Even though this thread seems like it’s about credit card security and pci compliance, it’s really about usability. You’ll probably love your EV, but you’ll also probably have some frustrating moments at a public charger. Most of us are just glad we can do the vast majority of our charging at home
Sponsored

 
 








Top