Welcome to Tesla Motors Club
Discuss Tesla's Model S, Model 3, Model X, Model Y, Cybertruck, Roadster and More.
Register

Security Vulnerability - Tesla iOS app. If Tesla credentials got compromised, and someone connected to a car using an iOS Tesla app, it will not be

This site may earn commission on affiliate links.
#SecurityAlert - Tesla iOS app.

If Tesla credentials got compromised, and someone connected to a car using an iOS Tesla app, it will not be possible to disconnect mobile devices with the Tesla app that had been previously connected, if password is changed after the fact, and even if 2FA is activated. So someone can continue to access and control your car unless you disable mobile access for ALL devices.

Tesla was notified on August 4th, 2021. No update so far.

Steps to recreate the issue:
1.Install the Tesla iOS mobile app and login with current credentials
2.Change password and/activate 2FA
3.Turn off mobile access
4.Turn on mobile access back
The app will get automatically reconnected without requiring to enter new credentials.

See more at
https://twitter.com/Entrespace.../status/1424908699370463232
 
  • Helpful
Reactions: mkrc99
This is issue has been around for a long time, I think it’s being fixed in API version 14 though. The auth tokens issue for the mobile apps don’t have any TTL, I was surprised by this. I suppose, they chose this route because they wanted a friction less expensive?