FCC will require phone carriers to authenticate calls by June 2021 [pdf]
docs.fcc.gov
docs.fcc.gov
It should be relatively easy to identify the bad actors here and I don't mean the spammers, I mean the telcos that make this possible, deliberately so, by essentially "laundering" spam calls.
My response to picking up a number is to answer the call and say nothing. Auto-dial systems will route the call to a person when they get a "live" response. I don't know the criteria but I'm pretty sure it's them detecting noise on the call (which could be voicemail).
A human calling will wonder what is happening and fill the silence by saying something. A machine will not.
I hang up within 6 seconds of this in the hopes that it affects some metric somewhere of this being a low-quality or spam call. I don't know if it does. I think I read somewhere once that it did. I could be wrong.
If a real human is on the other end and does say nothing in this window, they'll generally just call right back. You get the exact same number again then this time I'll answer it.
It is nice to filter contacts vs non-contacts but there are too many things on non-contacts. Businesses you deal with, primarily.
In the email world where obviously spam is a huge problem zombie relays that allow this (which I believe is the primary source?) can get blacklisted. Why don't telcos who do this also get blacklisted? Or at least identified? This isn't AT&T or Verizon. It's the little telcos that connect to them.
But is this all too little too late? I think we've discovered over the last 20 years that we're all pretty much over open networks. It's all opt-in now with the likes of Whatsapp, FB Messenger and so forth.
Oh and while we're at it, can we get rid of this stupid exemption to robocalling restrictions for political campaigning? It's defended as "political free speech". To me, this is nonsensical. Free speech doesn't mean that I should be forced to listen to it.
EDIT: Found an example [1] of the bad actors I'm talking about.
[1]: https://www.theverge.com/2020/1/31/21117477/justice-departme...
That kinda/sorta was the mandate, until we put a telecom shill in charge.
"An independent U.S. government agency overseen by Congress, the commission is the United States' primary authority for communications law, regulation and technological innovation."
Source: https://www.fcc.gov/about-fcc/what-we-do
You can have arguments until forever about what they should or shouldn't do, but their raison d'être is to set policy according to these overarching objectives.
Oh, and just to be clear, the lack of an Oxford comma in that quote is inexcusable :)
In 2005, the FCC decided that ISPs should be regulated by them. From 2005 - 2012, Congress failed to pass new bills granting the FCC this authority. It was denied by congress. In 2015, the FCC decided that they didn't congress to grant that authority.
So yeah, the FCC website claiming they have an authority is not an impartial source. Two years later, the FCC reverted back to the Title I classification.
So for 2 years, the FCC claimed a power that they were not authorized to claim.
If Congress wants the FCC to have this power they can easily pass a bill granting them that authority, they have repeatedly failed to do so.
https://en.wikipedia.org/wiki/Net_neutrality_in_the_United_S...
It's inexplicable that the same party that claims the act establishing the FCC is more limited than the wording states while the federal arbitration act is continuously expanded to cover cases that neither the authors nor previous courts ever tolerated.
https://www.rpc.senate.gov/policy-papers/why-title-ii-is-not...
The GOP lays out an obviously slanted view about why they are opposed to the "utility-style" regulation that Title II entails.
However, this assumes that the market is functional when it's been clear since the '96 Telecom Act that it has been anything but. The idea that the FCC can't claim this authority without Congress acting first is FUBAR.
From pricing (generally higher for lower speed) to barriers to entry (the upfront cost for infrastructure is enormous), time has shown that carriers and ISPs will refuse to behave unless they are forced to.
Legislation is needed, but Republican arguments that a light touch will "preserve innovation" or some other nonsense doesn't work. 1993 was a long time ago and almost anyone who cares about this issue will tell you that Internet access is a utility (essential service, widely available, for reasonable cost) but the incumbent providers don't act like one.
(Save for maybe Google/WebPass, Sonic, and any number of municipal broadband initiatives)
What do you think about the 'Free Press' group asking FCC to sensor Trump's corona virus updates?
Does FCC have authority to do that?
https://thefederalist.com/2020/04/02/far-left-media-group-as...
Telco has not been a free market, ever.
Someday we'll have A.I. to screen calls for us, and hopefully it can also screen this highly-upvoted-but-worthless tripe from message boards for us.
If you pay upvotes and karma, you get unsubstantiated politicised arguments. The feedback mechanism rewards those comments.
The funniest one is when my fixed line provider (let's call it P) calls me on my mobile phone (which is another provider) and ask me if I'm one oh their (P) customer :-) (the explanation is that the mobile/fixed businesses are separated to avoid monopoly and, since they can't share customer data ('cos of data protection rules), they have to ask them again :-))
Since then, I only get such calls from companies that got my details in exchange for some freebie. I tell them I'm not interested, and would they please stop calling me, and they do.
The only calls I got recently were in English with a heavy Indian accent, "Ilse Smid" or another stereotypically Dutch name, claiming to be from Microsoft Windows, and that my computer had alerted them that it had a virus... These scam calls all came from nonexistent Dutch phone numbers.
Competition is only a solution for problems where the telcos' interest and the consumers' interest align. And that's very rare.
Otherwise, every hyperbole will have to be considered as irrefutable truth.
Or, is the 'who comes up with wittiest hyperbole' is the type of 'thought exchange' framework you would like to engage in?
Wheeler was born on April 5, 1946 in Redlands, California. He attended Ohio State University.[7] From 1969 to 1976, Wheeler led the trade group Grocery Manufacturers of America.[8] He then went on to work at the National Cable & Telecommunications Association from 1976 to 1984, becoming president of the trade group in 1979. For a year until its closure, Wheeler was president of NABU Network, before spending a number of years creating or running several different technology startups. In 1992, he became the CEO of the Cellular Telecommunications & Internet Association, a post he held until 2004.
https://www.justice.gov/opa/pr/district-court-orders-injunct...
Basically, he walks through the history of the phone system and how it never really considered bad actors, and then what they are working on now and what it'll take to deploy it.
I've encountered robots in the last 6 months that have started with "Hello?" when I didn't say anthing. It tripped up my Turing Test at first, but eventually hit an ALICEBot-like moment that crashed the whole thing down.
I work with phone systems. It's usually determined by how long they hear a continuous sound at the start of a call. If it's relatively short (and it can be adjusted by settings), it assumes it's a live voice (like someone saying "Hello?" is usually pretty short). If it's continuous for a certain period of time, it assumes it's a voicemail.
For our speech applications we have different behaviors depending on which call disposition is detected (that's the term for this, also determines things like invalid phone numbers).
Sometimes when testing speech applications I'll pick up and scratch the receiver continuously or speak without taking a pause until the voicemail disposition is triggered so I can test a voicemail message without having to check voicemail.
We make these calls on behalf of health insurance companies for health reminders and surveys, so our calls are more legitimate than most, but we do use an autodialer to reduce the load on our live agents.
Question you might know the answer to: I've noticed it's a pretty common practice to get appointment reminders with caller ID from the doctor's office. I like that feature. I'd imagine there are plenty of other legitimate use cases for caller ID spoofing as well. Do you have any idea how that's going to work with STIR/SHAKEN?
I'd guess it's going to be some kind of oauth for your phone number, where you own it and can grant spoofing access to other entities?
Google seems to be supporting it: https://ecfsapi.fcc.gov/file/1119583115056/2018-11-19%20Goog... (via https://www.fcc.gov/call-authentication)
If you call the missed call back, you realize the person picking up didnt make the call.
This is a naive assumption. I've come across robocallers that do exactly this. It is sort of trivial, if you think about it.
The time I told the robocall bot that this was very worrying because I was on my way to a driving test was actually true though. :D
I spent a full weekend texting back and forth with the scammer.
Although I never went as far as your lorry of circus animals, I did give _many_ hints to him that he was being played with.
Now, the more interesting part is that I was particularly fed with scammers and wanted to see if I could out scam one, which I did.
On the Monday after that weekend, I managed to get my scammers to provide me with his bank account username and password.
Once I got this information, I checked that they were correct credentials and stopped all and every contact. I also did nothing with it as I didn't want to myself be on the wrong side of the law, nor did I want to mess too much with a scammer and get myself in trouble.
I don't see how people can sit there and watch this live with him trying but normally the clipped/edited videos are pretty funny how much he can waste their time
A website they pointed me to had a multidomain SSL certificate gave me a list of other scammy domains, and one that appeared to sell robocalling software. On that site I found a phone number to call to get started. I called the number and somebody immediately answered! I pretended to be an interested customer for a while, and he claimed to be the author of the software. I wasted his time for about 10 minutes asking questions about how it worked, and where i could get lists, etc. Then told him I wanted him to add a patch to prevent my number from being called again, and that I'd be calling him again if i got anymore calls.
It was very fun!
The second and more common is to simply ask for their company name, their name and employee number, and their boss’s name. By the time I get to the third question they hang up and often don’t call back again. In my state you can sue for unwanted cell phone calls and the max you can get is something like $1200/call, which I am happy to inform them of. No clue how to actually do this but if someone automates the process of filing a suit, I will split the profits :)
Source: I've sent demand letters to vehicle extended-warranty robocallers using DoNotPay
I've never gotten enough information to file a complaint
The times it has failed me is, actually, right now. I put in a call to have a delivery, maybe the last four digits are 4700- I've plugged that number in. But the guy calling me back calls on 4709 and gets VM. So I have to remember to turn this off if I'm expecting a delivery.
I do the same thing. I moved and my old number is forwarded through google voice. Everytime i get a call from my old area code I know it is a neighbor spam call as no one calls me from that area code anymore.
It's gotten so bad i let my calls go to voicemail now.
Robocalls shove someone else's voice into your ear, without offering you an ear in return. They signal a synchronous communication, and then reneg on that promise with a spammed asynchronous message.
"Political speech" is the same as every other kind of speech. There should be no exemptions for policy just because someone running for office is involved. They have the same duty of courtesy as everyone else, and we have the same right to block our ears from their spam messages as businesses and scams.
No idea if it worked, but it was the least I could do to halt progress in the wrong direction.
I know nearly nothing about telco software but after working at enough big places I suspect one likely answer is "because it's monstrously complex for both technical and human reasons, moreso than it might seem at first".
My mobile carrier puts "scam likely" on calls that its algorithms have determined are likely spam, I wish there was an android option to just not ring the phone if that was the caller ID name.
It only bit me once in several years - I was expecting a call-back from a doctor and they weren't in my contacts. Missed their call, which caused a several hour delay and some annoyance (thankfully not for something critical).
Maybe after a few popular apps do that, the phone companies will start to fear losing relevance and finally take effective action against phone spam.
Given my experience with robocall and stuff, I _do_ want to be unfriendly. I hate to guts that a lot of people assume that they can interrupt you at any given moment. One guy called me when I was driving and wasn't having any of that, kept on complaining that I didn't pick up.
My current plan right now is to have a landline number from my internet provider (that's SIP essentially). Whenever anybody requires a phone number give that.
Now, there will be an voice mail device on my side with message: "Hello, you've reached p2t2p and his wife. We _DO_ _NOT_ appreciate your call. If you think your message is important, leave a message and we maybe, just maybe call you back. Otherwise, use email please".
And that is not even for bloody robocalls. Every single bloody prick think they are important enough to steal my time. Hey, I wrote you an email so respond to email, dumbass, don't call me. There were one windows installation company that stopped interacting with as soon as I told them that I won't pick up the phone and asked them to use email.
I guess the ultimate solution is to have my iPhone in permanent "contacts only" mode.
(Yes, I know, a significant portion of my email ends up in their hands anyway.)
In the above scenario that happened to me, sometimes you just don't have time to let the information find you.
Fortunately, I only get a few of those a week, so far.
I don’t usually answer my phone from unknown numbers, but when I get three calls from the same number within 3 minutes I’ll pick it up.
I'm surprised robocallers don't do this too
I called a local friend, he didn’t answer. I called his wife she didn’t either. Both follow the “don’t answer unknown numbers” rule. As do I.
It wasn’t until I called friend a second time that he answered the phone. His response? “When my wife got a call from the same number back to back is when I started thinking this must be worth my attention.”
I wonder if it would be possible to set up something like this more rigorously. Give everyone unrelated two phone numbers. The first never rings the phone. The second only rings if the first was called within the last minute.
This is why fax is still so common in medicine and law (in law there’s also a belief that a fax confirmation says it’s been delivered, if not read, while email is considered less reliable / more easily deniable.
Note that an individual has the right under the Privacy Rule to request and have a covered health care provider communicate with him or her by alternative means or at alternative locations, if reasonable. See 45 C.F.R. § 164.522(b). For example, a health care provider should accommodate an individual’s request to receive appointment reminders via e-mail, rather than on a postcard, if e-mail is a reasonable, alternative means for that provider to communicate with the patient. By the same token, however, if the use of unencrypted e-mail is unacceptable to a patient who requests confidential communications, other means of communicating with the patient, such as by more secure electronic methods, or by mail or telephone, should be offered and accommodated.
Patients may initiate communications with a provider using e-mail. If this situation occurs, the health care provider can assume (unless the patient has explicitly stated otherwise) that e-mail communications are acceptable to the individual. If the provider feels the patient may not be aware of the possible risks of using unencrypted e-mail, or has concerns about potential liability, the provider can alert the patient of those risks, and let the patient decide whether to continue e-mail communications.
https://www.hhs.gov/hipaa/for-professionals/faq/570/does-hip...
Mine have already, and I assumed it was becoming ubiquitous already.
I'm frustrated with it because I get multiple texts, multiple emails, and multiple voice calls & voice messages for every appointment I make. I want maybe one text reminder the day before or a couple of hours before and no more, just in case I forgot to set my own reminder. But usually I do have it in my calendar reminding me anyway, just two more notifications on top of the 10 the doc/dentist sends me... :P
I couldn't recommend doing so more. Text is so much easier, even if you have voicemail transcription.
They actually also emailed and texted us both so in reality there was no chance of us missing that specific message...
So now I can't help but answer calls from unknown numbers even though I know 999 out of 1000 of them will be spam. It's abusive and an incredible waste of everyone's time and energy, not to mention in my case I wasted 10 minutes of critical time I should have been with her at the hospital.
https://www.consumer.ftc.gov/articles/0204-family-emergency-...
In Australia a lot of it seems to target Chinese international students for some sort of visa-related scam ('Your visa is out of date, the police are coming, you need to pay your fees immediately in gift cards').
It would solve 99% of the problem just to be able to block all the calls that either 1. originate directly in other countries, or 2. that originate from number-ranges leased to carriers known to exist solely for the purpose of leasing numbers to VoIP/softphone/"app calling" providers; or 3. that originate from numbers that refer to the PBXes of companies whose business is to proxy foreign numbers to appear as local numbers. (Heck, once there's no more spoofing, we'll notice how big of a problem those are, and we'll probably get a law against them.)
See [1]
It basically asks the telecom operators to implement digitally signed certificates.
So it would work, if I understand it conceptually, like your web browser, when it receives https traffic unsigned certificate, or https traffic from a domain that's not part of the certificate chain.
Therefore, this mandate will prevent 'spoofing'. And without spoofing, the spammers would necessarely have to reveal their identity, and there are already bunch of existing legislation to prevent them from doing this type of business.
I missed important business calls when in US. Because they were calling using same area code where my sim card was registered, so I thought it was from the area local to me.
It is horrible, I am sure people actually lost not just business value, but also had negative health impacting incidents, due to this abuse of telecommunications.
[1] https://transnexus.com/whitepapers/understanding-stir-shaken...
I just ignore calls from my prefix. There's literally nobody in my contacts that has the same prefix I have, and I consider it extremely unlikely that any legitimate calls will come from there. 90% of spam calls come from my prefix, and most of the rest come from out of state (different area code entirely).
Another way is to just ignore all calls not in your contacts, and use Google voice's voicemail transcription (I think I've read about some way to do this with Twilio or another service, but I might be wrong).
The spoofed caller ID to match your local area code has landed on people in my contact list, and it was extremely jarring to think "why is my best friend's mom calling me out of the blue" and get offered a discount cruise by a robot.
All the major carriers are implementing a STIR/SHAKEN strategy that should be in effect by next year. But it is complicated to do and there may still be problems when they do - as others have explained here it's not as simple as it first appears.
I don't have any sympathy for the operators in this. They've profited from this for long enough and ignored the problem. There's a lot of pressure on them to solve it and the impression I have is that there's no appetite for "the dog ate my homework" excuses from regulators so let's see.
So far my guess is ‘the forties’. Or maybe the fifties, with all the ‘atomic’ ridiculousness.
The name in the post seems pretty emotionally neutral.
Right now, I guess I'm "spoofing" my caller ID by using a VoIP service unrelated to my actual phone provider to make outbound calls. My phone provider has every incentive to sabotage this, since this alternative provider allows me to pay probably something like 1% of the rates I'd be paying to my regular provider.
The VoIP provider verifies that I own the number before letting me use it as caller ID, but towards the network it still relies on the ability to send arbitrary caller IDs. Will this remain possible/will providers controlling someone's phone number be required to somehow enable this?
How will this work for call centers that want to send a central well-publicized inbound number from multiple locations?
Edit: So I read up on the protocol The SIP provider will provide a claim, signed with their key, confirming that they checked my number.
This leaves the possibility of providers having bypassable checks (I think mine e.g. let you set an arbitrary caller ID if you edited a HTML dropdown client-side) and "how to identify which provider is trustworthy", but that seems a lot easier to solve than the original problem.
I imagine we will see a tickbox in the operators apps and web settings portals to block or send such calls straight to voicemail (or similar), as they'd be able to be distinguished via the reduced attestation level.
Seems to target spoofing. If they can eliminate spoofing it should make tracking down bad actors easier which should ultimately put many of them out of business.
Pixels also have their own solution to this: If that condition occurs, the Google Assistant will answer the call and auto-decline if it is actually a robocall.
https://www.t-mobile.com/support/plans-features/scam-id-and-...
Also, their website doesn't have the option for me like it used to, and here's a thread on their site from 2018 that talks about it not being available to pre-paid users:
https://www.t-mobile.com/support/plans-features/scam-id-and-...
Here's also a thread about it on their site.
Regarding your actual reply, though, that basically means we shouldn't really hold our breaths for this to actually stop calls? :\ Just less fraud, which is nice, but from the only thing that makes these calls such a nuisance.
Because of this, you can just blacklist spammers again, and burner numbers for them become harder to come by.
Step 2 is to start to put the fraudsters in jail, now we can figure out who they are.
This also means easier blacklisting for the client.
I get this too. Which is great, my being a New Yorker who hasn’t had a driver’s license for close to a decade.
This.
Heck, I've lived most of my (middle-aged) life without ID and probably haven't used it in the past three years.
My U.S. passport certainly doesn’t.
(Agree that it’s a poor form of primary identification. It is bulky. It is difficult to replace. And it contains more information than you need for identification.)
Having it pickpocketed in the US would be far less of a headache, minus lacking an ID for a few weeks.
I don't know if it's actually Marriott or not. I suspect it's just one of those "affiliate marketing" scumbags, but it still makes the brand look bad.
I even hit them with "But YOU called ME with this extremely urgent notification! It's my last chance, you gotta help me!", but sadly I couldn't get her to give me a quote.
Knowing a number is legitimate is great, going after scammers and those that support them is better.
I'm not saying I never get spam calls, but I certainly have to scroll back quite a bit in my phone call history to see the last one.
Also, on the rare occasion I do get a spam call it's always from some random international country like South Sudan or Oman that I would never expect a phone call from.
What makes this problem uniquely hard to solve for the USA as opposed to anywhere else?
Most US spam calls originate outside of the US, though.
* Carrier maintainer blacklists and other tools have also been used by providers for a long time.
* My provider, Voip.ms, enforces a provenance whitelist by default. This block all SPIT calls coming from unspoofed caller ids. That may not sound like a lot, but yes, many of those calls are just random poeple picking their phone or mobile apps using the real phone number. Having regulation to track internal sources of SPIT (and enforcing it) helps too.
* In Canada, you can subscribe to a non-telemarketing list. That doesn't help for scammer, but it helps for unsolicited ads, political spam and private surveys. This works when enforced with actual penalties for all parties involved.
Would you decide to set it up to call over 40 different countries in europe? Each with their own way to show phone numbers.. each carrier attempting to block spam calls in different ways.. each country virtually speaking a different language.. most countries having some different banking/credit card systems..
Or would you target the united states which everyone in the country has the same phone prefix, pretty much all speak one language, banking/credit card system is the same, etc.
It just makes sense for scammers to target the US. You can target hundreds of millions of people the exact same way.
It's the price we have to pay for Freedom (TM).
The USA's implementation of caller ID does not require telephone providers to verify that the caller ID provided to them is real (prior to this order).
It also lacks the regulatory structure to "trace" (prosecute/fine) calls through the various interlocking copper, cellular, and internet telephony networks, even when each provider in the chain has data.
It also lacks the legal experience in knowing how (and the political will) to prosecute an individual who dials random phone numbers with an app on a cell phone using a prepaid SIM card and conferences whoever they're calling into a spam line to disguise the spam line's phone number.
Finally, our regulatory system is captive to politicians who depend critically on spam calls for political purposes, and continue to fight to have those calls exempt, making it vastly more difficult to stop all robocalls because some are legal and others aren't.
That and you know.. breaking the law has actual consequences for both spammers and telcos.
Back in the early 2000's I remember doing the same thing you're describing: startling spammers by telling them that I was on the list. But today, the people calling don't care because they aren't inside of the US.
If you're being called from a local number, then this should mean (and outside of USA actually means) that there's somebody who's subject to local law and fully responsible for ensuring that the spam laws are met. If you're a telecoms operator sending in calls to the nework, then you ensure that the fines get paid - the spammers are, naturally, liable, but if you enable access to scammers in an unreachable jurisdiction or insolvent shell companies, well, it's coming out of your pocket and it's your problem on how to recover these losses. In USA, however, telecoms who specialize in providing such access to phone spammers have a legal and profitable business model. This needs to change.
CID spoofing is when you tell the network to display a different caller ID value than the actual originator. This never had any sort of authentication in the US (until the announcement in the OP)
Most of the spam calls in the US aren't CID spoofed, but some egregious scams are. This is usually used for things like scammers displaying "SOCIAL SECURITY" on the caller ID.
The US just generally doesn't make carriers liable for the crimes of their users. We don't need to change that, and I don't think it's a good idea either because of the unintended affects that could have on accessibility. We just need to require controls that authenticate proper use of the network. The announcement in the OP is one step towards doing that.
But preventing CID spoofing alone is not going to stop spam calls from local numbers, because VoIP.
How does this help with a spoofed call from India?
Every time this topic comes up on HN, someone asks that same question.
Then there's a bunch of responses that are lots of suppositions.
Then several people from small European countries chime in saying they've never had a spam call.
Then a bunch of Europeans from large countries show up saying they get spam calls, too, and it's not just an American thing.
"Why is this problem unique to the USA?" is pretty much a meme at this point.
Also...
You start with "Why is this problem unique to the USA?" Then follow immediately with, "I'm not saying I never get spam calls" which means it's not unique to the USA. So your first sentence is invalid.
Europe is also a big pot of honey. But people speak all sorts of different languages, so you'd have to redo the scam in a bunch of different languages, which increases the effort needed to operate it.
China has way more people all speaking the same language, but relatively less wealth per person, which reduces the potential payoff. Also, I wouldn't be surprised if China has already closed off most the holes people exploit to operate these scams, because they seem less inclined than the US government to fart around about silly crap like this for literally decades on end.
Latin America has scads of people all speaking the same language, too, but they're split up among a whole bunch of different countries, which I'm guessing also makes the scam more expensive to operate at scale than it would be in the English-speaking bits of North America.
This means they'll exploit the most profitable targets almost exclusively. It doesn't have to be much more profitable, just the most.
If they were victim limited, they'd expand the pool of targets to include the most profitable N until they became resource limited again.
In the UK, I get the occasional spam call ("I'm calling with regards to the recent accident that wasn't your fault..."). At its peak, I got about one such call per week. It's been months since I've had a spam call.
In France, I got zero. In the 7 years I lived there, I got exactly zero.
Every time I go to the US, I get 2-5 per day ("last chance to renew the extended warranty on your car").
As is often the case, things are bigger in the US.
I used to get occasional spam calls on my rarely-used old Polish number, but since beginning this year they somehow stopped (late effect of GDPR perhaps?)
It's not. Who told you it was?
Experience reports are still useful and interesting.
The problem described in https://news.ycombinator.com/item?id=22742976
Is precisely why US get so many Spam calls, and very little in many other developed countries on earth.
And judging from that, it is also no wonder why SMS passcode hijacking is much common in US as compared to many other places.
It reality it really is an US thing, much like how rest of the world have public health care ( Good or not ), and it wasn't until ObamaCare did rest of the world realise public health services is not a standard practice in the wealthiest nation on earth.
Starting back in 2018 or so there has been a big problem in Australia with scam robocalls claiming to be from the Australian Tax Office. The area code on the phone number said it came from Canberra (Australia's national capital) which made it look more legitimate–even though in reality the call was coming from an overseas call centre. The robocall started out by saying that you owe a tax debt and the government was about to commence legal action against you. I got several, most people would hang up realising that the tax office would never do that. (It is illegal for them to discuss your tax affairs without confirming your identity first, so they would never begin a call by saying you owed them money.) But, some people (many of whom were older/vulnerable people), stayed on the call until the live operator connected. The live operator would then pressure them to go to a store and buy thousands of dollars of gift cards (such as Apple iTunes gift cards) and then read the gift card details out over the phone.
So this definitely is not a problem unique to the US. And other countries have been taking action, see e.g. in Australia – https://www.zdnet.com/article/acma-proposes-three-point-acti...
(Definitely the incidence of these fake calls appears to be falling, in my personal experience, so I think the Australian authorities'/industry's attempts are producing some results.)
I assume it's simply more worthwhile to create a fraudulent scheme aimed at a larger population with more potential marks.
a) it's a large market with a large penetration of internationally chargable credit cards. Several countries in the EU have their own payment systems including a bunch on a push model --- it's hard to scam germans over the phone because it's going to be hard to get them to send you funds without a german bank account; and if you have a german bank account, that's going to get you caught. Everywhere can process US visa and mastercard though.
b) large community that can be addressed with a single language; yes, there's a lot of people who would prefer another language, but they can probably be scammed in English (Although, with a bay area number I do get a good amount of scam calls in Chinese).
c) last, but probably most important; outbound calls to the US are incredibly cheap, as long as the number is not in Alaska. It's easy to find retail voip offers for less than 1 cent per minute to US numbers; and it doesn't matter if it's a landline or a cell phone. Calls to most EU mobile phones are at least 10 cents, but many countries are closer to 30 cents. That adds up quickly.
Until this HN post it never occurred to me that you could spoof phone calls. While landlines used to get lots of spam calls, perhaps I've had just two of these calls to my mobile in my life. Each time I typed the number into google and found reports of that number being spam. And maybe less than 20 spam sms's.
Does this mean that other countries (such as Australia) do not allow spoofing of numbers?
Will be nice to go a step further.
Some have provided timelines (such as AT&T), others skirt around it basically saying that they offer call SPAM protection already but that they will go along.
If that were easy we would have solved email spam too, 20 years ago.
The legitimate use case is basically: I am placing this outbound call over VOIP or a different phone line, but I want this ANI to show up on the callee's phone, so when they call back they go to the correct line (dentist's desk, software sales line, whatever)
The goal of the regulation is to cut down spam/scam calling, not legitimate uses, and the telecom providers know these uses and lobby heavily to make sure they'll still be allowed to work.
The telecom providers don't like scam calls either, or more specifically they don't like short calls. All the work and compute power in telecom is used to set up the call, then the cost of keeping it going is minimal so the longer the call goes on, the more economical it is for the provider
Based on the given situation, the museum won't own the caller's cell phone number that they're trying to legitimately spoof for their staff's cell phone.
Asterisk is an open-source PBX system.
I think the original call will come in with the correct STIR/SHAKEN-validated SIP headers and the PBX can forward them as is, see some discussion here: https://community.freepbx.org/t/stop-robocalls-act/60921/5
I previously worked at a telecom software company, and I know everyone with their shit together has been preparing for this for a long time, which is why I'm not concerned that these common cases should continue working. These softwares are often built on top of or on a branch of Freeswitch/Asterisk.
I've thought about some potential SaaS products that would leverage a similar approach. But I would authenticate the number back to the customer before allowing it to be used to avoid spam/malicious use.
Based on this:
https://www.zdnet.com/article/at-t-comcast-successfully-test...
I'm guessing this is down a layer at the provider level. So in my case, voip.ms would verify the number I'm using as my caller ID is actually a number that comes back to me. Right now, I just tested by swapping my wife's cell number in, they do not validate this. Now I understand how people are spoofing numbers so easily.
Obvious approach is to voice call or text the number and require the confirmation code to be entered on the website. Just curious though if there are other requirements or if this is up to the provider.
I think the telecommunications world will need to adopt whitelisting instead of blacklisting. I run a whitelist-based robocall blocking service called CallStop and a lot of customers have straight up given up using their landline, or their personal number with unknown numbers.
People who claim that whitelisting is a bad solution because it could block an emergency call don't realize that many people don't answer unknown calls anymore--and I don't think SHAKEN/STIR will change that.
Whitelisting without SHAKEN/STIR is still extremely functional.
There are billions of unique American numbers possible, and with 250-500 average contacts per random dial, contact spoofing is not statistically significant.
They usually hang up at 'blacklist'.
...But it will equal-and-oppositely create a market, perhaps a black market, for anonymous voice calls on the other... Perhaps these would be delivered by an open source Voice-over-IP program which uses an anonymizing P2P network as its backbone...
Also... will it make any difference for phone calls that originate outside of our country?
Now, those small observations aside, I think that hard authentication of the source of phone calls, is a great idea to help combat scammers and robocalls... I'd use this service myself, and I know other people that would be immensely benefitted from it...
Unless I'm missing something though, these measures don't do anything to address the gaping security hole in mobile networks around roaming interconnects. That seems to still be a pretty good way to do SMS and call interception, which are increasingly valuable as phones become the de-facto 2FA channel for access to banking, cryptocurrency services and more.
Before that, I'll keep allowing calls from my contacts only, and bear the miserable inconvenience that sometime my packages may take a month to arrive because of denials of calls from the delivery guy.
Turns out they're still doing that robocall scam where they say you won a free cruise
Google Voice works by acting as a proxy for outbound calls. You dial your friend's number, your phone dials Google, who in turn dials your friend with your Google Voice number displayed. Since Google is the legitimate carrier for your Google Voice number, I can think of no reason why they wouldn't be able to correctly sign the call.
Additionally, Google is listed as one of the companies that the 14 companies that the FCC appears to be working with (see the table towards the bottom of https://www.fcc.gov/call-authentication), so I assume they are planning to use it for Fi and hopefully Voice as well.
Had to hop onto my VPN to view.
Edit: Ok, at least not viewable in the UK!
The Do Not Call list has been around for almost 30 years.
It will be interesting to see who will be running the CA for these connections.
* http://jdebp.uk./FGA/truths-about-telephones.html#CallerID
"The FCC has also called on the industry to “trace back” illegal spoofed calls and text messages to their original sources."
These concepts could be applied towards that purpose if the MNOs wanted to rejigger messaging within their networks & for inter-carrier connectivity- but pursuing that solution would likely be more challenging to implement than this solution.
I live in a country where cellphone carriers are legally forced to authenticate users. And this data is used against political opposition and journalists.