MagicJack has serious security problem. Exposure of the worst kind.

Toddskins

Member
So I just discovered that my new automatic software upgrade on my magicjack has the following problem. If you have one, or are considering getting one, beware.

= = = = = =

With MJ new software, they slipped in a new "feature" that is a horror. Located in the advanced users, selecting "My Magicjack" will automatically take the person to your personal account on the web WITHOUT asking for a password!!!!

I chatted with MJ customer support and this was confirmed. I am posting the conversation below.

In short, if you have registered another MJ for your son or daughter away at school, any of their friends can gain access to you, the parent's, account information. That includes your address, email address, ability to change password, complete telehone call list history, access to all your private features, etc. Likewise, it is also possible that if you have guests at your house and you need to run outside, or downstairs, they can gain access to all your personal and private information too, simply by clicking the My Magicjack selection in the front of the software. No Password required. There is NO WAY to fix this! The older software did not do this, and when they "upgraded" the software for you, they also exposed you to an atrocity of risk. If you have sent a MJ to a friend or relative in a foreign country, you are completely exposed!!!

= = = = = = = =

Please wait for a site operator to respond.
You are now chatting with 'Lira'
Your Issue ID for this chat is *************8X Lira: Hello, how may I help you?
Todd: Hi Lira, when I log into the My Magicjack from the menu of the software, it automatically puts me into my account WITHOUT asking for a password! How can I turn that off for security purposes?
Todd: hello?

Lira: I see.
Lira: So you clicked on the "MY" on the dial pad right?
Todd: NO
Todd: I click the button "Menu", and from that list are several... one being the "My Magicjack"

Lira: Thank you for the information.
Todd: When I click that, it takes me to the web and automatically logs me into my account
Todd: And I never put in a password!!!

Lira: I am sorry to inform you that it will automatically login to the magicjack account with out using the password since the dial pad is already online it would just directly login without asking the password.
Todd: that cannot be! Who made this decision? Anybody that walks up to my computer, can gain access to everything private and personal!!!
Lira: However our engineers have noted this issue since there are some customer having the same issue.
Todd: All my record of phone numbers, my address, everything!
Todd: This needs to be fixed today.

Lira: And hopefully they will add some modifications in the magicjack.
Lira: If you don't want anyone to access your account.
Todd: OF course I don't.
Lira: All you have to do is sign out the magicjack dial pad and activate the forwarding feature once you are not around in your house.
Todd: And if i go downstairs and friends are visiting, I have no way of knowing if they click my account, when i am not in the room!
Todd: No, your suggestions are no good.
Todd: This is too critical to be such a major gaff as it is.
Todd: How do you sign out of the dial pad? I don't know what you mean by that.

Lira: I know it is very critical.
Lira: All you have to do is click on MENU > Sign out.
Todd: that is not a command in my menu
Lira: Please click on MENU in the dial pad.
Lira: Please inform me what you see in there?
Todd: I don't see it. My "Menu" is located in the top right, above my contacts list.
Todd: above the dial pad is END and SEND
Todd: above that is MY.... AMAZON.... YAHOO
Todd: Anyway, that is not a solution.

Lira: The MENU button is at the top left of the dial pad
Todd: I need to speak with your top manager on this, because this nees to be fixed, like Yesterday.
Lira: One moment please...
Lira: I am transferring you to one of our top 10% agents as rated by our customers. Please hold while I transfer you.
Todd: ok
Please wait while I transfer the chat to the best suited site operator.
You are now chatting with 'Riona'
Your Issue ID for this chat is ************8X

Riona: Hi, this is Supervisor Riona and I will be assisting you for today. Please let me read your past conversation with the other agent. Thank you so much!
Todd: ok
Riona: Thanks
Riona: Let me inform you if your magicjack is plugged in on your computer then anyone can log in into your magicjack account there is no password which need to verify.
Todd: I know that!
Todd: That needs to be fixed, NOW!
Todd: So my son has a magicjack at college, and now all his buddies and fraternity guys can gain access to his dad's account info.!!!!

Riona: Let me inform it is not an issue with the magicjack device
Todd: That is a horror!
Todd: what do you mean?

Riona: If you do not want to use magicjack with any other person then you can keep your device with you all the time
Todd: but that is not what you advertise, and that is not how people use this!
Todd: We buy additional devices, register them, and we expect basic security and privacy, but you have blown it!!!!
Todd: And anybody in my house can gain access, if i go downstairs, go outside, leave the room, etc.

Riona: I am sorry there is no such kind of security
Todd: I could spell out 50 scenarios, all of which are cases for fraud
Todd: There needs to be!
Todd: It did not use to do this!

Riona: Okay I can forward your request from my end
Todd: WHen I first bought my magicjack, this was not an issue. Your upgrade created ths problem.
Todd: This needs to be broadcast on the news. I will send it to CNN, FOX, MSNBC, etc.

Riona: Todd, All the feature are provided by our engineers. If you want to suggest this then I can forward your suggestion from my end only
Todd: do so
Todd: And i will forward to the news, too.

Riona: Sure, Please wait .............
Riona: Mr. Todd, I am done with the report and I have mentioned your suggestion there. I have sent it to our concerned department now they will look into this.
 
While this is a serious problem, your chat transcript really made me laugh! :) I always think it's funny how customer service people react to unhappy customers. Thanks for spreading this info!
 
Dang that sucks...

I lol'd though when you threatened to send it to CNN, NBC, etc. :laughings:


:) Happy to always provide a laugh.

But seriously, I did in fact send that report to the news agencies I said I was going to. This, since MagicJack has been featured by many of those news agencies for PR, and use their logos on the front page of their website. Not to mention the original security gaff (shaking head in disbelief).

So I thought I'd let them know that their PR paid off. They successfully made me aware of which news companies they like to get in bed with. <grin>
 

Attachments

  • MJ.JPG
    MJ.JPG
    51.8 KB · Views: 884
Come to think of it I haven't seen any of their commercials for several days now. They advertise heavily on The Weather Channel, The History Channel, and TV Land.
 
Chief Security Analyst of PC Magazine wrote me back and told me he agreed with me and that it was, to quote "very, very bad". Because he is on the other side of the country from their Labs, he told me he was forwarding the info. to the editor at their Labs with a note from himself.
 
And just when you thought it was safe to go back in the water...... Just unplug it!!!

What you and others just keep failing to understand is that people have been buying these and sending them overseas to their friends, etc., to avoid long distance charges. The other scenarios I wrote about are true, too. If you actually thought about security and how people actually like their information to remain private, you might have accidentally stumbled upon the issue and its simple answer. Implement a password.
 
if someone were concerned about security they would probably invest more than $19.99 a year for phone service.

Not that I think what they did was very smart - and I build software systems so I know it's not that hard to fix it... but I mean - it's not public information - they would have to be on your account or have access to your computer. Someone sneaking into your computer when you were in the bathroom or whatever could probably steal a lot better information than your calling history...
 
All magicjacks that are registered to the same owner, as people have done for their family and friends they wish to speak with long distance, all have access to the account and all the information in it since Magicjack removed the password from any of the devices. And in the account is MORE than just a call history, but that is no small thing. Why do people insist on fighting for the stupid position?

This was explained in the first post. Or if you had a magicjack, you might also understand. Not having read the first post, nor having the device makes me wonder why you bothered to post anything.

The company had security in place at one time, but then undid it altogether.

The price of a device has nothing to do with anything, especially since security used to be in place, but not anymore causing hardship and exposure to people who had counted on security being in place for the past 3 years or so. And you also make it sound like $20 (each and every year) is like nothing. And yet the company has made somewhere around $300 Million since it began just 3 or 4 years ago.

If Levis removes the buttons and zippers from their jeans, and somebody complains about it, your response is on a par with "Why complain? Just use a stapler if you're really concerned about keeping jeans closed."
 
lol @ anyone buying a MagicJack. I suppose you bought a Slap-Chop and a few Snuggies too? Maybe a few Bedazzlers? A Garden Weasel?
 
...If Levis removes the buttons and zippers from their jeans, and somebody complains about it, your response is on a par with "Why complain? Just use a stapler if you're really concerned about keeping jeans closed."

Now, there is a REAL "privacy" issue! :D
 
Al
If Levis removes the buttons and zippers from their jeans, and somebody complains about it, your response is on a par with "Why complain? Just use a stapler if you're really concerned about keeping jeans closed."

It's not like that at all. Buttons and zippers are functional items on the jeans. They need to be there. Your MagicJack will work fine with no security.
 
All magicjacks that are registered to the same owner, as people have done for their family and friends they wish to speak with long distance, all have access to the account and all the information in it since Magicjack removed the password from any of the devices. And in the account is MORE than just a call history, but that is no small thing. Why do people insist on fighting for the stupid position?

This was explained in the first post. Or if you had a magicjack, you might also understand. Not having read the first post, nor having the device makes me wonder why you bothered to post anything.

The company had security in place at one time, but then undid it altogether.

The price of a device has nothing to do with anything, especially since security used to be in place, but not anymore causing hardship and exposure to people who had counted on security being in place for the past 3 years or so. And you also make it sound like $20 (each and every year) is like nothing. And yet the company has made somewhere around $300 Million since it began just 3 or 4 years ago.

If Levis removes the buttons and zippers from their jeans, and somebody complains about it, your response is on a par with "Why complain? Just use a stapler if you're really concerned about keeping jeans closed."

I read the first post and all the rest of them - I have 4 magic jacks sitting unused in a box somewhere cause they suck - I used them for my customer service people to do phone support when I didn't want to add phone lines - the service is spotty, intermittent, drops calls, calls don't get through, non-functioning vm - I switched to Vonage

Like I said before - its a $19.99 piece of junk - don't expect spending on IT security from a company that sells you a twenty dollar usb device that gives you free phone service. You get what you pay for - cancel your service if you don't like the crap support

These Blu-Blockers are amazing! I don't need my prescription sunglasses anymore!

and it lets you see giant bass swimming right under the water!
 
Back
Top