I'm still blown away at how hard it is to get people to use any encryption, even people who work in infosec/etc. If nothing else, 2020 was a great year for the uptick in using crypto to communicate with non-technical fam and friends.
I'm still blown away at how hard it is to get people to use any encryption, even people who work in infosec/etc. If nothing else, 2020 was a great year for the uptick in using crypto to communicate with non-technical fam and friends.
There is actually encryption technology[1] available that would solve this or at least make it traceable and blockable. But here we are.
[1] https://en.wikipedia.org/wiki/STIR/SHAKEN
Edit: Also the political situation at the time was that if Clipper was adopted, all other encryption technology would be outlawed. It was a very scary time.
Robocalling with spoofed ANI has been a problem long enough that I think we can safely say the network operator is 100% complicit with this activity now. The phone company could track down kids war-dialing blocks of numbers in the 1980's in order to make sure they were not telemarketers not paying higher telemarketing fees. Do people really think the phone company is not getting a cut of these robospoofers?
Anyway, we're getting shaken/stir or whatever RealSoonNow(TM), so we'll probably have better CallerID. I don't think it'll be enough to solve the problem, without a reporting mechanism, but I guess we'll see in the next couple years.
So where is this magical solution you speak of? We're all products that the phone company sells to telemarketers, there is no incentive for them to give us these tools now.
Again, the clipper chip would have made it difficult for anyone to pretend to be someone they are not, cryptographic signature is part of the deal to ensure you are talking to who you think you are talking to.
IP ranges have registrants. Servers usually are assigned IP addresses temporarily by the registrant, or by someone the registrant has assigned the block of addresses to by some other means. This means differs from region to region. In the US the responsible party is ARIN, and registrants can reassign addresses using a database called SWIP. In the EU both registrants and their partners use the same database called RIPE. I have never registered addresses in other regions.
> then people do report this to the owner of that address?
Yes. Registrant again, but yes. And if you don't get satisfaction, then you can (and should) escalate all the way to the region's authority.
Email has a "from" address that the SMTP protocol (the thing that often carries emails) that is separate from the IP address of the sending server, the exact same way "CALLER-ID" is a separate field from the billing address (called ANI, or Automatic Network Identification) in telephone networks.
Requiring that ANI match CALLER-ID would break many voicemail systems and call-forwarding systems. They can be fixed, but it will be expensive to do so.
Similarly, requiring the email "from" address agree with the SMTP server's responsibilities breaks mailing lists and email-forwarding, and again, this can be fixed, but it is proving expensive to do so.
1) That the source IP address be from a range 'controlled' by the operator of a given AS. This might be proven, semi Out of Band, for a duration by a PKI challenge with a key representing that authority. (Allows distributed services on the same IP anywhere. Fulfillment can be asynchronous if UDP.) Edit: This would also be how to securely claim an AS route; you might still need a link authorized for this level of service.
2) The mentioned feedback mechanism should be coupled with 'do not forward me anything from IP || net/mask for X time' via a similar mechanism. A reason might be provided, reasons of clear abuse MAY be aggregated and used to isolate misbehaving hosts / networks.
I live in the EU and have literally never gotten a robo call in my life. It's a political problem, not a technical one.
Yes, if the internet community had acceded to their demands to use the clipper chip, that would have been one route to them lowering the barriers they had put in place to encryption. They also could have just recognized that widespread encryption was in the national interest without the clipper chip, instead of deciding it was opposed to it.