High jacked

BMW i3 Forum

Help Support BMW i3 Forum:

This site may earn a commission from merchant affiliate links, including eBay, Amazon, and others.

Waitingi3

Active member
Joined
Jan 24, 2013
Messages
27
Location
Tucson Arizona
I read an excellent write up on experiences living with a Leaf for a week and I offered the author the loan of my i3 for a week to compare the two. Brian did an interesting review, see it at:

crazedkeebler.wordpress.com

This raised a disturbing security issue for me. Brian tried to add himself as a secondary user to my iRemote account but ended up creating a new account for himself which referenced my car.

I got an email from BMW saying in effect " We removed your i3 from your account. iRemote is wonderful. Enjoy using it". Brian and I laughed about this, but it seems to me that it is possible to start an account, enter someone's vin and take possession of the vehicles data reporting.

Comments? :shock: Jeff
 
When I took my test drive i3 out for two days I had my phone linked to the car. For a couple of weeks after I regularly checked on the car but resisted the temptation to wind the windows down or to flash the lights. I deleted the app to avoid the temptation after that.
 
Waitingi3 said:
I read an excellent write up on experiences living with a Leaf for a week and I offered the author the loan of my i3 for a week to compare the two. Brian did an interesting review, see it at:

crazedkeebler.wordpress.com

This raised a disturbing security issue for me. Brian tried to add himself as a secondary user to my iRemote account but ended up creating a new account for himself which referenced my car.

I got an email from BMW saying in effect " We removed your i3 from your account. iRemote is wonderful. Enjoy using it". Brian and I laughed about this, but it seems to me that it is possible to start an account, enter someone's vin and take possession of the vehicles data reporting.

Comments? :shock: Jeff

I'm not a big fan of i Remote either, but I'm surprised you managed to do that. I remember that I had to register with BMW i before I was able to use the i Remote. How did you manage to set up a secondary user? In any case, I guess the confirmation email you received should alert users and contact BMW i immediately if the transfer was not authorised. Even better, the old owner should authorise such a transfer, ideally.

As an aside, I actually received this email once. It happened when BMW i's Connected Drive changed user IDs to email addresses - this happened about 4 months ago and freaked me out at first.

Overall, it is pretty clear to see that BMW currently hasn't got the same Silicon Valley DNA such as Tesla. However, this will come over time. BMW events like the recent #HackTheDrive (invitation-only SF hacker event for i vehicles) show that the bavarians are catching up.
 
Back
Top