Sponsored

Attempted Ford Pass Hack

RalpL

Well-known member
First Name
Ralph
Joined
Sep 9, 2021
Threads
3
Messages
634
Reaction score
574
Location
SW Florida
Vehicles
2022 F-150 King Ranch, 601A, PB, 4x2, AMB/SG
Occupation
Retired
This isn't a "hack". Anybody with a Fordpass account can request access to any vehicle. All they have to do is input the VIN into the app.
I can vouch for what Pioneer74 is saying. I found an incoming F-150 to one of the local dealerships. I took the order number and VIN from the window sticker to enter into tracker software for the latest status. The tracker software then referred to it as my truck. Out of curiosity, I entered the VIN into my FordPass app to see if I could get more info. The app ask me to enable (or words to that effect), which I clicked. After a long waiting time, I received a message that my request was denied. Bottom line - we'll all need to be on guard for malicious activity.
Sponsored

 

MikeG

Well-known member
Joined
Jul 5, 2021
Threads
4
Messages
47
Reaction score
40
Location
West Coast
Vehicles
2021 F-150 XLT
They need rotating 2FA in the truck's settings or something. Sure you should be able to share with another account via email, but that person should have to physically start the truck and input the 2FA code to have access.
 

Orlando150

Well-known member
Joined
Jan 17, 2021
Threads
12
Messages
320
Reaction score
463
Location
Orlando, FL
Vehicles
Ford
They need rotating 2FA in the truck's settings or something. Sure you should be able to share with another account via email, but that person should have to physically start the truck and input the 2FA code to have access.
Or just add an account option to auto decline requests. Most people probably don't use this feature or use it once to add family and then never again.
 

RalpL

Well-known member
First Name
Ralph
Joined
Sep 9, 2021
Threads
3
Messages
634
Reaction score
574
Location
SW Florida
Vehicles
2022 F-150 King Ranch, 601A, PB, 4x2, AMB/SG
Occupation
Retired
Or just add an account option to auto decline requests. Most people probably don't use this feature or use it once to add family and then never again.
That's what I was also thinking. Kind of like telling Facebook, WhatsApp or Skype to decline friend requests, etc.
 

JediNut

Well-known member
First Name
Emmett
Joined
Aug 4, 2021
Threads
31
Messages
360
Reaction score
326
Location
Nashville, TN
Vehicles
'21 Ford F-150 Lariat PowerBoost
Occupation
Old Time Geek
My old supervisor used to have a sign on his wall that said “I drink because your password is password”
In all seriousness there’s a reason most secure sites force passwords changes. Good password hygiene will keep you better protected. Use a password keeper or a revolving password naming convention Also if possible always enable two factor authentication. something you know (password) something you have (cell phone). Not 100% safe but nothing is.
Cyber bad actors want your user name and passwords and use very clever phishing scams to trick you into providing.
Banking and email credentials are at top risk. If you use the same password over multiple platforms they are all at risk.
<begin password security lecture>
Good advice... especially the "password keeper" recommendation. I do not know 90% of my passwords, I don't have to. I use 1Password and have it generate a long, random string for all my passwords. It will also keep an eye out for any sites that get compromised for which you have saved a password. Like I said, I use 1Password, but there are others... for work we use LastPass (but I don't particularly care for it.)

One thing to note... the recommendation now is NOT to change your passwords on a regular basis. Pick a really good, secure password (or have your password manager generate one for you) and keep it. Change it only if needed, i.e. the site where you use that password was compromised (why you use different passwords everywhere). Continually changing a password leads to (1) bad passwords because you tend to make ones that are easier to remember, or (2) an unencrypted "notepad" file or piece of paper with passwords written down.
<end password security lecture>

Sorry if this sounded condescending to anyone... it wasn't meant to call anyone out. I'm just offering some advice from someone who has been in the business for 30+ years.

Stay safe out there!
 

Sponsored

MikeG

Well-known member
Joined
Jul 5, 2021
Threads
4
Messages
47
Reaction score
40
Location
West Coast
Vehicles
2021 F-150 XLT
Or just add an account option to auto decline requests. Most people probably don't use this feature or use it once to add family and then never again.
If someone steals your phone or puts malware on it they could still disable that setting on your Ford Pass App and then add themselves. Having a 30 sec rotating 2FA code (like Google Authenticator) on the truck's nav will make it so they have to be physically at the truck.

Just thinking of the most secure option for Ford. I could see a huge lawsuit if a hacker remote starts a vehicle in a garage and someone dies of carbon monoxide poisoning.
 
OP
OP
SonnyDigs

SonnyDigs

Well-known member
First Name
Sonny
Joined
Dec 23, 2020
Threads
8
Messages
802
Reaction score
506
Location
Texas
Vehicles
2021 F150 King Ranch
If someone steals your phone or puts malware on it they could still disable that setting on your Ford Pass App and then add themselves. Having a 30 sec rotating 2FA code (like Google Authenticator) on the truck's nav will make it so they have to be physically at the truck.

Just thinking of the most secure option for Ford. I could see a huge lawsuit if a hacker remote starts a vehicle in a garage and someone dies of carbon monoxide poisoning.
I'm thinking it will only run 10 minutes on remote start.
 
OP
OP
SonnyDigs

SonnyDigs

Well-known member
First Name
Sonny
Joined
Dec 23, 2020
Threads
8
Messages
802
Reaction score
506
Location
Texas
Vehicles
2021 F150 King Ranch
Well they are at it again this morning..

Ford F-150 Attempted Ford Pass Hack Screenshot_20210925-105958_FordPass


Ford F-150 Attempted Ford Pass Hack Screenshot_20210925-110106_FordPass
 
  • Wow
Reactions: 780

JediNut

Well-known member
First Name
Emmett
Joined
Aug 4, 2021
Threads
31
Messages
360
Reaction score
326
Location
Nashville, TN
Vehicles
'21 Ford F-150 Lariat PowerBoost
Occupation
Old Time Geek
In all seriousness there’s a reason most secure sites force passwords changes.
it is no longer considered “best practice” to force people to change their passwords on a regular basis. That actually leads to insecure passwords, because the user has to continually pick a new password that they have to remember. It is Better to force a secure password choice that the user is allowed to keep for a long time and becomes muscle memory.
 

Sponsored


Sbdavis1

Well-known member
First Name
Stephen
Joined
Nov 20, 2020
Threads
4
Messages
124
Reaction score
215
Location
Fayetteville
Vehicles
2010 F150 Lariat ordered 2021 F150 Lariat
Occupation
Financial Planner, Lawyer
I use “FMCSorryAboutYourTruckPleaseSendMeAPmAndIllDoNothing@Always”. Yet to be hacked or helped.
 

Jglew82

Well-known member
First Name
Greg
Joined
Jan 31, 2022
Threads
1
Messages
70
Reaction score
94
Location
DFW
Vehicles
2023 GMC Sierra 1500 AT4
Occupation
Tech lead
I've denied access to mine from someone named "Terry" at 3am 4 times now. Knock on wood, it finally stopped a few months ago. It started right after I purchased mine in January, so I'm guessing they're just inputting a VIN character incorrectly.
 
 




Top