Report to Congress: Robocalls and Transmission of Misleading Caller ID
fcc.gov
fcc.gov
> The Commission does not collect criminal fines for violations of section 227. > If a party fails to pay a forfeiture, we refer the matter to the U.S. Department of Justice for further enforcement action. We have referred to the Department of Justice forfeiture orders involving violations of section 227 by Adrian Abramovich, Marketing Strategy Leaders, Inc., and Marketing Leaders, Inc. (Abramovich), Philip Roesel, dba Wilmington Insurance Quotes, and Best Insurance Contracts, Inc. (Roesel), Affordable Enterprises of Arizona, LLC, and Scott Rhodes a.k.a. Scott David Rhodes, Scott D. Rhodes, Scott Platek, Scott P. Platek (Rhodes). 34 During calendar year 2020, the Attorney General did not collect any forfeiture penalties or criminal fines for violations of section 227 cases that the Commission has referred. We lack knowledge about the U.S. Department of Justice’s collections beyond those cases.
It said earlier that these entities owe tens of millions of dollars in forfeitures. Why were they not collected? If these criminals know that there’s no penalty, they’ll continue acting badly. (And we can see already that they do this. They change names and start over.)
Referring the issue to the Justice dept is really the only thing they can do. I think this goes for all independent agencies. Of course, once it's referred over there, it goes in the big tumbler of prioritization for the FBI/US Attorneys.... and I'm not shocked they wouldn't immediately jump on a non-violent, extremely technically complex case.
First hand statistic attesting to it, watched it happen right before my eyes in a Texas court (except the other kid was being charged with his second DUI).
Cops specifically love weed being illegal because they can "smell weed" and use that as a justification for a lot of things.
Like startups, criminal prosecutions don't have a 100% success rate. The system, despite its flaws, has a lot of protection for defendants. So you're basically asking the taxpayers to speculate on your pet project. Sometimes they do, sometimes they don't.
Here we're primarily talking about collecting civil forfeitures. DOJ can go scoop up assets they find, and defendants can try and claw them back (and the DOJ only requires a preponderance of the evidence to keep the money).
Maybe the fines could be used to pay for future prosecutions? Or maybe let the justice department outsource prosecution to private sector attorneys who can keep most of what they win? Doesn't California do something similar for ADA cases?
Telegrams gave way to phones, but it was never possible to spam someone with telegrams, and they had a cost per word.
On top of that the telcos are joining in on the fun. I am an AT&T cell phone subscriber and in the last month they’ve started robo-calling me non-stop to sign up for their ailing DirecTV service. Who in their right mind would subscribe to that with all the better streaming options available? But the worst part is that they technically aren’t breaking the rules themselves because we do have an existing business relationship (if you can call paying my bill on time and doing everything in my power not to otherwise interact with them a relationship).
I recently got one of those, and I'm not an AT&T customer.
Oddly enough I remember DirecTV doing this ~20 years ago. It was the first time I was willing to pay for CallerID. DirecTV (or some representative that had that as their outgoing name) called me several hundred days in a row. I ended up making a game out of it, seeing how many times they’d call back if I never answered.
It's bizarre that AT&T would sabotage the usefulness of their own customers' telephone service, but this is a bizarre world.
Large swaths of the US can't get usable broadband. These people use satellite TV services. Of course that market is already developed so growth requires pestering the people with better choices available.
"Yea, so here is an app you will love! Install it, and it allows anyone, anywhere, anytime, to interrupt whatever you are doing on your device, background whatever app you are running, cause it to ring, buzz, and notify! Further, if you press the green button, it will allow that random person to start talking to you."
Even if it managed to get past either of the app stores' rules, who would install such an intrusive app?
Yet, every smartphone sold today has that exact annoying app pre-installed!
Also, what if you could set time and day for availability - i.e. for work related numbers.
A large weakness with existing communication systems (phone, e-mail, physical mail) is that its a pipe where anyone in the world can blast at you, often anonymously.
But you were right about one thing, telecoms do profit a lot from the robocalls.
If I get a robocall, my carrier owes me $100. They can then collect $100 from the peer they got it from, etc.
This will cause carriers to only peer with good carriers, not fly-by-night VoIP clown shows.
I will set up a front company, and create thousands of phone customers that are hard to track back to me. Then I'll have my front company call all of my 1000 fake customers repeatedly. Those customers collect $100 each for every call from the phone carrier, and when the phone carrier tries to collect from the originator, poof, they don't exist anymore.
Very likely, if this $100 fine came into play, the first change telcoms would implement is verifying every single line in and out to make sure this exact situation can't happen. Will be cool to need a passport and birth certificate to get a new phone number.
In many countries, it is impossible to get even a VoIP number without showing an ID, and in some (like Bulgaria) it should be a local ID.
In Europe, esp eastern europe, like Bulgaria, there's a vast market of stolen phones, stolen or resold sims. You'll have to ditch them after several weeks of course. But it is not in any way impossible.
I'd guess it's the same in Americas.
It's been several years since I worked at an MVNO, so I can't say much about how do you get number capacity nowadays, but back then that was literally the least problem imaginable.
Telephone numbers used to be handled pretty much like IPv4 addresses. A telecom would get a block of numbers and distribute those to their customers. It wasn't really possible for you to move your number from one carrier to the next.
The 2003 rule change around number porting forced a bunch of upgrades to telecoms to make it possible for any phone operator to send out a call for any number.
Are you trying to claim that's the reason that anyone can forge a number? Because I don't buy it. Just because you're forced to accept an inbound number doesn't mean you don't log where the number came from -- the peer service provider at the very least.
And then what are you supposed to do with the peer service provider data? How the heck does that help an operator?
The whole point is VOIP and the porting rules broke the implicit trust relationships that used to exist, and the low level call routing protocols don't have a solution for that - because it could have never been a problem before VOIP and the new porting rules.
Until the underlying call routing protocols for long distance get enhanced, this problem isn't going to be fixed any time soon. And I'm not holding my breath on an overhaul of what is fast becoming legacy infrastructure. And in a VOIP only world establishing trust will be no easier, maybe harder, than doing so with email today - so that's not the answer either :p
Actually if phone providers would prefix calls from VOIP gateways with an asterix then I could set up a rule to just force all of those to voicemail by default. Would probably kill 90% of the bogus calls. Hell I'd pay an extra $5 a month for that feature.
I don't think my cell carrier is making anything on the spam text I get. At this point, it's also a negligible cost to them.
With that being said, I'm tired of the carriers / phone creators deciding when I want to answer my phone.
An example of what I'm talking about: https://discussions.apple.com/thread/251165362
My bank was trying to get a hold of me due to them turning off autopay, and I wasn't answering their calls because it doesn't show a phone number or anything. Just "Spam Likely"
IMO I'd rather see all calls coming to my phone, and send them to VM if I want. Devices nowadays even have the capability to block calls from outside your contact list if you want.
These decisions should be up to me! Not some blackhole where algorithms decide if I should receive the call or not.
There are issues with mail servers being blacklisted and they can't send emails to me. But there's actual visibility to that. You can look up mail server IP's and get to the root issue of why you're blacklisted.
Honestly I'd rather the government focus on the endless junk mail I receive to my home than anything. I spend more time sorting that rather than hitting decline on my phone.
There doesn't seem to be any way to tell Gmail that this email is fine, in fact it's coming from me.
Meanwhile countless horrific obvious spam gets through to my gmail just fine, much of it straight to my Inbox.
On the other hand, I frequently get obvious spam emails in my inbox, including from one address that I weekly received a spam email. It was a very obvious email (“increase the size of your member with this one quick trick”), and each time I would mark it as spam, but Gmail never realized that that address was spam. I eventually just had to create my own filter.
I’m not sure what’s up with it, but they need to rethink their approach.
This is a very old problem. In the days of landlines, we screened our calls with the answering machine for this very reason.
This is quickly becoming not the case! I get several spam voicemails every week now. They're intentionally hitting my voicemail by placing a "dummy" call to my phone, then another call a second later (forcing it to my VM due to the first call being in the middle of setup). The first call is disconnected before I have a chance to answer it. It's only there to force the next call to voicemail.
The voicemails all follow a similar pattern. Here's one:
Hi this is Josh calling. We spoke some time ago about solar for your home but the timing was bad so I wanted to reach back out because we have a brand new program that's only for a limited time...
and it goes on from there. I've never once spoken to "Josh" about solar for my home.
These are call placement patterns that should be trivial to detect on the carrier's end.
But today I got hung up in 7 seconds. Feel bad.
Nomorobo used to be awesome, but even though they are not as effective as they used to be for the stuff they do detect I have it set to just discard the calls and that's better still. Keeps voicemail from filling up with junk. Now if I could just get Nomorobo's SMS filtering to actually work - not sure if it's them, Apple or some combination; really need to pursue that though because SMS junk is getting totally out of hand :p
There is also a deleted messages section, automatically made for some bounced callers, that needs to be cleared
Non solution offered here
In fact, I'm getting to the point I may start deprecating "Users" in my lexicon, and replacing it with "victims" upon whom technical implementations are "inflicted".
Because I can't honestly say that industry has been looking out for anyone but industry in a looooong time.
In order to stop robocalls, you just need to do three things:
* Flat out ban them and make it illegal to route them at network handover points
* Make caller ID mandatory with a reachable number to call back to
* Create an authority caring for those robocall reports
Then, put heavy fines on violations and go enforce the heck out of it. That's exactly what the EU did pretty much in the infancy of this technology.
I can't recall ever getting a robocall here in Germany.
That being said, my bet is this being a tragedy of the commons, as the only two parties in the system seem to heavily rely on the tool for fundraising — oh and they probably also make millions for some selected members of congress... ¯\_(ツ)_/¯
The simpler reason you haven't gotten a robocall on your cell phone^W^W"handy" is that the caller pays a non-negligible amount of money to call you (at some point it was around £0.25). This makes the sort of mass spam calling that's happening in the US uneconomical. In the US, the receiver pays the cost of the tower-to-mobile connection; meaning it's fractions of a cent to call anyone, even on their cell phone.
Making the US more like Europe in that regard would instantaneously get rid of a massive amount of spam calls, without the need for any more complicated regulation.
Back when cell minutes were expensive what Germany has made sense. Today nearly everyone in the US has unlimited voice minutes (in and out) and nobody worries about how long they talk to each other.
The thing is, the "flatrates" aren't flatrates under the hood. The providers still pay fees per minute to each other, they're just fractions of a cent now - but at a scale of hundreds of thousands of minutes a month, a robocall outfit can still generate five to six figures of revenue for the phone networks.
Can you explain this? My German friends have never mentioned that as a problem and based on how surprised most Europeans seem to be that Americans let spammers train the country not to answer calls it seems like the opposite is true.
Even today most people I know answer their phone when it rings. And most people call each other often (though video calls are becoming common) We complain about the spam problems, but most people still answer the phone.
Anecdotally I can say spam calls were never the majority of my calls - and I don't talk on the phone much compared to most people I know. And the amount of spam calls has been going down a lot.
Want to know the number I do not answer? My US VOIP number that I keep for business purposes. It all goes straight to voicemail and I wait for the transcription to tell me if it is another extended warrantee offer, someone wanting to tell me my computer is infected with herpes/ebola, a fake tax issue from a state I have never lived in, or if it is in the 1% of calls to that number I actually want to receive. US mobile customers have had unlimited calls for more than a decade, but I did not get a noticeable level of spam calls ten years ago.
It is not about the number of minutes available, it is simply a matter that Europeans care about the problem and prevent it from happening while US carriers do not care and their customers did not care enough to create sufficient political pressure.
[0] there actually has been a rise in one type of scam robocall over the past couple of years: the "we have been notified that you were recently in a car accident" calls are a once a month or so annoyance.
Generations of brainwashing in support of the divine right of "free enterprise" has something to do with it, I suspect.
What drives me nuts is that spammers leave a voicemail that's essentially 2-4 seconds of silence. Why can't the carrier or my phone determine that there's no message and just auto-delete the voicemail? I get five or six of these a week.
Of course not all robo-calls are by bad players. For example, if I am offered a call-back from a tech support call because of wait times, I need to remember to turn call control off until the call comes. Rob calls from political parties during election time, on the other hand, I am happy to live without.
I wish all providers were required to provide this service.
For example, what happens if the robocaller sends 0-9 digit tones in rapid succession? Does it let them through even though they got it wrong an average of five times before getting it right? They could even use voice to text to listen to the number requested.
I would love if my provider had this feature but it doesn’t. So I end up whitelisting my contacts and putting my iPhone into Focus mode. One of the ways of getting past Focus mode default settings is to call twice in fast succession. I’ve noticed some robocallers calling, hanging up immediately and calling right back which puts the call through.
I only know enough about Mandarin to distinguish it from all the other East Asian languages. Maybe I should have my coworker teach me "fuck off and stop calling me," but what I really want is a Mark as Spam button on my phone instead of just block caller.
I'm now actually more curious about the meme itself. I wonder if the actual motive is to get non-Chinese people to be more curious about the event. If so, it would actually be a meme or a mental virus. Fascinating to say the least.
Sadly with cheap VOIP numbers I rarely get more than one call from the same number - apparently it's too cheap and easy for them to buy new numbers to rotate through.
Email is more of a fair marketplace. In theory, you can even roll your own on a $5/mo VPS. Switching costs are low. You can forward messages anywhere. So email providers cannot charge exorbitant rates or require 12-month contracts, and they must provide better service to retain customers.
Yes, you can roll your own e-mail; but you're taking on the challenge of both getting spam out of your incoming mail as well as getting your outgoing mail to be deliverable to everyone else. As a homelab[0] training exercise, it's fun; but businesses that need reliable mail just outsource it all to Google or Microsoft. The end result is that e-mail users more or less reinvented the restrictive systems that phone service used to have before the FCC opened POTS up to everyone that wanted to call an entire state about the their car's extended warranty.
When you mention spectrum limitations, that's for providing mobile phone service; which is only tangentially related to the actual phone call routing these days. Just getting a dialable number or placing a call is hilariously cheap and plenty of services of varying quality will let you do this in bulk. Providing access to that number over wireless spectrum is the expensive part; but you don't need spectrum to spam people.
[0] Don't try to take the word "homelab" literally and run your mail server on your residential ISP. It won't work.
Now why are cell carriers dragging their feet even for basic problems like caller ID spoofing, which have been solved in the tech industry for decades now? 10 years ago, if I could have switched to any carrier at all that blocked spoofed calls, I definitely would have. But no company offered that service for the reasons I mentioned, and now it's too late and people have mostly given up on voice calls.
If email were a government-bolstered oligopoly and we all had to rely on Verizon's in-house engineers for spam filtering, email would be good as dead too. Email is certainly not perfect, but overall I think email's open model has aged much better.
Bit of a tangent, but I don't think people are making these spam calls because "human nature". They're making the calls because we have a society based on the accumulation of fungible wealth through profit, they can make a profit from shilling something through these calls, and the expected negative consequences of doing so aren't significant. Nobody wakes up with the natural urge to talk to hundreds of strangers about refinancing their student loans.
Unfortunately the real problem with email is liability. There's no way for me to force liability of a received email onto the sender. I can't tell Gmail to block all non-US email. I can't even tell Gmail to block all mail from specific IP blocks or domains. If malicious email originates from the US then there's some very strict laws around malicious use of computers...
A phone call though? The liability is in the caller or, at least, the service provider.
2) We actually have kinda solved the caller ID problem with email. We have SPF and message signing and the Telco industry seems to be dragging their feet to implement equivalent caller ID verification technology. Imagine if you could block a spam caller and report their endpoint on the telephone network. They'd at least have to purchase a new number each time this happens, rather than just impersonating as they do now.
E-mail is largely controlled by a small number of companies. The vast majority of people use Microsoft, Google or Yahoo Mail. The reasons it's not centralized is the same as with phone numbers - interoperability.
As you note, all the major e-mail providers already implement SPF and DKIM which is more advanced than anything the carriers are talking about implementing. Spam remains a problem. I think spammers will evolve the same techniques of attacking and taking over "valid" endpoints and routing traffic through them as they do with e-mail today. Of course, this is a good thing. It raises the expense and risks associated with spam phone calls. Still, I think the claim that any technical measures will stop these calls is unhelpful hyperbole.
Ultimately the only way to actually stop these is to starve these services for funds which will be lobbied against heavily by large players who rely on these services (knowingly or unknowingly) to drive sales.
There are ways to enter the VoIP market by purchasing trunk access but iirc that's still controlled by a few big players.
Another difference is that email in your junk folder still contains the information. Blocking a spam call means no information gets stored.
This isn't the case for phone calls. Any phone call originating from anywhere on the planet, from any network, from ... literally fucking anywhere can claim to have originated from any random phone number.
If I own the DNS name foobarr.com, and foobarr.com points to my IP address, 1.2.3.4, and my IP address 1.2.3.4 opens a connection to another SMTP server, and claims to be coming from the domain foobarr.com and the source IP address of the connection is 1.2.3.4, that still isn't fucking good enough. I need to do a cryptographic challenge (DKIM) that shows that it's the legitimate address. And SPF too, which I forgot how it works, but I need to pass SPF also.
With phone calls... the calling number just claims to be from 1-800-555-1234, and the carrier is like "ok cool, we'll send you right through" with ... no verification. At all. It just.... goes through.
The comparable situation with phones is that a home IP address with no DNS server attached to it connects to a random SMTP server and claims that its originating e-mail address is joe.biden@whitehouse.gov and the the SMTP server is simply expected to deliver the email. It is the dumbest of all possible systems.
The problem is it's a complex issue affecting millions if not billions of what is now legacy phone equipment that would have to probably be replaced. And for land lines that's a dying market - no one in their right mind would want to modernize infrastructure that's more than likely on it's way out. Might be able to get cell phone providers attention far easier.
Both groups have significant lobbying presences, I'm sure, so it will continue to be a pitched battle - but if it's ever going to be a traceable/solvable problem the fundamental protocols used between phone exchanges are going to have to be beefed up with spoofing in mind. Before VOIP and the number porting rules others have referenced in this thread it was nigh impossible to spoof numbers because each phone company owned their own block and that was that. Now any number can be held by any phone provider - the horse is out of the barn :p
If these people feared having military attack their call centers and operations they would turn on each other in a heartbeat.
Regarding the money trail, etc: I can't help but think we'll never really see the "surveillance economy" properly regulated, where our data is profited from. Because there is just too much profit.
EDIT: The context for this thread: I get SPAM calls on my mobile about extending my car's warranty. How do SPAMMERs know about my car purchase? How do they know the exact model and date of purchase? Someone sold this data.
That’s why I like what Tim Berners Lee is doing with Solid, but I think the main point is we need to build some way for personal data to be distributed and encrypted so that it’s fundamentally very difficult to steal every customers data even if the system itself is broken. I dunno if it’s possible though since most tech companies make a significant portion of their money on their customers’ data.
Scroll down to the last section "Send unknown and spam callers to voicemail". You want to activate the Silence Unknown Callers feature.
Go to Settings > Phone, then tap any of the following:
Silence Unknown Callers: You get notifications for calls from people in your contacts, recent outgoing calls, and Siri Suggestions.
Call Blocking & Identification: Turn on Silence Junk Callers (available with certain carriers) to silence calls identified by your carrier as potential spam or fraud.
There has to be stronger enforcement on this.
That's not at all what Net Neutrality is, and its removal as policy wouldn't directly enable more of these spam calls from happening
- The robocallers DGAF. Many of them are already doing something illegal to start with. The only entities who really seem to be concerned with downloading the registry and scrubbing their call lists are big legitimate corps. Rachel from Cardholder Services just wants to dial as many numbers as possible and isn't going to comply with the law.
- Reporting violations is an effort in futility! A couple years ago I decided to report an idiot who was calling multiple times a day. The form asked for a bunch of information about the call, I filled all of it out, and several weeks later I got a reply from the FTC through postal mail with a dozen printed pages (including my complaint rendered onto their internal paperwork) saying sorry, they didn't have enough information to act.
I get 10+ robocalls a day, I'm not spending my time filling out a form that goes nowhere. It's unfortunate, but the registry has no teeth.