Closed buzurk26 closed 5 months ago
I don't believe anyone has had their account locked out since the poll rate was changed. However best practice would be to create a new fordpass account and Invite/share your car with it. That way you have a separate account for this integration.
@itchannel funny you mention that... I woke up this morning to an email from Ford today saying that my account had been suspended:
To help protect your personal information and vehicle, your Ford account has been suspended due to either suspicious activity or a violation of our Terms and Conditions.
Your account will remain suspended until you take action. To reactivate your account or if you believe this was done in error, please call Ford Customer Service at 1‑800‑392‑3673.
Luckily this is a second account that I made just for this integration, and it has only ever been used for this integration (aside from when I created it and shared my car over to it which I did from my phone). The integration has been up and running with no concerns from Ford ever since I set up the integration, I can't remember when that was, but it has been months, likely 6+
I'll give them a call after my work meetings and see what they say the reason is for them having disabled it.
I'm on the phone with them now, once they were able to locate the account that was suspended, the customer support/guide checked with another team and when he came back, he asked directly if I was using "Home Assist" (close enough to Home Assistant for me). I clarified to him that I have not provided my account information to any third parties, that this is a self-hosted application and the only person that has access to those credentials is me.
@itchannel can you confirm for my own sanity that the APIs that this integration uses are the ones documented at https://developer.ford.com/apis ?
EDIT: Ford is telling me that they will not be unbanning this account because it uses a "fake email address". I am using a gmail account and gmails "plus sign" feature. Normal gmail addresses are username@gmail.com and you can also use username+whateveryouwant@gmail.com and it will still be delivered to the same username@gmail.com address. According to Ford this is not a "real email address" and therefore the account is fake and has been banned. I am trying to speak with a supervisor about this, because an email address that they can email, and I can receive that email, is obviously not fake.
TL;DR: The integration appears to still be safe to use, but make sure you don't have any special characters in your email address, especially a plus sign, because Ford thinks that means it's a disposable email address.
Here is the final word from Ford. I was able to speak with a supervisor, who said that they will unban the account, which will take up to 48 hours to happen, and I should get an email when it is unbanned. Then I will have 48 hours to change the email address. The thing that flagged the account was NOT the API usage, it was the fact that the email address has a + in it, which tripped their filter for a "disposable email address".
You may want to add a note to the README that having a + in your email address (for example if you use gmails plus addressing feature), can cause your account to be banned. You may even want to have this fail input validation when configuring the integration as Ford told me directly that having a plus sign in the email address matches the filter for a disposable email address and will result in a ban.
I did explain to them that this is not a fake or disposable email address, which is evident by the fact that I received the email that they sent informing me that the account had been blocked, and the supervisor on the phone understood that I was basically an "innocent bystander" of their email filter. I did explain to them how this is a valid character and that he should bring this up with whoever is in charge of that filter, because they are going to suspend perfectly valid accounts if they have their filter set up like this.
For now, I wait to have my account unbanned, then I will change the account to use a completely new and separate email address that is not using plus addressing with gmail.
@cryptk Interesting read. Good to hear it's not the API causing you issues. But interesting they've suddenly implemented an email filter I can't think fake emails are a big thing with Fordpass but I do have a suspicion the IBM backend software isn't just used for Fordpass.
I will add a bit to the readme on the next release just to advice people 👍
I just had my account banned as well, and it contained a +
sign. Glad to have found this thread!
Samen issue here. I've also used the + in the email address and the account got locked 4 days ago. Looks like they startend (enforcing) this policy then.
I had the same, however I managed to get it activated again. I've contacted the customer service, and after some explanation plus verifying my vehicle VIN, they reinstated my account :)
@itchannel funny you mention that... I woke up this morning to an email from Ford today saying that my account had been suspended:
To help protect your personal information and vehicle, your Ford account has been suspended due to either suspicious activity or a violation of our Terms and Conditions. Your account will remain suspended until you take action. To reactivate your account or if you believe this was done in error, please call Ford Customer Service at 1‑800‑392‑3673.
Luckily this is a second account that I made just for this integration, and it has only ever been used for this integration (aside from when I created it and shared my car over to it which I did from my phone). The integration has been up and running with no concerns from Ford ever since I set up the integration, I can't remember when that was, but it has been months, likely 6+
I'll give them a call after my work meetings and see what they say the reason is for them having disabled it.
so you made another account ? how i do that ? just use another phone, install app , sign up and link the vin ?
My account doesn't have a plus sign just my email and it doesn't work anymore....
I there a way to change account information for the integration? I want to use a different account, but do not want new entities.
Will you still be banned with the new API?
Hi,
I want to start using this integration but read many reports of people saying their account got locked out
Is there a way to use this, certain settings etc that can aid with not having your account locked?