T-Mobile says it blocked 21B scam calls this year
bleepingcomputer.com
bleepingcomputer.com
* T-Mobile, like the other carriers, is offering a numerator and not a denominator. These call filtering services are plainly valuable, but it's difficult to evaluate how effective they are based on current public evidence.
* It isn't a coincidence that the top robocall destinations include locations that are popular for retirement. These scams disproportionately target and take advantage of older customers.
* Call authentication (STIR/SHAKEN) is helping, and will continue to become more effective. The FCC did not push carriers to rapidly adopt call authentication during the last administration; Congress eventually stepped in with the TRACED Act, and the FCC has since made STIR/SHAKEN a top priority.
It is reassuring to see the stir/shaken “checkmark” on my iPhone call log indicating that the call has been authenticated. Unfortunately as you say it’s not very effective yet.
I’ve noticed that there are carriers/voip gateway providers who are proactive on shutting down spam emanating from their networks and others who are not. Not affiliated but the list here seems to be accurate: https://scammerblaster.com/the-ultimate-method-of-scammer-pa...
Holy crap. That's six a day. I would have thrown my phone away.
I also received a lot of other scam calls targeting older folks: namely callers impersonating Social security administration officials who scare you into sending thousands of $$$ to them so you avoid getting arrested - you’re told that your SS benefits are suspended and you’ll be charged with a crime because your SS# was associated with some vague crime in the “southern border of Texas”…
It’s honestly sickening to see in real time how these low lives fleece innocent people and it makes me furious. I do what I can to try and shut them down but I’m sure it’s just a drop in the bucket and they just pop back up with a different voip provider in a few days anyway.
They can be very persistent and they will track your “identity” for years. I had invented a persona back in 2015 and forgotten about it. Someone called several dozen times - very aggressively - asking for that persona. I had fun messing with him but it was scary having him pull up personal details from over 7 years ago even if it was totally fabricated.
Why is there no way to find the people who are making these calls and why are the phone companies not liable for allowing these calls to be made without accountability?
If the FCC mandated a $1/spam call fine for cell phone providers (automatically paid as an unbounded rebate to subscribers), I suspect they would fix it in under 12 months.
More reading on the protocol (Signaling System 7) is here:
https://en.m.wikipedia.org/wiki/Signalling_System_No._7
The fundamental issue is that is assumes 100% of global telephone exchanges are trustworthy.
I vaguely remember an interview with somebody involved in early ARPANET standardization efforts stating pretty definitively that the prevailing direction for network protocols was source based routing. Anybody who has ever had to write an email address parser has seen vestiges of this (multiple @, ! and : symbols). Supposedly a representative from the NSA helpfully "suggested" they abandon that line of thinking and just mimic the PSTN's approach of trusting the next hop to do the routing.
I wonder how accidental it is that SS7 was implemented in such a plainly insecure manner.
"Five U.S. states, Costa Rica, Guatemala, India, Mexico and the Philippines are where most robocalls originate."
I imagine it's much more complicated to prosecute robocallers that live overseas, as you're now dealing with having to extradite people.
Won't solve everything but maybe a little bit.
It’s an easier fix, but not really a solution.
The reality is that everyone wants fairness but no one really wants government regulation (Russia is a great example of this where your phone number is essentially treated like an assault rifle. Registered, monitored, and geo-tracked).
They are providing me a phone but most callers are spoofed and it can't be answered any more in the way a reasonable person would expect a phone to be useful.
The only thing that has made email remotely usable is that the service is concentrated in a few providers who spent a huge amount of effort to minimize the spam.
It's classic tragedy of the commons.
Obviously we don't have authenticated caller identity in the phone system and you can argue that would solve the problem of spam. No argument it would help but I very much doubt it would solve it.
For awhile you were able to IM Gmail users from outside Gmail (through XMPP). This was unsurprisingly shut down because the likes of Microsoft (Hotmail) didn't reciprocate (ie Hotmail users could message Gmail users but not the other way around).
Spam on phone networks continues because bad actors profit from it. For example, spam traffic is "laundered" with legitimate traffic so the exchange itself isn't blocked by other parties. It also gives plausible deniability.
These things are all inevitable consequences of federated communications systems.
It's a shame that (just like TCP/IP), SS7 was designed in an era of good faith and didn't have security baked into it from the start.
I think I get up to 5 spam calls a year (up in the north of Europe; knock wood).
Only of ones that have historically existed with these flaws.
One of the reasons I think urbit is cool is that the non zero (but low) ID cost solves this economically making spam non-viable and moderation easy.
I was also bummed that federated systems seemed to have these core issues that lead to centralization. It’s also why I think the non-urbit attempts at federation are DOA. To fix this for real you need to fix the entire stack. The problem is upstream from the application layer.
Your analysis of the flaws inherent in federated systems is right, but you’re wrong that it’s an inevitable consequence - it turns out there is a way to solve the incentive problem and avoid them.
Yes and: Many purists (utopians) continue to oppose infra for authenticated speech. Despite all the evidence, experience, and logic.
I wonder if this stubborn naivety comes from our modern geek creation myths. Wasn't it Ender's Game (Orson Scott Card) that had some kids conducting a Greek dialog in public, arguing both sides, anonymously, shaping the zeitgeist, thru their amazing rhetoric?
As if. If allowed, noise always overwhelms signal. More as the production costs of noise approaches zero, driving the cost of discerning signal up to infinity.
(What geekling hasn't read Ender's Game? Imagined themselves as humanity's savior? Huh. Now I wonder what fables Harry Potter reading Millennials will unwittingly foist onto the world, when it's their turn.)
This is a global problem and no single country or company can be expected to fix it on their own.
I'd be shocked if most of the US's spam doesn't come from within. I'm not against attempting a global body to regulate, but I doubt it would work. We can't even get internet providers to ensure their traffic isn't spoofed, and that's just firewall rules.
Edit: maybe not shocked, but personally the only out of country voices I hear now are when I call GoogleFi support.
Something interesting happened I think a few years ago, when a hosting company in the US that turned out to be the major hoster for spammers went down for technical reasons and the world went spam free (by 90%) for a couple of days. You'd think it was obvious what to do... but nope, once the hoster was back everything was back to normal like nothing happened.
I also suspect that a lot of spam calls are coming from within the prison system - not prisoners trying to run scams off payphones, but actually working from a phone bank at a prison for a nickel an hour. It's the only thing I can think of that explains their dogmatic adherence to the script in front of them. Free scammers from overseas will start insulting you once you're onto their scam; free scammers from the U.S. will typically just hang up and try again; but if you're a prison worker, the punishment for going off script is much worse than just losing your job.
Wish I could prove or disprove my theory.
Not all of them, but enough that I don't think messing with them is morally justifiable.
I also don't think making it psychologically hurt is going to make any difference, especially not when you're asking them why their fellow countrymen shit in the streets. Based on what I've heard and read, a lot of them justify their work by villainizing us in their eyes. Which isn't unfair! We're vastly richer than them, and they don't see any particular problem in what they see as being a Robin Hood-like character. Insulting and abusing them just further justifies their actions in their mind.
I used to try to waste their time as well, but after I postulatede my prison-work theory, I no longer do that - they don't have a choice, and it's cruel to put them through that.
Year 2020: 40k complaints about 18k phone numbers (12% from outside Germany) for predictive dialing. 155k complaints about phone spam (company trying to sell you something). 1.3 million Euros in fines. https://www.bundesnetzagentur.de/DE/Vportal/AnfragenBeschwer...
I received one spam call in 2020.
But the current system has people blocking those spoofed numbers, so its effectively doing that now. Google phones give you a fast button to just block the number, despite knowing its likely spoofed.
I’d request two features.
- Some API that allows apps to get through (like door dash)
- Ability to disable for a brief period (30min? A day?) when expecting a call from an unknown number.
This is a far better solution than the blacklists that hardly work.
I received about 25 calls per day on average that slipped right through their service.
Senior health coverage, car warranty, etc calls. All using spoofed caller ID. All using the same technique of call screeners in India or similar that then forward the calls to US companies buying the leads. I actually had a conversation with a U.S. based insurance agent that was buying the leads and told her of the spoofing and other shady techniques they use. Her response was, “They supply good leads so I keep buying them.”
Anyway, I switched to Verizon and it is no better. I ended up setting my phone in Focus mode 24x7 and whitelisted almost my whole contact list. It was either that or change my phone number. Can’t concentrate on work when you’re being called every 20-30 minutes.
We need to fine companies that continue to route these calls. It is not like tracing is impossible.
Turns out, T-Mobile charges businesses a fee (I want to say they said something like $250/mo?) to allow messages through even though I opted in and wanted this communication.
Seems a little bit like they introduced a "solution" but then can simply charge to profit off letting people through the solution?
I want my phone to give me the option to only let authenticated calls through and give everybody else a busy signal. Today, the ham:spam ratio of my phone is worse than my email.
I have no idea why I'm even allowed to get calls from V11109011700119 on my cellphone. They're so clearly scams / spam that every carrier globally should close these down.
So they may as well use "I am a spammer" as their Caller ID.
I wonder if formatting the number this way allows them to circumvent spam lists, but doesn't trip anti-caller ID spoofing mechanisms?
Still, I like seeing "Scam Likely" when a robocall comes in. Too bad they insist on engaging my voicemail - my least time-wasting option is to just pick up the call and immediately hang up. I'm extremely lucky that my cell phone gets only a few of these a week, but that's annoying enough.
T-Mobile prepaid is odd. It is almost like it is an MVNE using T-Mobile's network rather than a part of T-Mobile. When I switched from postpaid to prepaid, for example, the T-Mobile mobile app stopped working. It says "Sorry we're not ready for you yet. We're working on improving your app experience" and suggests using the website instead.
Checking on their forums, I see it has been doing this for years. They used to say they were working on it, but they stopped saying that.
Still, I find it worth it because of the savings. I just need voice, text, and a small amount of data. The cheapest postpaid I see at T-Mobile that would be open to most readers here is $60/month for 1 line [1]. Verizon and AT&T seem to be a little above that.
My prepaid T-Mobile plan is $15/month (around $17.something with taxes and fees, which are included in the $60 for the postpaid plan).
[1] They have a plan for people 55+ which has about the same features for $40/month (plus taxes and fees, which are included in the $60/month plan). This puts them way ahead of Verizon and AT&T, whose "senior" plans are only available to Florida residents. WTF is up with that?