Welcome to Tesla Motors Club
Discuss Tesla's Model S, Model 3, Model X, Model Y, Cybertruck, Roadster and More.
Register
  • We just completed a significant update, but we still have some fixes and adjustments to make, so please bear with us for the time being. Cheers!

Carmiq

silentcorp

Member
Jul 20, 2018
513
667
Denver CO
Nope, I'm not giving a 3rd party my login information to my car for any reason. There are already a few alternatives out there that have a track record, I'd recommend going with them if you are willing to give up your credentials.
 
  • Like
Reactions: TexasEV and bd7349

gaswalla

Model S,3,X.. CT with Austin delivery
Sep 23, 2012
3,250
3,520
San Diego
Honestly - it sounds like a scam. Probably isn't, but what's in it for the folks that set all of this up?
 

haydn

New Member
Feb 18, 2019
2
8
Los Angeles
Hey everybody, thanks for your interest in Carmiq. I'm Haydn, one of the co-founders. Of course, user security is a paramount consideration of ours. The authorization process is a standard 'OAuth' that is hosted on Tesla servers. Therefore, we never have access to view/store the Tesla account credentials. When you input your account credentials, we receive the same token that provides temporary and limited access to the account. This is the same process used when you sign up to a site using Facebook or Google. While allowing users to input a token is a possibility, doing so does not actually provide any security advantages and requires users to generate their own token (through a different third-party site).

Many of Carmiq's features rely on individual data from users' Teslas, which is why we require this information to sign up. All vehicle API calls are done through the official Tesla fleet API's, which we have been granted a license to use. Furthermore, all features/data-sharing must be explicitly opted in to by the user. Carmiq will never spam you with ads for services or share your data without your permission.

If anybody has any additional questions, please respond below or direct message me and I'll be happy to answer.
Thanks!
 

focher

Member
Oct 15, 2013
991
1,435
Bay Area
The authorization process is a standard 'OAuth' that is hosted on Tesla servers. Therefore, we never have access to view/store the Tesla account credentials. When you input your account credentials, we receive the same token that provides temporary and limited access to the account. This is the same process used when you sign up to a site using Facebook or Google.
That’s very helpful information. I would, however, recommend switching to Tesla’s own authentication window just as Google and even Facebook do when using their login process to obtain a token. It would just be more secure as CARMIQ can never be accused of “holding” the user’s Tesla account password, even if for the brief initial OATH session. It also would give more comfort to those who do not want to - even briefly - hand over their password.
 

Runebane

Member
Jul 12, 2018
282
231
Visalia, CA
That’s very helpful information. I would, however, recommend switching to Tesla’s own authentication window just as Google and even Facebook do when using their login process to obtain a token. It would just be more secure as CARMIQ can never be accused of “holding” the user’s Tesla account password, even if for the brief initial OATH session. It also would give more comfort to those who do not want to - even briefly - hand over their password.

Definitely this. Or, let the user get their own token to give you like other Tesla apps do.
 

haydn

New Member
Feb 18, 2019
2
8
Los Angeles
Thanks for the feedback. Unfortunately, Tesla has not yet developed its own authentication window yet. However to clarify, allowing users to input their own tokens would not increase security. When somebody enters the credentials on the page, they are saved in local memory until the form is submitted. At that point, it is sent to Tesla which verifies and grants/denies the token. At no point is the information accessible by Carmiq. Therefore, allowing users to input their own token adds friction while creating a misleading narrative that inputting the token is more secure.
 
  • Like
Reactions: CullinKin

MentalNomad

Member
Dec 6, 2018
354
395
USA
However to clarify, allowing users to input their own tokens would not increase security.

You're neglecting the fact that without being allowed to enter their own token, the user feels insecure.

YOU may know that your code doesn't store the user credentials, but the user does not.

YOU may know that your code receives and uses a token, but the user does not.
 

smatthew

Active Member
Jun 9, 2018
1,227
2,037
CA Bay Area
Many of Carmiq's features rely on individual data from users' Teslas, which is why we require this information to sign up. All vehicle API calls are done through the official Tesla fleet API's, which we have been granted a license to use. Furthermore, all features/data-sharing must be explicitly opted in to by the user. Carmiq will never spam you with ads for services or share your data without your permission.

Tesla granted you a license to their API?
 

derotam

Member
Oct 31, 2018
818
695
Oak Hill, VA
So I read the main page for Carmiq but all I interpreted from it was I sign up, I "selectively share my vehicle data" which I just read as you sell my data to who I say you can sell it to. I miss some some great user value somewhere?
 

ngogas

Active Member
Sep 19, 2018
1,725
1,106
Utah
Glad to see you are using OAuth for authentication and token. I wouldn't support allow user to upload a token. Insecure....
 

MentalNomad

Member
Dec 6, 2018
354
395
USA
I signed up about 2 weeks ago. Unsure about the value, yet. May still revoke the tokens if I don't see info worth having. Definitely not there yet, but I'm looking forward to getting range/battery data, so I'm willing to share data to the analysis pool, for now.

upload_2019-5-10_16-41-15.png
 

About Us

Formed in 2006, Tesla Motors Club (TMC) was the first independent online Tesla community. Today it remains the largest and most dynamic community of Tesla enthusiasts. Learn more.

Do you value your experience at TMC? Consider becoming a Supporting Member of Tesla Motors Club. As a thank you for your contribution, you'll get nearly no ads in the Community and Groups sections. Additional perks are available depending on the level of contribution. Please visit the Account Upgrades page for more details.


SUPPORT TMC
Top