There is precious little within SS7 to prevent or respond to spoofing. It's a major nightmare for telephone companies.
There is precious little within SS7 to prevent or respond to spoofing. It's a major nightmare for telephone companies.
> It's a major nightmare for telephone companies.
Disagree. It's a bug for the telcos, and a major nightmare for the rest of us.
As for billing, it is usually based on the destination number, and your originating telco, unless I am misunderstanding your question.
Toll free routing may be less amenable to grey routes and things as well. International callers aren't "supposed" to be able to call US toll free numbers, which may make it harder to get to. I've seen some companies claim that they can use call routing information to toll free numbers to get accurate caller id information in some countries; but I would never trust it.
You also shouldn't trust the source IP, or the return address on a standard envelope in the mail, unless you have convincing evidence. It's hard to think of an example of a source address in communications that's really trustable.
To change the routing of a call other than yours would require you to access a carrier's systems and change where the call is routed to--which is substantially more difficult.
phone - I dial the number my bank gave me and no man in the middle ever answers or interrupts. But still completely insecure!
Now imagine you see me trying to enter my credentials over an http connection to AwfulBank.com. "Stop! That's completely insecure!" you say. "Sure, but so is calling a bank using the phone number they gave me."
If both cases are already completely insecure, why am I wrong?