Calling a real estate robocaller back
philly.com
philly.com
Scammers have this popular trick of spoofing the caller ID for a number local to you. People are more likely to pick up the call if it's a number that seems familiar to them (like, the first 6 digits are the same as your phone number).
I've known about this trick, but I never really thought about the collateral damage. See ... that number they're faking is a _real_ phone number. And it's someone else's phone number. It's not the scammer's number.
Well my wife's phone number got used. You wouldn't believe the number of people who call scammers back! She was getting hundreds of calls a day; non-stop. Most people were calling back trying to figure out who called them. Some were angry. A few threatened her with violence.
And there's absolutely nothing you can do about it. You can't stop someone from spoofing your phone number on Caller ID. You can't stop people from mistakenly calling "you" back. You're just stuck in phone hell. The only solution is to change your phone number ... not really a great option.
It lasted about a week; we resorted to just keeping her phone on Do Not Disturb.
What a nightmare.
This worked OK when the only operators were the various national phone monopolies (Cap’n Crunch notwithstanding), but today that level of access is much easier to get and abuse, and is difficult to trace.
There are efforts to bolt-on security to the telephone network but it’s really hard.
I think it’s more likely that (over the next handful of decades) the phone network fades into obscurity as more voice calls are connected over data links which offer much improved security models.
I assume you mean Captain Crunch, not the breakfast cereal... :-)
Here's an article about it: https://www.howtogeek.com/402141/how-phone-companies-are-fin...
What your neighborhood grocery store buys from the phone company is just a pool of voice circuits, probably fewer than its extensions and even its DIDs. There is no simple circuit-number mapping like in residential telecom.
Designing federated AuthN/AuthZ for this is not simple; getting it rolled out across all the participating equipment (with many owners and service lifetimes of 15+ years) is basically never gonna happen.
https://www.fcc.gov/document/fcc-adopts-rules-help-block-ill...
I recently moved to a different state and kept my old phone number. When someone calls using that old area code, it's immediately obvious that it's a robocall. I have no ties to that area code, therefore no reason to answer. I usually Spokeo the suspicious numbers afterwards because I'm curious who it is.
A few months back I tracked down the PII of a number that called me, so I texted them back. Here is our short, interesting conversation: https://imgur.com/a/4V2ugw9 (phone numbers and contact list names have been redacted)
> Will’s so busy leaving messages all over town that he never answers the phone when you call him back...Sometimes calls were forwarded to a host of people who went by “Pat.” They said they worked for PATLive, an answering service firm that takes calls for businesses when they’re busy or closed. Pats were taking messages for “Steven’s Office” in Alexandria, Virginia.
> Asked why there were several Pats, a Pat said: “We’re all Pat.”
> “We all go by Pat to keep it easy,” said Pat. “But we do have some Pats in the office.”
I get so tired of these B2B service providers who get caught up doing borderline illegal shit and then just shrug their shoulders and say "not our responsibility." Everybody has these clauses doing the ass covering so they can sell services to anyone who knocks and they're never held responsible because of some bullshit contract.
WHY is that allowed? You're doing business with an individual/organization that is breaking the law, and you know it, or you would know it if you cared to look. That's gotta be at least worth a charge of negligence?
I'm just saying the "Will"s of the modern era would have a much harder time if the call centers, teleco providers, internet hosters, etc. were held responsible when they were found to be operating in cahoots with a scammer and I don't understand why they aren't.
Vet your fucking clients. And if you don't wanna do that, then shut your doors.
It's an answering service for a phone line. Are they supposed to magically know that the people are calling from some robocall and not because it's a semi-large real estate office somewhere? Perhaps the best way to to let them know is to inform them. Then they have a choice to make, investigate whether the accusations are true and decide whether to continue providing service. At that point, they may actually be responsible for something.
How many of the people that call in do you think calmly explain that this is a telemarkerer, and they are breaking the law, instead of being aggressive or saying "take me off your list" or "I'm on the do-not-call list" and then try to end the conversation? The assumption that both ends of the service are connected actually allows the criminal portion to continue operating for longer, as anger is likely directed at the wrong party, and possibly in an non-constructive manner.
And this all assumes people actually take time out to call the number back. How often do you go out of your way to interact with a telemarketer that doesn't have an actual person on the line for the call? My bet is the vast majority of calls are either interested parties or so enraged that understanding what they are actually upset about (and getting them to calm down enough to explain it) is actually rather rare.
With more free form types of calls, identifying problem accounts might take a little longer. That said, even if it lasts a week or two before a problem account is identified and removed, who is to say that's not plenty of time for the scammers? It's not like there's only a few call answering services around. Just cycle to a new one every week or so.
Do I think services exist that cater to illegal and semi-legal activity and try to skirt the line? Yes. I just don't think we should assume that's the case here without evidence, given how trivial it would be to do this with perfectly legitimate services.
Except if a PO Box was being used for fraud, the person using it would be prosecuted, or at the very least the Post Office would cease providing that service.
> or even a software or hardware provider, like Microsoft or Dell, being liable for providing assistance in the crime.
Entirely different, that's a misuse of provided products by the purchaser. If you buy gas and use it to commit arson, it's not BP's fault.
> Perhaps the best way to to let them know is to inform them.
I find it incredibly hard to believe that people aren't informing them, probably at high volumes (audio volumes and quantity volumes) that they don't wish to be called anymore. If I was getting called 3 times a day by some jackwagon wanting to buy my home, the number they'd be giving would definitely be aware of that situation.
And, even giving an incredible amount of credit that maybe they didn't know, they now definitely know. What's the over under on them still providing services to "Will"? I'm guessing it's pretty definite they are, because they have no reason to not as long as his checks clear. And that's my point.
When notified.
> Entirely different, that's a misuse of provided products by the purchaser. If you buy gas and use it to commit arson, it's not BP's fault.
And how is that different than misuse of a third party service?
> I find it incredibly hard to believe that people aren't informing them, probably at high volumes (audio volumes and quantity volumes) that they don't wish to be called anymore.
See my other comment to the other reply. Also, I get a lot of calls. After the first time, I generally just hang up after identifying it. I'm not even hearing the number after the first time. Sometimes I'm mad and might want to call in to complain, but I'm not always at leisure to do so.
> What's the over under on them still providing services to "Will"?
That's not how I interpreted the article. I interpreted it as they were the answering service for one of the target lines that the number forwarded to.
For example, scam line forwards to 4-10 real agents in on the scam, one of them has an answering service. Occasionally calls forwarded to that agent forward again to the PAT service. That's not necessarily the same as providing answering service for "Will" if that's the case, and may not be immediately obvious if mixed with some other types of calls.
That said, yes, I expect they would investigate and cut ties if notified. Why wouldn't they? You seem to assume they aim to provide this service on purpose for illegal activity. Phone answering services are extremely common. Have you ever called a small medical office during lunch, or after hours at any time? You get an answering service with emergency contact numbers for personnel, in case that's called for. Legitimate businesses do not want to open themselves up to the liability of being complicit in a crime. I'm not sure we've seen anything to indicate the answering service is not a legitimate business being taken advantage of.
Because a purchase of, for example a server, is a one-time deal. The server is then in the hands of the scammer, and can be used for all kinds of ill intent and Dell for example has no way of knowing, and even if they knew, really don't have any recourse to address it.
A third party service, on the other hand, has an ongoing relationship with the scammer, assuredly having access to some form of payment details, some kind of ongoing communication in order to fulfill the service they're contracted to provide, and provide ongoing labor to that end which assists the scammer in, well, scamming.
> You seem to assume they aim to provide this service on purpose for illegal activity.
I'm saying they're not asking questions because the scammers checks are clearing, and I don't think that's right. That's what a lot of providers do, they provide the services, and even with ample evidence that everything isn't quite on the up and up, they just keep cashing the checks because why wouldn't they? I'm not even saying they're twirling their proverbial mustache here, I'm saying companies are inherently unethical, and only act ethically when mandated to. So let's mandate it.
Where are you getting the information to assert that as fact? Or even as likely?
> I'm saying companies are inherently unethical, and only act ethically when mandated to. So let's mandate it.
If a company knows it's being used in a crime, then it's an accessory to the crime. We don't mandate ethics, we create laws. In this case, how is the law failing, beyond you asserting some situation is happening without providing any evidence?
Can you actually explain what we know to have been done wrong here, even ethically if not lawfully? All I've seen so far is a lot of accusations about what must be happening, when I see (and have provided) clear examples of how it might not be the case. Or should we just punish people and companies based on assumptions now?
We had a lot of trouble finding a reliable cloud services provider. Even though none of this is illegal at all, a bunch of them have clauses against it in the service agreement. So we avoided those. We figured the ones that didn't have it shouldn't have any problems because nothing was illegal and it's not like we are abusing the cloud services - we're talking about a significant amount of time with nothing on the network (that we pay them for) and then a short burst of traffic that is still low on bandwidth while all the clients are trying to hit the sites up at the same time. But one after another kept cancelling our accounts, citing a violation of the terms of service. We pressed a number of them for an explanation. Many just ignored us. A few outright lied and said they received complaints from ISPs about our IPs sending spam emails. I challenged them on that because nothing of what we did or any of our client did was sending emails. And we tightly controlled the network traffic, ports, etc. So it's simply not possible, they were lying to get rid of us because their terms didn't account for it. To this day, I still can't figure out why all these providers were so against what we were doing. Eventually my friend explained his use case to the CEO of one of the companies and they signed and agreement and were totally fine with everything so I'm really perplexed.
"No, it's Michael."
"That's going to cause a little confusion."
Phone operators follow relatively simple scripts for most clients, taking down information so someone else can call back, but occasionally perform more complex tasks like scheduling appointments. My impression is that most of the clients were small businesses at the time; a few were government agencies.
It's easy for a scammer or robocaller to pass as a legitimate business with a service like that: just don't include any red flags in the script.
"His name is Robert Paulson."
Oh, and "Will" on the voicemail isn't Will either. It's a voice actor off of Fiverr that likely has no idea their voice is being used for this scheme.
Sounds terrible in theory!
The paperwork isn’t too difficult to put together either.
Just ask Donald Trump.
It strikes me as the same thing as the fake-check auto purchase scams that infest different on-line auto sales channels.
...and then, I'd re-sell the note to a rich person/company who can afford better lawyers, because I don't really need my assets pinned down like that in one high-risk loan.
I always say "yes", then you get a real person who picks up.
Then I will do the old bait and switch. Start talking about how my car got written off after the great M25 exodus of 2018. That I lost my foot from a low flying scooter delivery driver. The story then becomes more and more ridiculous and eventually they will hang up.
Since opting for this tactic my phone call count has gone down considerably.
I got some so angry that they threatened to come over and break my face at home. This technique has up to now never failed me.
I played along until I got bored pretending to be a fumbling, bumbling, low-knowledge user, and revealed that I was not really at my computer, or any computer at all, and I was just messing with an obvious scammer for fun. And that induced a spluttering, heavily accented rage-stream of insults, which was also fun. "I am not scam people! You are the scam!"
They’re never telling you that upfront but they’re usually more than happy to say after “closing” (or so they believe) their deal.
At that point I can go after the company in small claims court for calling a number registered on the TPS (equivalent of the do not call list in the US).
On the plus side, patlive.com charges $1/minute as their cheapest plan. Robodialing them back, with a sufficiently clever script, would be costly for "Will".
If it was a reloadable card, you can still figure it out with more effort. You threaten to sue them into oblivion as facilitating criminal actions, and you get them to get you on a real phone number with the scammer, and then you track them down that way. You just have to try harder.
A reporter could pursue this by getting a job with that firm and tracking backwards.
We may get there. It'll probably take the form of deploying STIR/SHAKEN on the US side and making engagement with anyone who doesn't implement it purely opt-in.
I'm not a facebook fan, but I wouldn't be entirely against "Facebook Phone" (as in, a drop-in replacement for dialing numbers now that works as an appliance, not a shitty "add-on" for fb messenger) if they moved in to disrupt the industry. Of course privacy-be-damned at that point, but it's the lesser of two evils IMO.
You realize that the vast majority of "robo-calls" are originated from Class 2 Interconnectwd VoIP providers, aka SIP companies like Twilio, Flowroute, SIPSTATION, SIP.US, voip.ms, and the like.
VoIP is the problem, because you can put an extraordinary amount of of volume down a very narrow pipe, with almost zero verification or validation on the technical if you are an active customer with a SIP provider. Becoming an active customer is not very difficult, either.
I suggested FB only because it has fairly strong identity verification and (arguably) spam control. Plus they have the infrastructure to handle the bandwidth of a massive VoIP network.
Nobody will call you, of course, including spammers.
"Please enter the result of 7 modulo 5 to prove you are somebody I want to talk to."
I've gotten some helpful calls from neighbors though whose number I didn't have saved.
Just set your phone on permanent DND w/ exceptions. It's literally the same thing, except you're not going through annoying contortions to "stick it to" someone that is probably a robot...
Any given person only needs $2-3 in reserves in their wallet, to make at most 4-5 outgoing calls, before their fees are refunded. Then a nominal fee for the miners.
They use the typical trick of calling you twice simultaneously, so the second call can go straight to your VM box. The message was boiler plate: "we're looking for a home in your neighborhood for a client, but inventory is very thin as you know so we're wondering if you know anyone who might be open to selling."
The thing is, there were 3 houses for sale on my street at the time, so it was immediately clear this wasn't based on an actual client. I had recently spoken with an agent from this brokerage firm and I sent her a follow-up email to let her know that her colleague's (illegal) shenanigans were undercutting her company's reputation.
https://github.com/kaliturin/BlackList
I have no connection to the software other than being a satisfied user. Yes, it's open source. Yes it's Android only.
Yes, it's SMS app is bare-bones. And the UI is ugly.
That's the tradeoff for this kind of thing. It's a shame there isn't an active development community around it making it so much better.
The basics are all there and they work great. Mainly if the UI was updated, and certain "extras" were added to the SMS app (for me, that'd be emoji/smiley usage and photo upload/download) - it would be perfect. But I'm willing to put up with the "bad" to gain the "good" parts of the app.
Callfire allows for things like enabling recording on the call forward (potentially illegal) when someone calls it. Then investor themselves or pays a virtual assistant like $3hr to sift through all those calls for any potential leads. You can hear the entire call to patlive if you wanted to. Or they just trust patlive to forward messages as they’re the answering service.
So long as your answering service or where you’re generating your numbers doesn’t blow your cover then you can keep this game up for a long time. That’s what these answering services are trained to do is protect their clients identities. But I doubt that holds up when the FTC comes knocking.
1. It’s probably correct? The US is a very large single market
2. From some quarters the US does come across as being fairly laissez-faire
3. The scale of predatory economic activity in an otherwise highly developed economy is(?) unmatched
4. Penalties seem to be a cost of business rather than genuine attempts at deterrent
5. The general appearance of a lack of accountability
But, I’m just looking on from afar, and I’m sure the media advances the hyperbole.
Apple really needs a way to enable permanent do not disturb for just phone calls, ie your phone only rings if you are in the contacts.
That's a really great feature idea. I hope someone here who works at Apple or Google reads it.
It doesn't catch all, but it hasn't incorrectly flagged one yet.
Works surprisingly well considering it is Google in 2019, but now that I think of it I can see a number of ways they'll mess up this as well ;-)
99% of the time, the call just disconnects.
I really wish Google would let me set my phone to ring only for numbers in my address book and give everybody else a busy signal.
The problem with settings like that is it still lets the call go to voicemail and I don't want to deal dozens of 4 second messages every week.
IIRC, it's done using frequencies that either can't be heard (ie, outside the freq response of the phone), or the sound is "switched off" between rings (quite possibly this, since the "ring" voltage is completely different from the "line-in-use" voltage - so this voltage change can be detected and switch the signaling as needed).
At any rate, it's a known thing, and if you understand how it works, it's possible (well, again, was - for land line phones) to build a box that can inject these signals between the rings so the phone being called will display it. Normally, this is done (IIRC) by the CO, but I think if the info is already there, it doesn't override it.
I might be completely wrong, though; it's been a couple of decades since I last read about how it worked; also, I have no idea how it works in cell-phone land, but likely it hasn't changed because "inertia" and having to support older land-line phones...
The caller ID information comes as a frequency-shift-keyed (FSK) message (I think). As you said, it's between the first and second rings. But you can't hear it, not just because it's not a normal audio tone, but also because the phone is still on hook and isn't playing any audio that comes over the line.
That's regular caller ID, which is type 1. Call waiting caller ID is type 2. It's also an FSK message. (That is, I'm sure that it's an FSK message. I think type 1 is also FSK, but I'm less certain of that.) This comes immediately after the call waiting "beep". It's short enough that I don't think your ear can pick it out of the transition from the beep tone to the regular conversation that the beep interrupted.
I'm not sure whether you could get fake caller ID that you send through a CO. The phone line isn't "off hook" yet, so the CO isn't passing audio. (If you say "hello" into the phone while it's ringing, I don't think that audio goes down the destination phone line either.) But that's only how I think it works; I don't know.
As for felony life sentence, while I'm sure that's facetious for effect (and I chuckled), if you accept any of the above reasons, it seems you also need to allow for inadvertent misconfiguration. Once we broke up the telephony stranglehold (overall a good thing, I think), we allowed a bunch of federated phone systems to start working together, most of whom are good actors.
That said, I viewed this page in incognito on chrome without issue.