My own phone number is now spam texting me
theverge.com
theverge.com
You should file a complaint with the FCC that your carrier has not clearly not properly implemented STIR/SHAKEN, since they badly mis-identified the source of a call. While calls from outside the US can be unsigned, the carrier should detect that the number is inconsistent with the source.
There are "A", "B", and "C" level of verification. "A" calls are probably legit. The others, maybe not.
If you're in California, try making a personal data request to your carrier for the detailed STIR/SHAKEN data for that call.
[1] https://commlawgroup.com/2021/stir-shaken-robocall-mitigatio...
So stoked that there’s finally a way to fight back against robocalls, and that carriers are being forced into compliance. Thanks for pointing this out.
The carriers aren't being forced at all (yet).
I'm no longer getting almost any robocalls on Verizon as of a couple of months ago when they "turned on" STIR/SHAKEN. What I am getting instead is the same volume of spam text messages.
Not sure which is worse, someone trying to sell me stuff or that.
How much volume? Is it a daily annoyance? My wife seems to get hit harder than me, but as far as I can tell we’ve both been equally careless about sharing our number online. So I’m dreading the day that these people figure out how to turn text messages into a gmail spam inbox.
It feels like it’s time to just write a Bayesian filter and proxy all text messages through it. It was theoretically easy to do that back when you could send texts just by emailing a special address, but sadly I think carriers ditched that feature. Nowadays I’m not sure where to start if the goal is to proxy our texts like that, but I’d like to.
Not that the country's been able to do anything about the sheer volume of scam texts pretending to be the Post Office with a parcel for you or Microsoft telling people their Windows boxes are full of viruses.
Plus, political speech is the "most protected" type of speech in the US. Pretty much anything campaign-related falls under that umbrella. Couple that with the explicit exemptions ldoughty mentions and we tend to get a constant stream of political spam in the lead up to election day (where "lead up" for a presidential election starts about 2 years out - le sigh).
Even worse, SCOTUS ruling over the last decade or so have reaffirmed that donations to political causes are speech, dark-money PACs are legal (donor disclosure not required), and all sorts of other things that many of us view as problematic.
My guess is that they’re sending this to all numbers in a certain area code. I’m in Missouri, which was mostly red. So they kindly delivered a MAGA to my phone and I’m like “thanks! … tell me who gave you my number so I can hire a hitman on them please”
The political tactics at play are actually quite fascinating to me, because they seem so dumb. But it’s the opposite. In reality it’s effective, and I’ve always wondered why. So it’s interesting to hear that politicians are prohibited from doing this in other countries, and makes me wonder if it’s an effective policy. It seems like it might be.
Of course, that doesn’t help rid us of the silagra spammers, but maybe the FCC can come up with a solution that can prohibit both. It feels sort of hopeless, but then I remember that we could literally proxy every text message through our laptops, run them through a 1997 naive Bayesian filter, and eliminate 97% of the problem with 0.03% false positives. It seems like a matter of time till some service comes along and makes that schlep effortless, and I can just pay $5/mo for the privilege of dodging spammers.
"National Security" means the Security Services, Special Branch (the dept between the SS and Police), Police, NHS, Companies House and other Govt depts you've not heard of, can do what they like if you read UK legislation. Just look at the GDPR legislation. https://www.legislation.gov.uk/ukpga/2018/12/part/3/chapter/... Section 44 Subsection 4d Section 45 Subsection 4d Section 48 Subsection 3d
And on the point of secure private communication, you may be old enough to remember the London Riots where Mark Duggan was shot dead which triggered rioting in London that spread? https://en.wikipedia.org/wiki/2011_England_riots#Police_shoo...
Well back then Rim Blackberry's and BBM were the popular mobile phone communication method, but what alot of people dont know is that RIM Root certs for BBM where in the possession of The Royal Canadian Police, who gave a copy to the UK authorities (5eyes data sharing), so every BBM message sent during the London riots organising disruption, were decrypted and read.
There is no secure telecoms systems, there is "no law" when it comes to National Security in the UK and alot more conspiracy's are closer to the truth than people realise!
After all, the whole POINT of these spam messages is that the systems are (and this simply reeks of incompetence) incapable of determining the true source of the messages.
My personal phone number is at twilio so I can set the messaging action to be a function.
My original intent was a proof of concept that I could flatten incoming sms to be something very tight like ascii 128 (or even smaller) and truncate extra characters and white space, etc.
Successful zero click sms would be very difficult if your message was rewritten and flattened in this way …
But I have no idea what our coherent interests are as the Czech-American voter block. The only things I can think that would cover, are like, unfair taxation of kolaches, or required subtitles on Czech porn.
Fortunately, there were only two of them, around the 2020 general election. If I got a lot more spam texts, I'd be pretty pissed. The voice calls alone have made my phone useless for receiving calls from randos, and much less useful for day-to-day operations.
There are three items here, party affiliation, name of recipient, and target phone number. Only one of those apply to me, and one was wrong but related. This was data driven not from a signup of any sort.
And they’re always so insidious. Want to try out some new app that’s going viral? “Phone number verification please.” Oh good, now I have the choice of not joining my friends, or risking some spammer from India three years from now will be texting me at 3am to sell me silagra, because Hip New App had a data sharing agreement with Company X, who passed around my phone number like a pipe at a frat party.
The worst part is that it’s somehow possible to detect whether you’re giving them a “real phone number” and not a twilio number. And it turns out that all those services that offer burner lines are all built on twilio. Which means (to my dismay) I couldn’t just set up a damn burner number unless I literally bought a second phone.
At this point the situation is so comical that carrying around a burner phone next to my laptop is suddenly seeming like a rational totally-normal thing to do.
Heh…as soon as I read this I glanced down at the little Nokia dumb phone I have next to my keyboard. $15/mo AT&T 4G prepaid plan exclusively for “when I’m suspicious of whoever I’m about to give a phone number to”.
Only ever gets “topped up” when I need to use it, and when it’s not in use it just sits in a drawer.
Parties maintain these datasets and then selectively share with candidates. There's always misuse and abuse.
My local (legislative district) party requires candidates sign a contract. We're one of the few (because we have geeks on the executive board). And even then, there's always some yahoo abusing the data.
I'm not aware of the relationship(s) state & national parties have with their large fund raisers. I assume the abuse is rampant. Just like with every other outsourced fund raising operation.
--
I've long been totally against voter profiling and ballot chasing. Harassing voters is another form of disenfranchisement (thru alienation). I've door belled, worked the phones, and done fund raising; voters HATE us.
But every else is utterly opposed to the alternative system. Universal voter registration, compulsory voting, and massively curtail campaigning.
In other words, be like every other mature democracy. But we couldn't possibly have that. Because Murica! or something.
TLDR: Burn it all down. Upgrade to genuine democracy.
I'm back to getting 4-10 robocalls every day. One text. Some are detected as spam by Verizon, but my phone still rings.
Spam SMS ought to be even easier for carriers to filter than voice. They need to do it and soon.
Someone can compromise your phone by simply sending an iMessage without the receiver interacting with the message (even to immediately block the sender)?
https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
I've got a private phone and a work phone on T-Mobile. My private number gets maybe 1 spam text per month, but 2-3 robocalls per week, while my work phone gets 3~ spam text messages per week and about the same number of robocalls.
Overall, the number of robocalls I've been getting has gone down somewhat, but not noticeably. It's probably decreased by something like less than 10%.
I had no idea anything had been done to robocalls, I really hadn't noticed any sort of decline.
One of the most annoying incidents was when I get new work cell from AT&T. It must have been a recycled number from someone who signed up for a lot of.... crap, because that phone got 10+ spam texts and 5+ spam calls every day I had it, from the moment I put the SIM card in a phone. Eventually had to get a different number from AT&T.
I guess I should drop my old skool Bell Canada landline in favour of a VOIP line...
[1] https://www.canada.ca/en/radio-television-telecommunications...
When WiFi and 3G signals are thrown into the mix, real-time communications go south fast...
To STIR/SHAKEN's credit, however, the only spam calls I've received go to the cellular number assigned to the SIM card I have that is purely for data (so I can make those VoIP calls outside of home wifi range)
I guess you could keep your phone number by porting it and get the call spoof protection?
This was only for voice calls not SMS. From a FAQ On Neustar's(SS7 provider) site:
>"5. Does STIR/SHAKEN apply to SMS/text messaging? Currently STIR/ SHAKEN applies to phone calls only. However, work is on-going in the communications industry to evaluate the best authentication method for SMS / text messaging."[1]
It's unclear as to my why it does not currently cover SMS. Perhaps someone else could shed some light on why this is. SMS certainly uses the same SS7 infrastructure as voice calls.
[1] https://www.home.neustar/resources/faqs/stir-shaken-for-busi...
TIL.
I know that makers of phone/texting apps are primarily targeting users who don't know or care about this kind of stuff, but man it would be awesome if that kind of info were available whenever an inbound call or text arrived on my phone. Just like email headers, I'd love to be able to see the raw authentication grade and other metadata.
Blame your phone company and the FCC for not solving this (and for not providing you with the data to solve it yourself).
In the mean time anyone who can’t just whitelist phone numbers loses. Being a business must suck.
I usually ignore calls from abroad at least, but even those I can't block; I'm constantly spam called by different anonymous numbers from the UK, but I also have colleagues in the UK whom I want to be able to accept calls from. I once got an unsolicited call from a French number which I ignored, only to find out that it was the phone number of a food delivery person who was there with my food. Just last week I got a call from an unknown German number; in that case, it was a call from a colleague in Germany.
I don't think a whitelist of phone numbers is a workable solution for most people.
Which is frustrating! Because it might seem like that's a low enough frequency to make whitelisting a viable solution. But it's not—for the reasons you outlined.
2 calls a month are important enough to me that I must receive every spam call that comes in. I'm still pretty good at sniffing out most of them. A lot are still matching my area-code and exchange numbers on the spoofed ID—a huge red flag. Many others show rural cities that I'm certain no legit caller would call me from. But then there are the in-betweens: calls I can't make heads or tails of unless I answer.
Whenever I do get one of these legit-but-unrecognized calls, I immediately add them to my contacts in some vain attempt to reach whitelist nirvana. But I don't think I'll ever get there.
I'm having trouble understanding how 2 phonecalls, poses such a big problem. Please help me understand.
My voicemail box is about 2/3 spam voicemails.
It doesn't really fix anything, just shifts it to another place that I then have to check to weed out spam calls and find the legitimate ones.
> I'm having trouble understanding how 2 phonecalls, poses such a big problem. Please help me understand.
Okay, so it's not a "big problem". I'm being a little hyperbolic in my previous comment. It's an annoyance, and a galling one. Like email spam was back in the day. I could still find the legitimate emails among that crap, but it sucked and I would've rather not.
The 2 phone calls themselves aren't the problem. The spam is. But the 2 phone calls each month are enough that I don't want to just ignore all non-whitelisted calls. Doing that will cause its own annoyance, as I miss calls that I didn't want to, and have to check voicemail each time a spammer calls me.
All of my incoming calls go to my VOIP provider, which in turn routes to my cellphone if someone has my 'extension'. Anyone who doesn't, has their message go to voicemail, which is transcribed to email (and the audio file attached). Prior to transcription audio plays telling the caller to enter a specific code, to leave a voicemail. Turns out this eliminates 100% of fake foreigners, and locals. They can't be arsed.
I ignore SMS. I receive nothing of value other than registered numbers (as in, a registration with the state) so I actively block them and add on an as needed basis.
My spam has reduced to zero.
Watch their terror as you open their text or email app and get snippets of their private communications.
I'm not sure about your plan, tbh.
Probably 90% of people under 40 years old. I've blocked unknown callers for over a decade, with no issues. Honestly, I'd be fine to lose the voice call and texting features entirely and just go entirely to email. Seems to be heading in that direction anyway.
I assume most "whitelist" approaches don't actually send the messages nowhere, they just remove notifications so they don't interrupt you. For colleagues / etc, you can just use Signal (or whatever company-imposed collaboration tool exists) to hold the conversation completely, or barring that you can at least schedule a phone conversation in advance (so you can whitelist the requisite number).
I'm sure if you're client-facing / in sales you don't have this luxury, and you'd rather be interrupted at any time even if it's spam, but I doubt that describes most people.
Same is true for food delivery etc... if you're expecting something that might require your attention, you can disable the whitelist and let any call through during that window.
My local hospital telephones with private numbers, which is the only reason I cannot completely block them and thus cannot use a whitelist. Outside of working hours I do not answer them. I told them it is a problem and they placed a note in my record to call me from a public phone which is nice of them (not their own desk but from a service desk which has a number displayed) but I imagine they sadly sometimes forget.
The UK number is a hassle too, all kinds of +44 numbers spoofing or reusing existing non-fixed location numbers to seem legitimate since some phones provide direct listing of the name of the company. They are actually foreign redirects which cost insane amounts of money if you call them back.
I would also like a native way of blacklisting number blocks (like +44), my phone currently can't unfortunately.
Can anyone with more context explain to me why a rational person decided on this? It's Biblically frustrating for me because 9/10 withheld numbers are spammers or scammers and I don't want to pick up the phone to them but 1/10 it's my local doctor's surgery who I can't ignore. It's such an antisocial thing for doctors of all people to do, but it seems to be common enough people across the world have to deal with it.
The other problem is privacy... imagine a woman consulting her ob/gyn about an abortion. The ob/gyn calls the woman back, and suddenly the abusive husband sees the phone number of the ob/gyn practice on the incoming call log.
Domestic violence is far from hypothetical [1], it is the sad reality we live in. Medicine in particular has a responsibility by the Hippocratic Oath to avoid causing harm, and the laws (e.g. HIPAA) reflect that responsibility.
[1] https://www.socialsolutions.com/blog/domestic-violence-stati...
No, precisely because random calls from suppressed numbers are so common for spam.
Then they should understand why people ignore calls coming from unverified numbers.
In my country, you only incur normal minutes when you call an ordinary non-overseas number. By ordinary, these numbers have a normal number of digits, and a known prefix. Paid call always have shorter or longer phone number.
It's regulated by the UK regulator OFCOM. They publish a list of number prefixes and the maximum costs that can be incurred:
https://www.ofcom.org.uk/phones-telecoms-and-internet/advice...
Some of those costs are high, but they are published, and capped. There are no surprises here.
There are a couple of myths that circulate endlessly in this country that:
i) You can receive a call from a scammer who prompts you to 'press 1' to be connected to an agent, and if you press 1 you're dialing a premium number and can incur large costs. This is impossible, inbound calls in the UK are not billable, nor can inbound calls count against any inclusive minutes on a contract.
ii) You can dial a cheap-looking number but the call is forwarded to an international or premium-rate destination and you can incur large costs. This is impossible, you can only be billed for the number you dialed, any onward forwarding costs would be incurred by the owner of the number you initally dialed.
I'd be interested to see if an entirely new business model rises up out of this. Some kind of verified business network of phone numbers people pay a small fee per month (per call?) to get assurance that it's a legit business call. A sort of for-pay group whitelisting.
At the very least, when it comes to my private number, I decline any call I do not recognize and I figure that if they are legit, they will either:
1) Call back immediately
2) Leave a voice mail and I can call them back in a minute.
It's tedious, but a sort of call/re-call seems to be like a kind of workaround to this. It's just a very tedious thing when it comes to stuff like doctors offices calling form a new number, 2FA from some website, or anyone I might not have saved in my contacts list.
It still doesn’t solve the problem of someone unexpected calling you though, or someone for whom you don’t know the number..
Carriers are milking it as much as they can now, as they don't have leverage to otherwise stop any progress that would make phone numbers finally irrelevant.
However, I have been getting 20+ spam calls a day for the last week and I am ready to get rid of the landline forever.
The generational decay would be much much slower if telecoms did their job.
Our elderly parents stopped calling us and moved to Line the moment they had an iPhone (then an iPad), and even with their friends they seem to just hit the call button from the messaging threads. They still say they had someone on the phone, though they’re on third party services, so it seems it kinda just switched in their mind.
Perhaps the same way we were switching between local calls, long distance calls, special operator calls in the offline days, but we’d still just think of it as phoning people whatever the actual service we were using behind.
I mean, who wants to run a phone company anymore? Selling data is where it's at, and old-school phone calls are for grandpas.
You want to reach females aged 30-35 in a city? Simply call or send an SMS from the API and you will be connected to a random one who matches your criteria.
At least, that's what my spammer told me when I insisted on telling me who gave them my phone number. Apparently, I gave the consent to be included in the pool at the time of purchasing some data package or something like that.
TBH, this a system that if it's opt-in only, I don't have much of a problem with. If it's opt-out, I'm annoyed. If it's required, we should change policy.
To know about it, you need to be annoying like me and investigate. Once I learned about it through questioning the spammer, I called the carrier and requested opt out. First the call center people didn’t know what I’m talking about then at some point they used some innocent sounding name for it and promised that I’m out. I still receive spam everyday.
I do. They don't care. AT&T doesn't even care that their cell network barely gets above 1 or 2 bars in a major metropolitan area. They mislead consumers by displaying 5Ge as the network (it just means you're on 4G but in an area that might have 5G service). My phone is really not a phone anymore, at least 95% of the time. I do make outgoing calls myself and only answer when I have a definite expected call from a known number. I use video chat apps for both audio/video calls for family.
But they could just prevent it entirely by giving us the originator info. The process is basically like this:
Alice calls Bob.
Phone system says "Alice, who do you want to tell Bob you are?"
Alice says "Bob!"
Phone system says "OK!" and bills Alice because they know who Alice is.
Bob gets a call from Alice but displays as Bob because Alice requested to display as Bob.
Bob goes "Wtf?"
Bob reports it to the FCC but he can only report getting a call/text from his own number.
FCC goes "Ooh those naughty caller ID spoofers we'll get them good next time! Too bad there's no way to prevent this..."
Part of the conservative push to deregulate is to argue that government agencies are incompetent but the reality is that they've constructed a system where these agencies literally lack the agency to do anything more than write a nasty letter.
So the phone company can pay the subscriber the $10,000, and collect it from whoever they got the text from.
I guarantee you spoofing would be solved immediately if this change to the law was scheduled for 12 months from now.
One could argue that since the more messages you receive, they more you pay, they have no incentive to reduce spam; whereas with ad tracking, as long as they find some advertiser willing to pay 100 million dollars for a 1% increase on click throughs on their overpriced toothpaste, they'll have a financial incentive to do a good job. So maybe we're actually really screwed.
Sad that a cell phone company can't be just a cell phone company. They were pretty good at that.
Laughs in €uropean. Btw €5.99 unlimited calls, unlimited texts (that the receiver doesnt pay for [maybe my US friends do....must check] 100Gb a month. Had the same tel.no for nearly 20 years, several different operators. My US friends are very jealous (though at least one has unlimited EU calls and texts).
We get North American roaming but T-mo is the only one that does seamless international besides Google Fi.
The link [1] links to Telecom Regulatory Authority of India (TRAI) website.
You sign up to DND by dialling a number that is dependent on your carrier (therefore you need to do this separately for all your phone numbers [3]), and go through the "Press 1 for English [2]... Press 2 for so and so... " etc. Takes a couple of minutes.
Once I signed up, the number of marketing and similar silly calls/messages have been nearly eliminated.
Maybe something similar — something that allows people to opt out of such calls/messages — can be implemented in USA.
[1] https://trai.gov.in/faqcategory/unsolicited-commercial-commu...
[2] The language question because there are plenty of languages in India.
[3] Tangent: do people not use multiple phone numbers in USA? Like, I wanted to buy an iphone but it does not support multiple SIM cards (unless you convert one of the SIM to an e-sim [4] which I'm hesitant to do because if I later switch back to an Android phone that does not support e-sim, I'll have to go to my phone company to get a physical sim. Too many hassles. ). Also I'm told iphones sold in China has dual sim capability [5], but I can't go to China just to buy an iphone.
With CallID spoofing its so hard to track down that violators never get enforced.
In India you have the advantage that the caller pays, which means you have a phone system that somewhat securely verifies who the caller is so they can be billed. In the US the receiver pays so there is no system in place to verify who the caller is.
Why is that information public? Shouldn't only the "middleware" equivalent be aware of who has signed up?
> In the US the receiver pays so there is no system in place to verify who the caller is.
What?! Why?!
What? That's bonkers. Why on earth should the receiver pay?
I can't say definitively but the vast majority of my spam calls are from South Asia or South East Asia (I'd guess Philistines based on accent). They typically don't respect the Australian Do Not Call register so much.
> do people not use multiple phone numbers in USA?
The e-SIM is the easiest way to get two numbers on the same iPhone. Having multi-SIM phones isn’t popular for a number of reasons, including the fact that Americans and Europeans can get a 2nd number via services like Skype and Vonage anytime they want — something India still prohibits.
Incidentally I wrote about having multiple SIMs in India a week ago[1]… they’re an interesting historical accident, and the well-to-do in India will continue to use them, but they’ll become increasingly less common as telcos raise prices.
I have had perhaps two unsolicited calls in the last five years and one of those was from a number apparently in London, UK.
We hate it as much as you do.
Why not opt in instead?
Not really, no. Dual SIMs are kind of a niche feature here, and most users I've heard of do it with a US SIM plus one for some other country they travel to frequently.
Curiosity: what are the use cases for two SIMs from the same country?
> Curiosity: what are the use cases for two SIMs from the same country?
I have one line on Verizon and one on T-Mobile for better coverage, robustness to congestion.
iOS 13 has a "cellular data switching" feature for dual SIM that automatically chooses networks based on availability.
Data from one network even provides "WiFi calling" capability for the other line.
For cost & complexity reasons, this is a very niche need.
I don't know the exact reason, but here are some thoughts on that:
Hypothesis 1:
In India, only the caller pays for the call. The callee pays nothing. I say this because I was surprised to learn that in USA, the callee pays.
Long long ago — before calling via the internet through WhatsApp, Signal etc became a thing — in India if you (or rather, your SIM card) travel to another state within India (say from Kerala to Karnataka), your phone goes into a "roaming" mode.
When you're in roaming (when your SIM is in a different state from where it was originally registered), both the caller AND the callee would have to pay.
So, if you're from one state and you intend to live in another for a condsiderable amount of time (perhaps because you got a job in another state), then it makes sense to sign up for a new phone number in that new state so that you wouldn't be charged when you get calls from family and friends from your home state.
However, this reason is no longer valid because in order to stay competitive phone companies stopped charging you for incoming calls if you go to another state within India.
Hypothesis 2:
Business people tend to have multiple phone numbers to handle the high volume of calls they receive, or to separate work and personal calls.
Hypothesis 3 (my reason):
I initially had a number that I used for personal calls.
Later, a new provider came on the scene with better rates, faster internet, better clarity etc, and I signed up for that as well because why not. This was before phone number portability was introduced.
My mobile data and work calls is through one provider, my WhatsApp is signed up via the other number, and most friends also call me via this other one.
And in some places only one of the provider has a proper strong cell coverage.
It's technically possible to merge that all into one number, but I haven't bothered.
Also, calling directly via phone (as opposed to via the internet) is still very common here because it's super cheap. For example, calls from Jio to another Jio number is free I think.
This was killing telcos like Airtel and Vi until they too adopted Jio’s model: every SIM has a nontrivial monthly charge whether you make calls with it or not. And that price has risen substantially in the last few years and will continue to rise.
It won’t stop affluent Indians but people on more near-median incomes will find keeping extra SIMs unaffordable.
Except in certain circumstances, I don't think this is true.
First, most calls are free now. You might have a number of minutes, but both the caller and callee have to pay for minutes at the same time. But most plans are unlimited calling within the USA now, I believe.
When calling other countries, the caller pays. Receiving a call from another country doesn't cost anything.
"Collect calls" are calls where the callee pays the long-distance charges. This is unrelated to the "minutes" above. There are no long-distance charges within the USA that I know of, but international charges will apply to the caller unless they "call collect" and then it would be the callee. The callee has to approve it, though.
Most 1-800 (and 1-888 IIRC) numbers automatically charge the callee instead of the caller. This is an agreement that the callee has with the phone provider.
1-900 numbers (and certain 1-800 numbers, for some reason) charge the caller. These are another agreement with the phone provider by the callee, and they're supposed to get consent from the caller before charging, but there are many scams here.
Because of the lack of long distance charges inside the USA, 1-800 numbers aren't as common as they used to be. For a while, almost any business that had wide-ranging customers had one. Now, it seems like only mega-corps still have them.
All that said, I vaguely remember someone saying that they had 2 sim cards because they had 2 plans. IIRC, they got better long distance rates on one or the other, and used them appropriately. That was a while back, though, and I could be remembering it completely wrong.
> >in USA, the callee pays.
> Except in certain circumstances, I don't think this is true.
Oh okay, so the caller pays and the callee does not pay under normal circumstances? Now I'm confused. When I said the callee pays in USA, I was working off of information from another comment[1] by jedberg in another branch on this thread. I'm pasting that comment below for convenience:
> In India you have the advantage that the caller pays, which means you have a phone system that somewhat securely verifies who the caller is so they can be billed. In the US the receiver pays so there is no system in place to verify who the caller is.
If I want to call any other country, I have to pay a certain amount per minute. If someone from another country calls me, they pay.
I outlined the exceptions to that above, but I haven't actually experienced those exceptions for quite a few years now.
The other crucial reason is that it was near-free to have as many prepaid SIMs as you wanted, you paid only if you used it to make calls (receive was, and remains, free, like in Europe). And VoIP numbers aren’t allowed in India.
These days, all the carriers have national licenses, there’s no long-distance charges, and you have to pay a nontrivial sum (nontrivial unless you’re a relatively rich Indian) every month to keep your SIM active. Whether you make calls with it or not.
This has been a slow, “boil the frog” change, and the relatively extremely well-off Indians on HN will probably be the last to notice, but the need to have multiple SIMs in India isn’t as strong as it was in the 2000s.
Having SIMs from different carriers to take advantage of different rates. This is mostly in countries where call prices are unregulated and calling someone using a competitor carrier can be a surprise that costs sometimes 10x more.
This is more common in poorer countries.
One phone number, registered to your business, that you never give to anyone other than 2FA, contact number for bank accounts, credit card confirmation etc. And one phone number that you use for business and personal calls.
I still get spam calls on phone #1, of course, but it protects me against SIM swap attacks from people who get access to the second phone number
They speculated that it is because in India the person making the call or sending the text is the one who pays for it. So spamming is expensive.
Also, apparently spoofing numbers is unheard of in many countries, the US seems to have it particularly bad.
If anyone here is familiar with the technicalities of how this stuff works, what are your thoughts on the hypothesis?
Wait, what, do people in US pay for receiving texts or calls?
Most cell plans now include unlimited incoming calls and texts, so it's not really a problem, but the sender does not pay anything either, which is a problem.
If the robocaller/spammer doesn't pay for it, I think that explains why these things are so rampant in the US. In Netherland, it's only the caller who pays, and robocalls and sms spam are extremely rare here (at least in my experience).
Although these days, many phone subscriptions come with unlimited calls and texts, so the caller/texter doesn't pay either. Somehow this doesn't seem to have lead to an increase in spam and robocalls.
While in Japan, I remember calling a mobile from payphone I could see the balance of the call card going down every few seconds...
Though, these days, I think most of them seem to have shifted to texting and VoIP calling on apps, which are free.
Even with "caller-pay" model, they still have experience good share of annoyances, that many of those caller opted for "one-ring" spam where they would call, but hang up before receiver picks it up.
The only thing is when the mobile phone is abroad and there are roaming charges; in that case, the callee still pays, because the caller has no way of knowing. But these days, roaming charges have been banned within the EU, so that problem has also disappeared.
The telecom authority here has been fighting against misuse of calls and SMS for years now. It all started when the Finance minister received such a call while he was speaking in the parliament :D https://economictimes.indiatimes.com/industry/telecom/raja-o...
Even with all this action the number of calls are quite a lot and this is the reason most folks have Truecaller installed to weed out unwanted calls.
What changes with region is the type of spam you get. I have never received a call for tech support, not to mention you need to provide two-factor authentication for each transaction and the fact that credit card is used by only a few.
I remember making sending emails cost a tiny fraction of a dollar was proposed some time back in the nineties to stop email spam. That was superseded by effective bayesian spam filters. The cost of that is that it's near impossible to self host email servers these days, as all those filters will label you as a spammer. Otoh requiring some payment solution would also be a strong barrier...
That is what made me interested in ML (it was an article by Paul Graham - "A plan for spam"), years later I am an ML engineer.
I put mom and dad on the do not call registry here in Canada but it doesn't help. Constant calls from Amazon, Visa, Revenue Canada etc. It's either the robo voice or someone with an Indian accent.
I worry about my Dad with this. I tell him constantly to hang up no matter who they say they are as a matter of habit. If he really wants he can initiate a call with that organization to ensure it's actually them.
Despite me saying this repeatedly, I've heard him give personal info over the phone to cold callers offering discount electricity rates.
Settings > Phone > Silence Unknown Callers
It's a nuclear option but it works
I managed to lock them down, except they still get spam texts. There's no way to disable incoming texts, even though they're supposedly data only devices.
I still get SMS spam on it.
I rec folks do the same.
I undo this anytime I get a good delivery tho
"Free Msg: Your bill is paid for March. Thanks, here's a little gift for you: ${short link redacted}"
The short link is hosted on Cloudflare which eventually redirect to a Russia TV website 1tv.com or 1tv.ru
< HTTP/1.1 302 Found
< Date: Tue, 29 Mar 2022 17:37:58 GMT
< Transfer-Encoding: chunked
< Connection: keep-alive
< Location: http://1tv.ru
< CF-Cache-Status: DYNAMIC
< Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=yEU2D%2FlNvx216BeQ8TK2oONisk12pAzUW7FlYuTb2Uth9LIT8pcSQyKok1FASqproAoWqBc%2FHaje8lf8pihU2kTSzuoslYERPQvnvRSv%2FyHKIDQ3%2F8e1hSaYMKEn"}],"group":"cf-nel","max_age":604800}
< NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
< Server: cloudflare
< CF-RAY: 6f3a605d595039ad-SEA
< alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
EDIT : thank you all for your answers !
I suppose it’s the same thing that allows you to receive messages from "SOME BRAND" and … why not. But this could be easily regulated. I don’t understand why anyone can spoof anything they want. Also, I don’t understand why my iPhone don’t allow me to block messages from "SOME BRAND" as if it was from any other sender.
its not exactly ELI5.
The CLI (Caller Line ID) field of a "incoming call" message isn't adequately policed. This is sort-of baked into how telephony works. It's stupid, and it should have been thought about more. The CLI field isn't how the call routes, its just how the caller announces who you are. Telephone call routing uses other data fields, its part of SS7 and the other signalling systems the phone network uses. The field which comes up a mobile call, inside "payload" isn't how it routed.
Imagine some company has the indial range 667 2200 to 667 2299.
If you dialled from your assigned handset 667 2241 the CLI can say 667 2200 so it looks like you come from the switch (in this example we assume the company's PBX operator is on 2200, and you publish 2200 as the incoming call number) so people don't learn your office handset: thats why they permitted it.
I have no idea why they allow to to "lie" above your indial group range. But they do.
STIR is how in a VOIP world people are approaching the fix. But really? the FCC and other national regulators have to tell the telco to stomp on the fakeout, when people inject calls into their system.
This has parallels with "envelope sender vs RFC822 header" in email. Or spoofed source if your ISP doesn't do BCP38. Guess what: SPAM is a problem in email (duh) and spoofed source is how DDoS can happen. "telling lies" in end-to-end communications is not helpful.
(genuinely curious why this happens in the USA but not here)
Are you getting that many spam texts?
I'm on ALDI which is an MVNO overlay on Telstra wholesale. Maybe ALDI do worse for source detect?
(there is no difference between SMS and calls in regard to CLI faking. I don't know about RCS, its possible RCS gets rid of this problem. ALDI doesn't have RCS, its not ubiquitous, has to be enabled in the phone profile by the provider)
Anyway, a company could have what was called a PBX — a bunch of lines would come in and the operator would connect them (by plugging cables — I still remember this system). When they replaced that with electronic “exchange” — Private Business eXchange you could dial straight out from your desk. However there were fewer lines coming in than extensions. For direct dial the PBX could either set all outgoing calls to be the main number or could send the direct dial number for the desk phone that made the call.
We had a system like that into the late 80s though by that time we weren’t getting a bundle of incoming lines.
This system does have an advantage: it lets staff make calls using phone number controlled by the company. So when someone leaves they can be forwarded to the appropriate person, like email addresses.
For the last 15-20 years I’ve just used my mobile number which means when I leave a company I continue to get phone calls. I’ve always left on good terms so this isn’t terrible, but what if I had not?
Since nobody calls on the phone any more this may be less of a problem, but phone numbers are still used as authentications for services like WhatsApp. These numbers need to go away.
The opposition was fascinating. Nobody predicted spoofing, of course, but I saw teary-eyed people crying on publicly televised hearings in NYC arguing both sides of Caller ID!
- One women's group was against it. "We don't want women who are in safe homes or moved in with relatives to have to reveal their location when having to call their abusive partners"
- One women's group was for it: "We want to know who calls us and says obscene things."
Total craziness!
See: https://www.google.com/books/edition/Caller_ID_Technology/84... for some of the hearing minutes
No, unfortunately it's not easy to regulate. It would involve not just all domestic operators, but also all telecom service aggregators (e.g. Twilio, Infobip, Sinch, and a thousand more), to find common ground and coordination of a working register of what company has the rights to what SMS sender name within one nation's network, whether it's numeric or alphanumeric.
STIR/SHAKEN (which regulates usage of numeric caller IDs for phone calls) has taken ages to come to fruition, and that's despite the huge technical benefit of phone numbers being inherently anonymous and already belonging to a specific network operator. With the sender of an SMS the logistics are very different, and that's before even touching on the enormous business of legitimate SMS services and how these should be able to compete on the open market.
Support dispatch may be subcontracted out to an entirely different company (that may change over the months/years), so you'd still need to ability to spoof numbers you technically don't own.
I agree there needs to be more controls and regulations in place though. The status quo is unsustainable.
For example, over here in Austria you can tell exactly what type of "line" a callee uses and so you know in advance how much you have to pay (even though in practice most people have unlimited calls/texts).
This means that when running a spam bot you will soon run into big issues because it simply doesn't pay off financially to send that many texts and calls.
In Netherland, it used to be that the caller pays. Technically they still do, but many subscriptions come with unlimited calls and texts these days.
Phone numbers that cost extra money tell you that before they connect you.
This was supposedly used to forge harassing emails from work accounts, which provided proof of false accusations.
Send a text (iMessage) to myself on the phone. Then look at it, and block my own number. The phone then reported it would block calls, FaceTime, messages from my own number.
Since I don't expect to ever need to call/message/FaceTime myself, that seems like a zero cost solution.
I got one of the Android stock text messages last week for when you auto-respond to a missed call. 'sorry can't speak right now' from a phone number I never called.
So a spam caller used my phone # to call, the person auto hung up with a response, and the real text message went back to my phone... It's absurd.
I get called at least once per month from (a different each time) someone in the same exchange as me saying they had a missed call from me. Presumably they got a spam call from my number, as I get about 5 spam calls per day with caller-id spoofed to a random number in my exchange.
They were apparently calling from a land line in area code XXX, and didn't know how to dial long distance on a touch tone phone.
I tried to explain that they needed to dial "1", then their number to reach their lost phone.
They kept calling, then screaming about how I stole their phone and to stop screwing with their head; they knew how to use a phone.
After about 5 minutes, I gave up and blocked the number.
It's really easy to spoof a phone number for SMS if you know which network the person's phone is on. Trivial if you know how. There's no black magic to this. At least, it was so a couple years ago. The last time I fooled with that for fun, I spoofed one of my friends admitting to another that he'd slept with the other guy's wife and decided afterwards he was gay. I managed to insert it from his phone number into our group chat as it appeared on android. (I think it might've ended up in a separate chat sequence on iphone). That was funny.
There's no dark arts here.
Additionally hours later I received a text about smoking weed.
Both links in these text messages, after further investigation, brought me to Russian owned sites as the article described.
A few months ago I started getting huge group text spam to hundreds of emails that were almost identical to my own
(changed obviously) if my number was : 123-454-9938 then i would get in a group chat with numbers from 123-454-9900 all the way to 9999. They were using email -> sms specifically which is a relatively new feature that allows you to text mobile devices on carriers that support email to SMS. [1]
Super annoying - but AT&T at a minimum allows you to call and request that they disable this feature for your account. If anyone else is getting constant sms spam from email addresses this is the way.
Disclaimer: I don't know and have not run into any issues where legitimate companies are using this feature yet. If so, then obviously you won't be able to receive those texts. At the moment there is no capability with carriers (that I've seen) that would allow you to create an "allowlist" of domains to accept texts from, but until that exists I won't be dealing with email to sms as it's just a huge cesspit of spam.
I don't think this is true? In ye olden days of text messages, SMS and MMS were relayed via email, IIRC. I remember emailing pics to a friends phone using the MMS email address. The format was unique to each carrier but included the phone number, obviously.
So with phone we shouldn't protect people identity, address and/or company name but protect people from disruption with calls they don't want to answer and give them ability to verify who was calling, by even seeing their photo cause yes if I'm your neighbour I can see you and if I move next to you next year I can see you too. Wow.
There should be 2 call indexes one for contacts that should behave same as it's behaving now and second index for anything else that you shouldn't receive notifications but you can check this spam missed calls index and verify anyone that called you and add them to contacts - just how the old good paper phone book worked.
This empowers people to be able to make decision if I want those people to call me or not, cause you can always call back and it should be widespread when you call someone first time expect they might won't answer your call same as if you email someone they might not answer cause your mail is in spam.
We have an agreement with a bulk SMS provider to allow us to do this (we had to show proof of our application, our mobile number verification process, and give our use case).
When users send an SMS from within our application, we send it as if it came from their number. Then recipients can then reply directly to their phone. Our users love it.
So yes, there are real use cases where the ability to do this is beneficial.
Users can love or hate all kinds of things, and often those preferences are at odds with security or other best practices.
Aspire to better.
If we have validated our users mobile numbers via a TOTP code, informed them that they are sending SMS as their number, then how is it different to an application like Signal or iMessage linking your messages to your mobile number? It's not.
And that's why it's allowed with certain SMS gateways. The SMS gateways are doing the due diligence to ensure you are sending spoofed messages appropriately and only as the user who actually owns the number.
Edit: The spammers are most likely using gateways who aren't doing these checks. The solution is to fine or shut these gateways down.
No, the alternative is to include proper contact information in the message. Security comes with all sorts of tradeoffs and one of them is often convenience. Is it inconvenient to have to reply to a different number? Sure. Is it worth it--if it means we all no longer have to deal with spoofed ID scam texts? Hell yes!
Until then, every legitimate use case pales in comparison to even a single spam call taking a second of my attention in a day.
It's trivially easy to fake a caller ID, whether for voicemail or SMS.
today I got an obviously scam sms from the SAME number/source as the official ANZ sms'
SMS is a junk protocol. it just needs to be banned entirely. its got no controls or protection whatsoever.
Extremely frustrating because they look more legitimate this way, like it's a local business calling me back or something.
Provider: Boost Mobile (MVNO for Sprint/Tmo)
Why does the media do this?
https://getyarn.io/yarn-clip/921915b0-4a3b-4e96-beed-eb7b50a...
Years ago, bills were introduced Congress that would've made falsifying Caller ID illegal, but certain people said it would be too onerous for small businesses. One bill passed in the House and was sent to the Senate, where it was promptly ignored (H.R.251 - Truth in Caller ID Act of 2007).
Lots of people, both those who know nothing about technology and those who know enough to know better, say this isn't enforceable because too many people are doing it.
Bullshit. Like spam, if you establish punishment for those who allow spam, you have a very simple mechanism for enforcement.
In the old days, when we got spam, we'd forward it to the administrators of the system that sent it or the administrators of the network where it originated. They'd warn, punish, and/or remove the person / system responsible for the spam.
These days, abuse@yahoo.com doesn't work, GoDaddy, Cloudflare and others won't do shit unless you find their web page for reporting abuse, then jump through hoops to shoehorn the spam in to their intentionally shitty web page, and even then they pretty much ignore it. Google just ignores everything sent to abuse@google.com.
Imagine if every spam that's ignored led to a fine. It'd be chaos and mayhem, but within a year we'd be back to how things were in the early '90s. Of course that wouldn't affect spam from the rest of the world, but imagine if large US networks stopped accepting email entirely from Chinanet until they started acting on abuse complaints.
The same can be done with Caller ID. You've got a T1 that lets you set your own Caller ID? Great. You might not get caught, but you can set what you want.
Your upstream provider might ignore it, but they connect somewhere larger, too. So let's say AT&T customers are getting complaints about phone calls with false Caller ID, and AT&T looks in their logs and sees that they're coming from your upstream. Now your upstream is in trouble unless they fix it. If they don't, they get a nice hefty fine.
How do they fix it? They force you to stop. If you don't, it's illegal, so they can contact the authorities. Or, they could just terminate you.
This is just like egress filtering in the networking world. If your network is passing along lots of spoofed traffic and someone contacts you to tell you, and you just pretend it's not your problem, you should be punished. You shouldn't allow traffic to leave your network that claims to be from sources that aren't on your network.
"But routing!" Bullshit. If it's coming on to your network from elsewhere, you should be required to say from where, so the originating network can be identified.
However, businesses don't want to be bothered putting any time or energy in to this. Businesses rarely do a thing because it's the right thing to do, unless they can make it a marketable advantage. They need to be forced to do this by law, by threat of loss of money.
Caller ID spoofing should've been illegal all along, and businesses which do nothing about it should be punishable. Because that's not the case, the old fashioned phone system might as well completely die.
The combination of Pixel and Google Fi means you never get spam calls, or spam texts.
There are plenty of other ways to accomplish what SMS and email do, but you will always need SMS and email. And the world is not creating standards like SMS and email anymore, at least with any widespread adoption success.
My point is you're right no replacement exists today, but the technology does and could easily be expanded if the phone companies agreed to phase out SMS.
Of course the technology exist, it's not like sms is some marvel that humanity could never reproduce. It is just that noone has the right incentives to do it properly or with users interest in mind.