Sponsored

tate16t

Well-Known Member
First Name
Robert
Joined
Apr 7, 2022
Threads
64
Messages
1,396
Reaction score
1,181
Location
NY
Vehicles
2023 El Cap Granite R1S
Occupation
Car Enthusiast
Starting December 13, 2024, Rivian is rolling out two-factor authentication (2FA) for all customer accounts. That means when you log into your Rivian account or app, you’ll need to verify your identity using two methods – your regular password and a one-time code sent to you. It’s a simple step to keep your personal info and vehicle access extra safe.

If you’re using third-party tools like ElectraFi to monitor or interact with your Rivian, you might run into some hiccups.

https://riviantrackr.com/news/what-rivians-new-two-factor-authentication-means-for-you/
Sponsored

 

COdogman

Well-Known Member
First Name
Brian
Joined
Jan 21, 2022
Threads
33
Messages
11,641
Reaction score
34,494
Location
CO
Vehicles
2023 R1T
Occupation
Cyber defender
Clubs
 
Is this Rivian's way (at least) to try kill third party tools?
MFA really should be the minimum standard on all accounts these days. Using it makes your account at least 99% less likely to be compromised.
 

electruck

Well-Known Member
Joined
Oct 6, 2019
Threads
74
Messages
4,155
Reaction score
7,728
Location
Dallas, TX
Vehicles
2023 Rivian R1S
This has been optional for about 3 years now, I think. Glad to see they're making it mandatory, I know it's something I enabled when it was first implemented. Hopefully they'll add support for push notifications and passkeys in the near future.
 

godfodder0901

Well-Known Member
First Name
Jared
Joined
Mar 12, 2019
Threads
27
Messages
5,748
Reaction score
10,138
Location
Washington
Vehicles
2022 Rivian R1T LE
Is this Rivian's way (at least) to try kill third party tools?
No. Many work with MFA. I have it set and still use the HA integration.
 

Sponsored

beatle

Well-Known Member
Joined
Jun 20, 2024
Threads
17
Messages
1,143
Reaction score
1,561
Location
Springfield, VA
Vehicles
'23 R1T PDM Max, '97/'25 Miatas, '19 Monkey
Occupation
IT
Clubs
 
Is this Rivian's way (at least) to try kill third party tools?
Third party tools work on tokens, so as long as you can still get a token, you should be good. Tesla uses 2FA as well, and 3rd party tools like TeslaFi work fine.
 

godfodder0901

Well-Known Member
First Name
Jared
Joined
Mar 12, 2019
Threads
27
Messages
5,748
Reaction score
10,138
Location
Washington
Vehicles
2022 Rivian R1T LE
I work in infosec and I'm really glad they're enforcing this. Seen too many compromises.
Same, but wish they implemented TOTP through an authenticator app instead of the much less-secure version they've chosen using SMS or email.
 

lefkonj

Well-Known Member
First Name
Jeff
Joined
Feb 6, 2021
Threads
37
Messages
1,445
Reaction score
2,594
Location
New Jersey
Vehicles
Gen2 R1S Tri, I4-m50
Clubs
 
they are requiring it, I have had this since day 1 on my account.
 

Sponsored

ElGuano

Well-Known Member
Joined
Oct 9, 2024
Threads
47
Messages
851
Reaction score
1,198
Location
Cali
Vehicles
R1T Trimax - Storm Blue, Driftwood, Sport Dark
I appreciate the extra security, but sites that over-enforce this (I feel Rivian does, as does Garmin) create huge usability headaches. It doesn't seem to preserve sessions on trusted devices and times out frequently, so if I have the site open, and refresh 10min later, I have to get another 2FA code. Ugh.

My Google account, which I care a hell of a lot more about, does a good job balancing first-class security with not prompting for a 2FA every time I refresh my browser window.

At least for Rivian, the app seems to have a refresh token that bypasses 2FA when you use it to log into the site to check pre-order status!
 
Last edited:

Greg Chick

Well-Known Member
First Name
Greg
Joined
Jan 27, 2023
Threads
12
Messages
914
Reaction score
652
Location
Tehachapi Ca. 93561
Website
diyplumbingadvice.com
Vehicles
R1T Quad, large battery, 21" Adventure
Occupation
Retired Plumbing Contractor
Clubs
 
So using your cell phone as a key and if your cell turned off while you were away from truck, a 2FA will be needed to open the door to the truck? Or is this just to drive the truck, or acess the app to do things?
 

ElGuano

Well-Known Member
Joined
Oct 9, 2024
Threads
47
Messages
851
Reaction score
1,198
Location
Cali
Vehicles
R1T Trimax - Storm Blue, Driftwood, Sport Dark
So using your cell phone as a key and if your cell turned off while you were away from truck, a 2FA will be needed to open the door to the truck? Or is this just to drive the truck, or acess the app to do things?
I think...neither? I believe the phone communicates with the truck directly through Bluetooth/UWB for PaaK, so no cloud/login needed. And the mobile app doesn't use 2FA (presumably it relies on your device unlock as security). So this should only be for the rivian.com site, right?
 

godfodder0901

Well-Known Member
First Name
Jared
Joined
Mar 12, 2019
Threads
27
Messages
5,748
Reaction score
10,138
Location
Washington
Vehicles
2022 Rivian R1T LE
So using your cell phone as a key and if your cell turned off while you were away from truck, a 2FA will be needed to open the door to the truck? Or is this just to drive the truck, or acess the app to do things?
It's for logging into/authenticating your account. You won't need to do anything different to drive.
 

JonW716

Well-Known Member
First Name
Jon
Joined
Apr 1, 2024
Threads
10
Messages
120
Reaction score
111
Location
Lithia, Florida
Vehicles
2023 Model S Plaid, 2023 Durango SRT Hellcat, 2015 ZX14R
Occupation
Armorer
As a former victim of identity theft, it's been enabled on my account since inception. With all the current crap going on with identity theft it's better to be proactive then reactive... Once you've been compromised you know what a pain in the ass it can be to get all your stuff fixed, not to mention the credit hit you can take while it is all being fixed. A PIN code to drive the car would be a welcome addition for an extra layer of security.
Sponsored

 
 








Top