FCC fines robocaller record $120M
techcrunch.com
techcrunch.com
The 'neighborhood scam' is one which I am frequently subject to, and there is virtually nothing I can do about it (except block all the numbers with the same prefix as my own, but even this only covers the cases where they restrict their spoofed numbers to that small range).
Domestic callers like the one described in this article seem like a very small part of the problem, since they can be tracked and prosecuted. Foreign callers never pay the penalty with our current system, and I suspect they are more numerous based on the accents of most robocall operators I've gotten on the line.
Every phone network will then quickly begin passing on that cost to anyone they "peer" with and it will be a non-issue soon enough.
Is there a compelling reason to allow such spoofs?
It makes telcos money. That's reason enough, since there are no economic downsides to the network operators that enable these crimes. If companies like AT&T and Verizon were also being subject to this $120M fine, we might see them decide to make caller ID trustworthy so that it could be used to block robocalls.
How?
A few use cases to spoof the number:
* Appointment reminder systems - if I see the caller ID is from my doctor's office, I'm going to pick it up and hear the reminder. When the calls come from some other number, people think it's spam. People still expect reminder calls even if you/HN crowd would prefer an email/text.
* Outbound call centers on behalf of others companies (same reason as above)
* People who work from home but want to make business calls from a personal phone
If no one could spoof, it probably result in a huge uptick of people claiming spam calls since they would be getting tons of calls from numbers they didn't know.
There really needs to be an SPF, DKIM, DMARC for VOIP. I don't think a no spoofing policy would go over well for businesses or consumers.
I'm not suggesting no spoofing, I'm suggesting a fine on the carrier for unauthorized spoofing, which will force them to actually verify that there is authorization.
You didn't make this clarification in your first post. In the first two examples, they don't control the claimed number, which is what I was responding to.
>I'm suggesting a fine on the carrier for unauthorized spoofing, which will force them to actually verify that there is authorization.
This makes sense. Legitimate companies will get authorization agreements signed etc.
If you want to place a call with spoofed caller ID info, your provider should require you to prove that the spoofed information is legitimate, not fraudulent. Otherwise, the telco should be obligated to strip the suspect caller ID information from the call so that the recipient can properly identify the call as fishy.
There's no need for any complicated cryptographic solution. Telcos should just be required to know their customer, much like banks, before allowing them to do certain things.
So forcing the fine on the last step in the chain forces everyone to carefully consider who they trust, which is as it should be. Nothing wrong with trust between trusted parties, but clearly the current system has untrustworthy parties given too much power.
That's the thing though, a lot of times they don't control the spoofed number, but there's a legitimate use case for spoofing it. Authorization to spoof is not the same as having control of a number.
The issue is that the PSTN is essentially a huge, worldwide message queue to which pretty much any telco can connect around the world, including shady ones - even if US law actually does fight spoofing, how do you prevent telcos from other countries from continuing the abuse?
Cryptography is needed - when a carrier leases you a number, they give you a certificate with which you can sign other carrier’s certificates if you want to let them use that number as caller ID. Every carrier on the call chain should verify call’s signatures against that and discard any calls with missing or invalid signatures. That will stop malicious spoofing while allowing its legitimate use, just like email where you can use SPF and DKIM to nominate any email provider to be able to send on your domain’s behalf.
If I complain about a call, that should be trackable to the origination carrier and account, and if either one gets too many complaints, it gets thrown off the network (and other penalties).
Mobile roaming is one for example - when you roam on another carrier and place a call, that carrier directly originates the call and “spoofs” your caller ID to make it look like the call originated from you.
Some companies may use different carriers for either load balancing or least-cost routing and so both of these carriers are required to “spoof” the company’s caller ID.
This can definitely be fixed with a CA system and “delegation” where the main carrier who owns the number can issue certificates for any other carrier you’d like to use to temporarily allow them to use a particular caller ID, and each call request should be signed with that certificate and the signature should be verified by call intermediate carriers down the chain, and the call dropped if the signature is missing or invalid.
The telcos will find a technical solution real fast.
> This is a technical problem.
IMHO, it's both. Economic sanctions need to be put in place to motivate the telcos to create and adopt robust technical solutions.
Or if they don't own it then it's on who's inserting the call into the system.
Telco systems are fun. And by fun I mean it's a complete mess. ISDN is hard and full of caveats (look at SIP for a taste of what it involves).
In most areas it was illegal to set that bit unless you were a telco. It was also illegal to sell equipment that set that bit unless you were selling it to a telco. But... it's not that hard to hack.
Someone who's more current can probably give you better information. As to why nobody does anything about it... well.. why should they? They literally don't care. The equipment manufacturers aren't going to change the specs (because it's pretty darn hard to change specs and they are all trying to screw each other over in the specs anyway). The telcos aren't going to demand that the specs are changed because people are making telephone calls -- exactly what they want. It's only if the governments demand the change -- and it will take laws to do that (even then, I imagine that it's cheaper to lobby against the law than to change the equipment -- you have absolutely no idea how crappy those systems are).
A user can request a "trace" (usually by dialing a feature code), but not only does this hit the user with a ~$20 fee each time, but the information gathered can only be released to law enforcement, and since local law enforcement would need to make the request, it rarely happens.
When the isp wars were going strong, before broadband put everyone under the thumb of monopolists and also before gmail, spam filtering was a serious competative advantage.
Why can’t phone companies take an RBL like approach? If your VoIP service garners too many complaints because you are selling to robocallers then you don’t get to have calls delivered to e.g. ATT mobile customers anymore?
Are there legal or technical interconnection requirements that would make such a thing impossible?
The two biggest carriers have a 1-2% monthly churn rate.
https://www.statista.com/statistics/283511/average-monthly-c...
At a technical level, spam filtering relies heavily on analyzing email text. Doing similar analysis on voice calls is way harder. Also, there's UI issues. You can redirect suspected spam emails to a folder the user can inspect for false positives. What do you do with a call that hits the robocall filter?
That approach could work here.
It’s not clear to me that carriers would be allowed to do that, especially accounting for situations where VoIP traffic is laundered through a legitimate service (so the entity at the exchange boundary with the end-user carrier is a legitimate one).
Could they get around common carrier restrictions by offering that service as opt in? I’m not so sure about that either.
More details here: https://www.broadcastingcable.com/news/fcc-clarifies-robocal...
Note that Ajit Pai (then a commissioner, not chairperson like now) voted AGAINST this.
Full disclosure: We (Nomorobo) advocated to the FCC to allow carriers to block robocalls.
All this occurs against the background of the Communications Act's common-carrier obligations, and the FCC's call-completion rules, which generally prohibit blocking calls. What the FCC did in the order you linked is to simply say "nothing in the Communications Act or our rules or orders prohibits carriers or VoIP providers from implementing call-blocking technology that can help consumers who choose to use such technology to stop unwanted robocalls."
Is that a safe harbor? No, as the next sentence clarifies, what can be blocked depends on the nature of the call: "Additionally, in the interests of public safety, we strongly encourage carriers, VoIP providers, and independent call-blocking service providers to avoid blocking autodialed or prerecorded calls from public safety entities, including PSAPs, emergency operations centers, or law enforcement agencies; blocking these calls may compromise the effectiveness of local and state emergency alerting and communications programs."
As explained in other posts here, it's hard for a carrier to tell what is a robocall. What is an "unwanted" robocall is even harder--it's a heavily-litigated issue in the TCPA context. (In fact, the rest of the order was about expanding what counts as an unwanted robocall in violation of the TCPA).
That leaves carriers between a rock and a hard place--it they block over-inclusively, businesses who think they fall into a TCPA exception could sue them for violating their common-carrier obligations. Then they get to litigate whether that business falls within the scope of the "unwanted robocalls" the FCC referred to (but did not define). Carriers have a huge incentive to not wander into that morass by offering call-blocking features.
This makes third party call blocking products a better/easier solution for carriers to recommend as a solution.
I don't really want my carrier deciding what calls to block. I just want them to ensure the veracity of caller ID data so that I can perform useful blocking at my end. There shouldn't be anything stopping them from removing fraudulent and unverifiable caller ID info from the calls they route my way. That leaves me free to block calls that lack caller ID info, and I'm assuming all the risks that entails.
Send it straight to voicemail, where the user can inspect for false positives?
Stuff it’s more confident about gets blocked outright. I think they’re automating what they’d do if you went into your account and manually blocked a number.
For reference, I've had the same New Jersey mobile number since 2001.
Google Voice has had spam lists forever, it's likely they are pooling the data from there.
T-Mobile does have the ScamID/block thing that can be controlled by shortcode. Documentation here https://explore.t-mobile.com/callprotection
My operator should be able to have a short list of teleoperators in this zip code, and drop other calls.
I think no-one receiving calls from parked non-local voip numbers would be an acceptable price to pay for the elimination of voip spam. You are free to disagree, tech is all about making compromises.
Incidentally, this quickly follows the path we took with SMTP. I can no longer telnet into a random SMTP server and dump incoming mail, which no doubt ruined the carefully honed scripts of many sysadmins.
Telemarketers have learned that certain area codes convert at much higher rates than others. 202, 203, 212, 213 are prime targets. 242, 246, 406 and 701? Notsomuch.
If your NPA isn't important to you, get a number in those areas. (Some carriers will let you choose your area code as long as you're within the same billing center.)
That’ll probably require fixing the broken design of the telephone system.
Carriers have no economic incentive to do this. Most people on AT&T aren't going to jump to Verizon because of the number of robocalls they get on AT&T. It's not worth the hassle of changing.
I remember at one of the WWDC keynotes, Tim Cook announced this as a new iPhone feature. But he also noted that it was only available in China. I wonder if whatever the Chinese carriers have done can be imported to the United States.
My wife's iPhone will occasionally get an incoming call with small text below reading "Possible spam." She never uses her phone for voice, so she never answers the phone anyway.
Those features of CallKit are what we (Nomorobo) use to stop the robocalls.
I switched to ATT Call Protect which works much better. Now i get 1-2 calls/week. I would go back to nomorobo if it worked better.
We used to show "unblockable" because there was a problem with false positives. Lots of families had sequential numbers that were accidentally getting blocked.
Now, if you give us access to your contacts (local processing only, never transmitted to our servers) we can completely block them.
What’s the technology?
Edit: https://transnexus.com/solutions/stir-and-shaken/stir-and-sh...
”STIR and SHAKEN use digital certificates, based on common public key cryptography techniques, to ensure the calling number of a telephone call is secure. Each telephone service provider obtains their digital certificate from a certificate authority who is a trusted authority. The certificate technology enables the called party to verify that the calling number is accurate and has not been spoofed.”
CallerID4U seems to have gone (has been put?) out of business, at least. My Asterisk box hasn't received calls from their prefixes (which I blacklisted) since 2015, and their website's main page returns a 403 Forbidden. [1] It took a bit of hunting with the Wayback Machine to find a good shot of their page. [2]
Spot-checking on telcodata.us, it looks like their prefixes/thousands groups have gone to others as well. 253-245-2xxx now belongs to CenturyLink, for instance, and 425-336-8xxx is unassigned.
Much like "unsubscribe" links in spammer emails, they even had a helpful "Click here to register a complaint and put your phone number on the DO NOT CALL (DNC) list" item on their web site.
[0] https://800notes.com/forum/ta-705926565a74ba5/callerid4u-inc...
[2] https://web.archive.org/web/20130310040410/http://callerid4u...
They were also known as 33 wireless and a few related companies. Here's an old discussion about them [0]
Not sure what happened but their telephone number blocks were all reassigned to other companies
[0] https://800notes.com/forum/ta-705926565a74ba5/callerid4u-inc...
Today, I use an iPhone and now use voicemail as a basic call filter. If I get a call from a number I don't recognize I immediately let it go to voicemail. At my leisure later in the day I can check the transcription service to see if it's spam.
I find it bizarre that the feature fell out of use for me, and came back into it because of this recent spate of spam phone calls.
I really wish they'd just make some kind of system or authority to keep VOIP from spoofing numbers. It's ridiculous. There's gotta be a way for them to secure that shit. I guess they're just inept.
It's not on F-Droid, but the source code is available on GitHub.
Play Store listing: https://play.google.com/store/apps/details?id=com.jachness.b...
GitHub repo: https://github.com/jachness/blockcalls
This FCC won't do anything meaningful because they've been bought off by the telecoms, and the telecoms make money hand over fist on robocalls:
http://www.latimes.com/business/lazarus/la-fi-lazarus-fcc-ro...
"The problem," he said, "is that for the carriers, it's a conflict of interest. All of these robocallers represent billable minutes. From a revenue standpoint, anything they do to crack down represents a reduction of billable traffic on their networks."
Same way this FCC's purported "deregulation" of net neutrality is a sham which rigs the game so that the telecoms can leverage their market dominance in more verticals.
We know what the technical solutions are for the problem of robocalls. Corruption and legalized bribery are preventing the application of those technical solutions.
The billable minutes thing is absolutely true. You might not directly pay for them as a customer, but carriers pay each other for inbound calls, so whatever carrier that is originating the robocalls is paying the next carrier in the chain, and that one pays the next, and so on until it finally reaches your phone. We’re not talking much on a single call (the prices are often around 0,01$ or even less) but when you take all the robocalls originated in a single day that adds up to quite a bit.
I certainly believe that the FCC is too influenced by large telcoms companies. As we see with the Michael Cohen thing, large companies believe they can buy influence. But those same companies that are receiving the calls are mainly paid by consumers. Is TMobile really willing to risk losing my ~$100/month to get whatever they do for calls I don't answer?
I'm sure there are carriers for whom the robocalls are a major slice of revenue. But are any of them nearly as big as the consumer-focused telecoms companies?
The industry is honestly shady as fuck. They’re being pushed into irrelevance by the internet and VoIP (where there’s no such thing as paying for minutes, thankfully), have thousands of employees to pay (despite not doing much, as they became irrelevant over time), and so while incoming call revenue is maybe 1% of total revenue for someone like T-Mobile, it’s still paying for some useless people’s pay checks, so of course those are gonna fight back.
Now aggregate that across the entire industry - everyone fighting for their 1% of total revenue - and you’ve still got a strong pushback.
Finally your carrier knows they’re not going to loose your 100$/month over robocalls because you have nowhere to go. The situation might change if one carrier bites the bullet and implements a working solution (but good luck given that it requires industry-wide cooperation), then the other carriers will wake up as they now know customers actually have a competitor to go to.
Doesn't that undermine a major premise of the OP's post? That one should assume corruption, because it's technically easy to filter robo calls and carriers don't do it only because they love the sweet, sweet, robo call inter-exchange fees?
It sounds like filtering robo calls would require cooperation not only among telcos, but also with the VoIP providers that originate these calls.
The current situation is the one, which requires cooperation of the whole industry, actually. It's a prisoner's dilemma in the sense that the first one to implement anti-spam will gain a temporary advantage but eventually everyone will have to implement it and keep up with the spammers who will be finding new ways to circumvent these measures. As it stands now - nobody gains advantage and nobody has to spend money on anti-spam and lose revenue from spam at the same time. As little as it is, taking your $70 and $0.05 from spammers is a lot better than taking your $70 and zero from spammers.
There is no real concept of "origin". Unless you're the direct upstream carrier of the originator of the robocalls, the robocalls will be diluted with legitimate calls in such a way no single inbound carrier stands out.
Small & shady carriers are where the problem is, and those often just resell capacity from bigger carriers (some of which in turn resell even bigger carriers), or sometimes even resell illegal "black" or "grey" routes as they're called, could even be compromised servers from legitimate customers of big carriers.
In the end this entanglement mixes legitimate calls with malicious ones by the time they reach the destination (final) carrier, making it impossible for them to drop malicious calls without impacting a lot of legitimate usage.
*I avoid saying VoIP retailers because it doesn't really mean anything; carriers often allow you to use different interconnects, and VoIP is just one of many.
No, I did not say "drop calls", I said drop the source. If Twilio got blocked on T-Mobile it would found which re-seller is responsible in no time. If it was their hacked server - they, again, would have found it and patched. It's no different from e-mail spam in early 2000s - all e-mail from a server sending spam would have been blocked, including legitimate e-mail.
Consider also that the telcos offer premium services to counter robocalls. Verizon "Caller Name ID" is priced at $2.99/month; for their landlines they sell hardware such as the "Call Blocker Shield". Sprint "Premium Caller ID" (which includes blocking capabilities) costs $2.99/month. T-Mobile "Name ID" is $4/month.
Consider as well that many cell-phone plans are not unlimited and that depending on the plan, incoming calls may count against monthly minute quotas.
On the cost side: the technical solutions to tighten up the network cost money, whether it's implementing heuristic filtering on the existing unreliable network, or working to make the origins of calls reliably identifiable.
Between the revenue and the cost telcos thus have significant incentives to avoid solving the problem of robocalling.
The staggering negative externalities of robocalls, though, are borne by the public. We have a huge collective incentive to see the problem of robocalls solved.
Ajit Pai's FCC won't help the public, though -- it's fine with telcos privatizing profits and socializing losses.
I wish credit card issuers would end their affiliate programs.
If they don't want to end the programs, they could at least clean them up. If I answer one of the Rachel calls and take them up on their offer for a different card, the credit card company should be able to track who referred me to them and close their account. But the incentives are all wrong.
It's like asking the post office to solve junk mail. Where's the incentive?
With PrivacyBadger disabled the connections keep on coming; especially as you scroll the page up and down.
Has anyone else had similar happen? For some naive reason I just figured the spoofers were using blocks of unused numbers, not live ones.
It technically is, right? Because it will make automated unsolicited calls at a massive scale.
* sacrifice an LLC (if he has one)
* declare bankruptcy
* be garnished at the legal maximum rate for the rest of his life? (little bit less than 25% of after-tax)?
I wonder if it is worth an FOIA to ask some of these high-profile agencies how much they are raking in with garnishments from gigantic fines?
Lately, I've taken to wasting their time, and at the end, telling them if you had put me on the DNC list, this wouldn't have happened.
it could be possible to have different PoW requirements for different callers. perhaps you could require a higher PoW for an unknown caller, and no requirement for someone you know.
I called my phone company and asked them to block all foreign calls. They did and now I very rarely receive any robocall.
Back in the day, when there were proposed laws to make SPAM similarly illegal, the Direct Marketing Association (DMA) lobbied hard to get exceptions that would allow SPAM. And the rest is history.
Remember the aptly named "Can SPAM" act?
Can could mean:
1. toss it out, eliminate it
2. enable it
3. a metal cylinder it is packaged in
It would be interesting to know what's different about the systems in the USA, as I don't imagine robocalling Britain would be somehow less profitable except by regulation or technical measures.