Robocalls are overwhelming hospitals and patients
washingtonpost.com
washingtonpost.com
I wonder if in the future people will wonder why they are called phone companies? Maybe this is all part if their plan to move us to paid SMS or some other thing, but it seems more like an oops.
But it's still a nice dream.
There was a single throw away line in WWDC that suggested they may have finally added this (depending on what they mean by “unknown” caller).
All I want is a contact based whitelist with an API endpoint that allows calls for a small time window (for doordash and Uber to use).
This would solve 99% of the spam issue. All other calls can go straight to voicemail. Allow an option for repeated calls to get through if you must.
Apple’s current call kit api only allows blacklists which work poorly and are a lot less elegant.
Then maybe they ought not to do that?
Services that cared could change behavior to call from a single number.
I've tested out the "silence unknown callers" feature in the iOS 13 beta and it works very much in a similar way. "Unknown callers" seems to be any call that isn't in your recent calls or in your contacts.
When I made MyHumans (just launched in the last month), I knew there was a risk of something like this appearing in iOS 13, but I'll be adding some more features.
Do you do something special?
You can also configure Do Not Disturb mode to allow calls to come in from your contacts or from your favorites.
For a free alternative, you could route all your calls through Google Voice. You can transfer your current # to GV and then forward your GV calls to your new number that you don't have to even know beyond configuring call forwarding. GV has spam filtering, call screening, and lots of other useful features. Dunno how/if it would mess up your texting app though.
I used GV for a long time, but abandoned it once I learned Google was silently dropping group chat messages (without telling the sender) because they let their gizmo5 purchase languish with no dev work for years and never implemented MMS (this was a couple of years ago). Google had such a head start with GV, but did nothing with it and let iMessage catch up and pass them.
If there's something that I find completely puzzling about Google it's their disaster around messaging strategy.
It's also frustrating to me that all of these mediocre blacklisting applications (robokiller, hiya, nomorobo) only exist as hacks because neither iOS or Android allowed the obvious contact whitelist ability. Though it sounds like in iOS13 this may finally be changing.
I could be wrong, but I believe a "known caller" is someone whose number appears in your Contacts, or a number that has recently shown up in Mail or Messages.
W/G/B is still the best policy: white/grey/black.
I couldn’t figure out an obvious way around the api restriction, but if you want to try there was a github project called open call block which was a decent starting point.
I know people who are already there.
When that notion grows, even slightly, it will be the instant death of PSTN (public switched telephone networks), due to negative network effects.
A huge question will be the fight over standards to replace this, and what capabilities (to communicating parties, initiator, receivers, carriers, vendors, third parties, criminals, law enforcement, intelligence agencies) are and are not afforded, intentionally or otherwise.
Similarly, I keep wondering if the word "phone" might annex the word "computer" entirely. If most people call their day-to-day pocket computer a "phone", what's to stop people calling every computer a non-pocket phone?
Some classic "futurism" ads of AT&T from back in the monopoly era (50s/60s) always had that interesting assumption that phones would be everywhere and do everything. We seem to have brought that future about ironically enough, just that the definition of "phone" is changing so drastically, and also that there are a lot fewer AT&T logos on everything.
The telephone network just seems like some vestigial leftover only used by pollsters to scare us with 80-year-olds' candidate picks in midterm elections.
The Finnish Competition and Consumer Authority has started receiving reports of marketing robocalls being made, and they issued a notice noting that such robocalls made without the customer's consent are illegal and that they and the Data Protection Ombudsman are currently investigating a case where a company has been using marketing robocalls: https://www.kkv.fi/en/current-issues/press-releases/2019/14....
What I don’t understand is how providers haven’t a clue which providers are even sending the calls. We know of rogue servers or countries, but not phone numbers.
This is how it works. The scammers are using $SCUMMY_VOIP_PROVIDER, which is a service that's pretty much marketing to illegal robocallers and making money off of it. The recipient phone companies only know that the calls are coming from $SCUMMY_VOIP_PROVIDER, and are unable to do anything about it because... they don't want to. They're not suffering from it, it costs money to build the systems to work out exactly how scummy $SCUMMY_VOIP_PROVIDER is, and trying to refuse calls from $SCUMMY_VOIP_PROVIDER might land them in legal hot water (which would cost them money even if they won).
There is a very effective solution, reputation, which is how spam mail exited the picture (from most users' perspective). Essentially, you rate your counterparty provider based on what fraction of their userbase is spam and make life worse for them the higher it is. The big email providers worked out the technical solution largely because spam is actually rather expensive to deal with (storing all spam email would increase your capacity requirements by ~10×), and the solution of screwing spammers over incrementally is easy to implement (effectively, you can throttle email since retry is builtin).
If I could transfer my main number to something that only accepted sms and voicemail I would immediately and move my iCloud account to an email address.
I don’t believe in at&t, Verizon it any of them. Something better is coming.
The international situation is harder, but if you apply the same rules, local telcos will have to start dropping foreign partners who don't filter their calls. No foreign telco will want to be in a situation where they're dropped so they'll be forced to comply too.
They must know: they're surely not forwarding calls just on the hope that they get paid, they're forwarding calls from providers who are paying them to forward those calls.
They get/got more money if they don't bother to check legitimacy in the short term. The phrase is something like "the chickens are coming home to roost" (ie the result of their bad actions are going to return to them).
I see no reason that my supplier can't add, say, a "0091" code to calls from India, or wherever. Or send a callerid prefix that indicates a spoofed number if it's a domestic call.
I was quite irritated in the beginning and always thought that my company as some kind of a business relationship with the caller. I got used to it and my first question is always if we have an ongoing business relationship of another former point of contact. If not I hang up.
A couple jail sentences would go a long way.
And to make sure the source is set to a value that the caller is allowed to possess. The problem isn't spoofing of numbers--because the utility is quite high for legitimate uses, like PBXes and after-hours doctor return calls for two examples--but the ability to spoof any number, not just numbers a caller is permitted to use.
PBXs? Surely you can get a block of numbers you’re allowed to have and use those.
After hours doctor return calls? Route the call through the physical office, or just call from a different number.
A system that’s overrun with spam is as useless as having no system at all. We got close to that with email in the late 90s and we’re getting close with phones today. Requiring some minor, inconsequential changes to how a few people use the system should be easily acceptable.
As useful as those examples may be, I am very much okay with cutting them off if it means we can greatly cut down on spam calls. People will adapt.
FWIW, I recently took the measure of setting my default ringtone to a "silent" sound file, and setting vibration to "none". Then I reenabled those settings manually for known-IRL contacts. A hassle to do, but absolutely necessary given the uptick in phone spam.
I really hope it’s a contact based whitelist.
I haven’t seen anyone write about this yet.
How about not sending them to voicemail?
I have literally _never_ used voicemail. I _will_ never use voicemail specifically because it has _always_ been riddled with spam. I even demanded T-mobile to disable my voicemail account. Not even six months later I started getting that annoying little icon on my phone again.
Whatever utility that feature may have is clearly outweighed by all the harm it's causing. It's past time we get rid of it.
Most of the responses I see so far don't seem to realise that world ever existed.
The bank/doctor/employer used to call from the local visible office. You'd know if it was the local bank branch, the nearby business office, the card, loan or mortgage centre as they'd all have different PBX spoofed numbers as it was constrained by the line groups. You wouldn't get to know from caller ID whose desk it was.
Let small businesses spoof the least significant digit - yes just ONE, and large businesses two digits. Then it can work like it was meant to, and we can have customer service again.
For $600/hr, I wouldn't mind to receive the spamming calls from them. Maybe some robo dialer might just be stupid enough to call? $$$$ :-)
The whole problem with robocalls is that your provider gets paid some small pittance to terminate the call, but gives none of that to you. Because they don't want to change, they drag their heels and complain and complain.
> The whole problem with robocalls is that your provider gets paid some small pittance to terminate the call, but gives none of that to you. Because they don't want to change, they drag their heels and complain and complain.
This must be the same logic used to allow for spam physical mail but laws against the virtual sort.
I made a deliberate effort to answer such calls on the first ring, thus costing them money by connecting the call, and after two weeks of that the calls stopped.
When we burn SS7 to the ground and start over, which will never happen in an era of WhatsApp/FB messenger/telegram/signal
"Hi, thanks for your enquiry about VoIP. Yes, we have a No Questions Asked policy and it'll be $5000 pcm plus $0.01 per second calls, we need the first $10 000 up front and you need to stay $1000 in credit or we pause service. OK?"
"What! That's crazy, we can't pay 1¢ per second, your competitor is ten times cheaper"
"And my competitor doesn't like spam. Either 1¢ per second is fine or you are wasting my time, get off the line. No questions asked is what you need, and that's what it costs. I paid $25 000 in fines just last week, that's a lot of seconds at one cent per second"
"I'll have you know we're a market leading direct sales business and every one of our calls is based on a legitimate sales lead, but I see your point, the $10 000 will be in your account first thing tomorrow".
Around the same time we can no longer spoof the From: in emails.
These 2 technologies are quite different, but similar in the way the architecture treats the originator. (i.e. there's no authentication or validation of the originator required)
I'm curious. What utility does spoofing a phone number have?
People with multiple phone cards, but wanting callbacks in one place.
People with phone numbers belonging to another country.
Doctors responding to out of hours requests, but not wanting to share their direct contact.
Of course, why it was designed to allow spoofing of any number in the world, instead of only numbers in the same block...
There’s probably a better solution.
[0] https://fivethirtyeight.com/features/study-excluding-cellpho...
I also find it really annoying how cellphone and smartphone companies don't give individuals the tools to redirect unknown callers to voicemail or do some sort of basic algorithmic/call screening things. On iphone the most beginning programmer could come up with something better than do not disturb.
But I don’t speak Mandarin, so all I can let out are some Nihao’s and can only waste up to 15s of their time.
I really need a Mandarin soundboard on a webpage to do some It’s Lenny time wasting.
The FCC just last week started tackling this. They're working on allowing telco providers to implement blocking and also whitelisting. I haven't read all the details, but it seems like there were regulations preventing them from acting, and they're trying to remove those regulations.
In the end, this is a technical problem. It simply shouldn't be possible to spoof phone numbers this way. Surely the major telcos know where these calls are originating, at least on a network level. If they're all coming from China, clearly they're not going to block all of China, but they could ensure that calls coming from China's telco(s) are not routed if their source caller ID info is spoofed to indicate a US network. That might not stop the calls, but at least they wouldn't show up as coming from US numbers.
If you've never been a recipient of one of these calls, one of the hallmarks is that the caller ID will show it coming from the same area code and exchange as your number. So if your phone number is 917-555-1212, the calls will usually appear to come from 917-555-XXXX. Surely the phone company has a way to identify and handle this situation, at least better than they do now. Mobile phones probably complicate this. Maybe someone who knows how the networks operate can speak about the technical barriers?
[1]: https://docs.fcc.gov/public/attachments/FCC-19-51A1.pdf
It's not just hospitals, it's any phone at all. I've deleted my voicemail and that seems to have helped a small bit. I'm on the job hunt and as such I get a lot more spam than when I was not in the market. Yes, some recruiters and HR people may fall through the gaps and I may not call them back, but generally anyone that wants to talk to me will send an email as well. I'm kinda using a crummy 2FA for the job hunt.
Almost all of mine are related to health insurance or small business loans. Is this what you think comes from China?
As I don't speak Mandarin, I can't confirm that all my calls are this specific scam, nor does that necessarily mean that the calls originate in China. The "block China" comment was more of an example. For all I know, it's a scam organized and operated from inside the US that just happens to target Mandarin speakers.
My comment was for illustrative purposes, with some assumptions backed by various news articles (a few random ones linked below). I should note that I have a NYC phone number and this specific Chinese-targeted scam is the source of basically all spam calls to New Yorkers (anecdotally, but strongly so based on everyone I know in NYC getting the same calls, and on the reporting indicating that SF and NYC are the prime targets).
[1]: https://www.cbsnews.com/news/whats-behind-all-those-chinese-...
[2]: https://www.pcmag.com/news/367491/chinese-embassy-robocall-s...
[3]: https://www.npr.org/2018/05/10/609117134/chinese-robocalls-b...
Should’ve stuck with the pagers.
No, I'm pretty sure this is very avoidable if phone companies put some effort into it.
Sometimes I just google “test credit card numbers” and read them off the dev documents for various processors. They almost always hang up the second it validates. I wonder if they realize the transaction won’t actually go through.
Almost any company can get one, and any person can get one on a VOIP line. (Yes, ironic.)
What I am saying is this -- I don't think Google solved the problem. I think you are just lucky.
When someone actually has a legitimate emergency, the emergency service provider is essentially overwhelmed by the volume.
Why is this such a big problem in the US?
https://www.ribbonfarm.com/2010/07/26/a-big-little-idea-call...
Imagine having a community-curated whitelist of numbers (plus the ones from your friends/family).
Serious question.
Most calls are known. Good calls can be classed at aggregate (for crowdsourced tools). Bad or suspect calls are either known or unknown and can be subjected to workfactor remedies.
So when someone calls you and you expect it to be bob, but it is steve the scammer, you can revoke bob's token and text him with WTF bob? How much did steve pay you?
I've caught so many companies either breached or selling data that it is not funny.
> Something went wrong
> We're sorry. This page failed to Outline.
I've noticed that a lot, lately, with Outline links posted on HN. Maybe sites have figured out how to block it?
But I don't.
> Democracy Dies in Darkness