Important Security Changes

NOTE: We STRONGLY recommend upgrading to Internet Explorer 11 or Safari 8 to avoid having to make subsequent changes as new security vulnerabilities are found. Effective May 27th support is removed for TLS v.1.0 and 1.1. Please ensure you are using the latest web browser.

 

In lieu of recent events, the wiTECH 2.0 application is undergoing changes to enhance the security stance of the diagnostic system. Some changes may not be convenient, but are completely necessary to protect the application and vehicles being serviced from being vulnerable to potential exploits. It is also important to understand that wiTECH 2.0’s security has a much higher priority because it is a cloud application operating on the Internet. The following list will help you understand some of the upcoming and already implemented security changes.

1: Splitting microPOD Use with wiTECH 1.0 and wiTECH 2.0

Because wiTECH 1.0 and wiTECH 2.0 have completely different infrastructures, it was necessary to separate the operating systems for the microPOD to meet our security model. Maintaining a cross-compatible operating system would result in reducing our security stance. While this may not be convenient, we are asking the dealerships to dedicate resources for the wiTECH 1 and wiTECH 2 applications.  If you have the older VCI Pod, which is not supported by the wiTECH 2 application, this would be a good choice for wiTECH 1. If not, please purchase a microPOD to fulfill this role.

2: Supporting Only Newer, More Secure Browsers

In order to secure the environment, the application will be moving to support only newer, more secure browsers. The following list of browsers will be supported:

-Internet Explorer 10*
-Internet Explorer 11+
-Safari 7+
*Internet Explorer 10 will not be compatible by default, but can be configured. We strongly recommend upgrading to Internet Explorer 11, but you can learn how to configure Internet Explorer 10 at the following article: Configuring Internet Explorer 10 to Use TLS 1.2.

For those using other browsers, which are not officially supported by wiTECH 2, the browser must support TLS 1.2 protocol.

3: Supporting Only the More-Secure HTTPS

Additionally, we are moving to use ONLY a secure hypertext transfer protocol (HTTPS). By default, browsers use HTTP, and the wiTECH 2.0 application will no longer support HTTP. This means that HTTPS must be specified in the URL when navigated to the website. For example, login.fcawitech.com will not work whereas https://login.n.fcawitech.com  will work. We strongly recommend that you update your bookmarks to a URL specifying HTTPS in order to facilitate this change in the near future.

4: Allowed Domains

The following domains must be whitelisted and accessible in order to use the wiTECH 2.0 application:

-fcawitech.com
-dealerconnect.com

5: Removal of WEP and Unsecured Open Wi-Fi.

In the upcoming months, the microPOD will no longer support older security protocols when connecting to Wi-Fi. WEP-based security and unprotected wireless connections will no longer be allowed. Only WPA- based security types will be supported. If you are using the FCA US provided networking equipment, this is already properly configured for you.

Attachments
There are no attachments for this article.
Related Articles RSS Feed
wiTECH Bandwidth Requirements
Viewed 1400 times since Wed, Jun 27, 2018
How do I order a wiTECH Diagnostic Extender microPod II?
Viewed 3491 times since Fri, Sep 1, 2017
How-to Configure a Wireless Profile on a microPOD 2
Viewed 128879 times since Fri, Feb 5, 2016
Video - Knowledge Base did you know
Viewed 417 times since Wed, Apr 3, 2019
wiTECH 1 / DRB III Enhanced Emulator Dealership Requirements
Viewed 4576 times since Fri, Jan 26, 2018
Improving your wiTECH 2.0 Connectivity Video
Viewed 6743 times since Fri, Nov 20, 2015
Account Locked After Too Many Failed Login Attempts
Viewed 729 times since Wed, Jan 16, 2019
Unable to access wiTECH 2.0 when DealerCONNECT site is unavailable
Viewed 7788 times since Wed, Apr 27, 2016
Road Test - How-to
Viewed 20475 times since Thu, Jan 14, 2016