Washington’s new anti-robocall law won’t stop the calls
wsj.com
wsj.com
https://www.atis.org/sti-ga/resources/docs/shaken-faqs.pdf
As the article mentions, there are some shortcomings. Caller ID spoofing is necessary for some services, as in the VOIP world calls are broken up into termination (dialout) and origination (dialin). If STIR/SHAKEN takes hold, the CID phone number for termination will have to be signed by the origination carrier. It should be fun to watch the carriers handle it. (There are 3 levels of attestation, but that's the gist.)
Bandwidth.com also has a good overview:
A = I know the customer, they own this number.
B = I know the customer, can't confirm they own this number.
C = I'm sending this call out, but I know nothing of the customer or this number.
Carriers sometimes don't want to receive anything other than A, because its probably useless to them. By that I mean, if it's not A, they don't want to be sent the attestation level or identity header at all.
Inteliquent (aka Neutral Tandem, Onvoy, Exiant, Vitelity, plus 20 other sub-brands) is the only provider implementing this protocol outside the cellular industry, and most of the CLECs they work with are not capable of maintaining SIP with a TLS certificate, let alone their own PKI as STIR/SHAKEN would entail.
Whether or not it's a premium service will probably depend on the carrier.
As for your original question (blocking), I'm not sure. It's certainly in the realm of possibilities and carriers' fraud departments will have to decide what to do with it.
I'd guess about 1/3 of robocallers are leaving me voicemails now. I also very recently started getting obvious phishing attempts via SMS.
I had the California DMV try to reach out to be about some form inconsistencies and they only contacted me by phone and voicemail. (To their credit they left me 3 voicemails through a very busy day I had.)
There was no other way they were going to contact me before letting my car registration expire.
Sorted it out, but barely. Very frustrating to have that sort of outcome from the root cause of phone spammers.
This is the real loss... missing calls I would have wanted or needed to answer.
But I havent gotten any spam calls in over a year ever since tmobile started blocking them for me. Are the other providers not doing this?
Interesting, since my mobile hotspot gets dozens of spam text messages from Seattle-area car dealers each month.
I did just switch to T-Mobile and they pass "SCAM LIKELY" as the caller name so I may start declining those.
Filtering out any number that shares my area code and first three digits and not in my phone book would go a long way to getting rid of spam.
My wife received a call from a person who was angry at some phone scammer and started cursing her and telling her not to call anymore. My wife tried to explain that she did not make the call, that the number was spoofed, but to no avail, the curses continued until they hung up. I find this kind of breach quite problematic and don't really understand how it can proliferate to this extent.
Filtering by number is a lot easier when you have a number with a small state's area code when you have not lived there for some time. All unknown callers from that state are then easily identified as spam with 99% probability.
The true future of AI is robots sending eachother spam.
With modern VOIP I’d be surprised if anyone compiles lists of possible marks: your outbound traffic can be way more than before, so why not let the computer call everyone and see who bites every time?
Note: I'm lying about Do Not Call. It's just another way for people to learn your number has a real person behind it. But the synchronization between the Federal list and internal systems of callers is a shitshow so actually reputable mass dialers will just assume they missed you and add you to their internal list. (Edit: So of course I don't report people. Even if I was really on the list, that takes time and has essentially no return)
One person insisted on trying to sell a car warranty so I ramped it up a bit. I'm only a little sorry that the person was apologetically crying about "interfering with emergency services" by the end of the call.
(If robocallers don’t leave voicemail...why?)
I don't do either, because the spam calls I get are in a language I don't speak, and my voicemail is full of messages in languages I don't speak.
I have to resort to "if it's important, someone will e-mail me or send a letter," which ten years ago used to be the biggest vector for unwanted contact.
I also get warranty spam calls that leave voice mails too.
If people want to get a hold of me they can text or email.
Not sure if that is legislation, technology or culture/economy related, and whether it's an active solution or it just passively works out.
But what stops the US from doing whatever it Europe is doing to not have tons of robocalls?
For one, making calls costs money. How can robocallers actually do multiple calls at the same time at a reasonable price in the first place? And then this spoofing: isn't the solution against that technological rather than legislation?
EDIT: A thing that gave me the impression the problem is much bigger in the US than Europe, is that the first time I heard about robocalling was in a Simpson's episode from 1996. So autodialers seem to exist for a very long time already in the US, but in Europe they're not really being used (that I know of. If they were used at large scale, I'd have noticed I guess?)
It gets a lot cheaper at scale.
> And then this spoofing: isn't the solution against that technological rather than legislation?
"Spoofing" is just a name for using caller ID you shouldn't. There's no tech solution for it... unless we create a global federated registry that can be queried online, a new phone network which cares about it, and migrate every phone in the world to it. POTS will be alive longer than us.
Why would there be no tech solution around fake caller ID? The phone company knows who it's billing for this call, doesn't it?
It seems like it's on the rise in the UK https://www.which.co.uk/news/2019/10/whos-really-calling-you...
As for the capability, in many ITSP companies you can sign a paper saying "I promise that all the calls I'm sending have a valid callerid" and get no restrictions.
I imagine so. It is quite easy to test. Here in Canada, if you verify your phone number with Google Hangouts [0], calls you make using Hangouts Dialer or through Gmail interface will show it originating from your phone number, even though it is originating from Google servers, not your phone. It seems Hangouts Dialer is available throughout EU. Have you tried using it?
I remember playing around with that on my rooted Android phone years ago (around Android 2.0-2.2) in germany.
It would probably be possible to discard this information from the client and overwrite it as the service provider, but they weren't doing that at least back then. It would also be costly (like a MitM proxy overwriting headers)
That was around 10yrs ago though. Might have changed by now.
In a previous HN discussion, it was pointed out by people in Germany that it does exist, and is a big problem in Germany. I don't know about the rest of Europe.
Oh please. The internet hasn’t been “gutted”. Far from it. It’s getting faster. It’s getting cheaper. It’s becoming more widely available. Do you have any evidence, anything at all, that the internet has been “gutted”?
And you’re going to tell me with a straight face that the internet has been “gutted” for the vast majority of its existence? Don’t be ridiculous.
I feel like any other solution adds yet more complexity and I would argue the only thing that should be necessary to make calls is an internet connection.
Some VOIP applications already accept calling via IPv4/IPv6 addresses.
same with email addresses -- this is some combination of your identity and a license to spam you
spam protection is the main feature of gmail because email wasn't designed with fraud in mind -- an email system rebuilt from the ground up for 2019 would be safe for medical information, receipts, not be the giant password reset security hole that email currently is, and not allow randos to spam you
every new product designed in this century needs prevent fraud by design (including spam)
By design, only people part of our organization can communicate with each other. There (AFAIK) is no endpoint for my organizational teams account visible to other teams users outside my organization. For spam to occur, someone's account would need to be compromised (which would be found quickly) or a fake account somehow created by the org admin (which seems unlikely).
With email, the IT department is commonly spoofed, or the president, HR, etc. Most people can spot the differences, but with teams they would virtually never get any fraudulent messages.
Every outbound call should cost $1 to the terminating carrier. ATT, Centurylink, Etc. Recipients can mark spam calls (*69, an app, whatever) and the dollar is split between the carrier and consumer. After 60 days the money is returned for calls not marked as spam.
No calls are connected that don't include this advance this money.
Now, the assholes who dial 2,000 people a minute will need to afford $2,000 a minute of credit to run their operations.
Carveouts or credits can be extended to bona fide groups such as political parties, 503c, etc.
Over time, trustworthy callers will have a revolving account or insurance to cover the costs. Untrusted caller no longer can afford to make calls.
As this forum attests, this commercial activity is destroying the worldwide utility of a vital communications channel for everyone.
I've owned a landline phone that had a blacklisting feature. A little useful, except everyone got one shot ... until the available memory slots were used up. I bought it.
Why any phone with a CPU would not offer a whitelisting option is a mystery. Not on the list ... zero attention paid.