FCC Closes Robocall Loophole
fcc.gov
fcc.gov
We just recently purchased a landline and have told nobody our phone number, so 100% of incoming calls are spam (and we get a few every day). It's amazingly frustrating.
only thing that will fix it is burning it to the ground.
fcc regulations and penalties mean nothing to shady offshore grey market scam call centers in india using suspicious/unethical voip providers and methods of getting phone traffic to the US/Canada.
shaken/stir is a joke
set up a voip based system with IVR on your incoming DIDs that asks the caller to input a short series of digits to be connected, then have that series of digits ring your real line.
it will filter out about 98% of the crap
Assuming your telco won't help you with whitelisting, your options are maybe? getting a new cordless system with caller id whitelisting, it seems like maybe some of the newest panasonic dect systems can do it (that will take care of the answering machine needs as well). Or getting an external box, most likely inline with your phone.
I don't have either yet, but it seems like reasonable options include the Digitone proseries II [1], or the Sentry call blocker[2]. Both are more expensive than they should be (IMHO), but offer some amount of whitelisting and blacklisting. The Digitone has a longer history in the industry, and what looks like a clumsier interface; the Sentry has a good, but slightly messy feature for handling inbound calls from numbers that aren't 'known', for those calls, it answers and plays an outgoing greeting (customizable in the 3.x device, prerecorded in 2.x), if the caller presses 0, their number is added to the white list and they can call back; from reviews, I gather on the 2.x series pressing 0 add you to the whitelist and then hangs up on you; on the 3.x series, pressing 0 generates a fake ringback, makes the device ring (but not phones on the line) and after 9 fake rings will let the caller leave a message on the sentry device (2 message capacity, FIFO). This is like not quite right; the recommendation from reviewers is to record a message asking people to press 0 and then hangup and call back, rather than having them go through the weird ringing stuff. There's some negative comments about recording quality.
The Sentry is much better, but has some notable flaws.
The Sentry works as a whitelist, so it blocks all calls by default. After you enter your whitelist (family, friends, etc.), you'll get three types of calls:
-Good Calls: From people on your approved list. These calls ring through as normal. -Bad Calls: From idiots (aka robocalls). The idiots aren't smart enough to press a button, so they don't, and then the Sentry hangs up the call. -Other Calls: From humans who are (ideally) not idiots, but aren't (yet) on your list.
This third item is where the Sentry really needs improvement. Other callers hear a (horrible quality) outgoing message, so they can either hang up, or press a key to leave a message - on the Sentry, not your answering machine/voicemail. The message they leave is only 20 seconds, and you can only receive two messages. And you can't screen these calls - you don't actually hear the person leaving the message, and you can't pick up the call if it turns out it's valid. And the Sentry doesn't timestamp the message. There's a log of calls, but you have to work to figure out who actually called, especially if the caller's message was cut off.
(What I would prefer is to have callers press a button, then my phone rings like normal.)
If you don't get a lot of "new" numbers calling you, the Sentry isn't bad. But you will miss some calls, especially at first. Thankfully, there's an on/off toggle for those times when you're expecting an important call from an unknown number (delivery guy, hospital).
(Assuming you don't specifically wants POTS though.)
At this point, retrofitting CAPTCHA in as an expected part of the telephone system seems like the only option that will make a significant dent.
100% blocking all not whitelisted calls is a more convenient alternative.
For every 300 calls I get, maybe 1 isn't spam. I probably get 5 spam calls per day and under 10 legitimate calls per year.
There are so many simple things carriers could do. The biggest would be simply deleting silent voicemails would help a lot.
I kind of wish a company that actually cares about voice phone calls would come around. Give me the highest fidelity calls possible, give me features for recording, give me the option to block all non-authenticated callers, show me the actual call data and not just the caller id, etc...
For example, you could port a number to VoIP.ms, and (in their terms) set up a caller ID filtering rule based on phone book entries, with the those entries managed either through the web form or API. If you wanted known callers to reach your mobile phone instead of a VoIP phone, I imagine you could use a call forwarding rule. Unknown callers could be routed to a busy signal, voice mail, a "not in service" message, or handled in a variety of other ways.
Because the problem's not just with landline but with any direct-dialed PSTN telecoms system. I don't want a landline or mobile phone any more. The situation's well past simple cord-cutting.
It's been about three years since I stumbled across this quote which confirms that at least someone on the inside is aware that the present situation is eroding all trust in the system, and that this is an existential threat:
[S]ince mid-2015, a consortium of engineers from phone carriers and others in the telecom industry have worked on a way to [stop call-spoofing], worried that spam phone calls could eventually endanger the whole system. “We’re getting to the point where nobody trusts the phone network,” says Jim McEachern, principal technologist at the Alliance for Telecommunications Industry Solutions (ATIS.) “When they stop trusting the phone network, they stop using it.”
https://nymag.com/intelligencer/2018/05/how-to-stop-spam-rob...
(From an earlier HN comment of mine: https://news.ycombinator.com/item?id=21542926
Stir-Shake may have reduced levels of spam, I've no way of knowing. But the level it's at remains intolerable and a real financial risk to individuals and businesses. I'm personally aware of several people who've been scammed of thousands of dollars within the past year.
Cut phone service and that threat disappears, along with all the attendant billing bullshit and customer service nightmares.
Is the industry aware of this and what if anything does it plan to do?
it's a legacy of the 1950s and 1960s era of the monopoly bell system when all of the phone system trusted itself.
the whole way that traffic moves between telcos in the PSTN is built on lack of crypto authentication, total trust between two phone switches, in a way that would be absurdly terrible if run on the modern internet (imagine all your online banking as http only, for example).
Or have any idea of what a solution-shaped object might resemble?
Your answer ... mostly confirms my outsider view. And that story ends poorly.
Thanks, regardless.
Headline: they never had a chance.
Conspiracy: they didnt want to.
- First of all, the legacy telco network is still out there in huge quantities. This is the copper landline to grandma's house. It speaks SS7 and TDM which have no inherent concept of identity: the tekco switch simply inserts the calling number in the signaling, the end. There is no economic incentive to replace any of this old stuff since there is no marginal revenue to be made. It will rust in place.
- the telco network has long supported cases where the caller had a legitimate need to replace their number with another. Your doctor calling you always shows as the office front desk, never their direct line.
- this use case gets even worse when you have call centers and other high volume users. Use of VoIP makes the modern call center possible, but also trivially easy to change the calling ID, and again, perfectly legitimately for the businesses that use it.
- extra wrinkle: offshore centers. now some agent in India needs to present as if they are calling from Ohio. No problem, VoIP can do that. But the same tech that does that also means their evil twin can call you up from an area code that looks like your town to ask about your car warranty.
I could go on, but this is a really hard problem.
The legacy assumptions built into PSTN seem to be getting in the way. Simple dumb terminals with no logic greater than being able to generate pulses or tones, logic in centralised switches (which should make upgrading more viable). Identity presumed to be based on the device and circuit, rather than the person at the end of the line (in the increasingly rare cases where a person is in fact at either end of the line). Stronger authentication, and different levels of authentication, are both necessary. (And some preservation for anonymous communications, within the constraints of technologically mediated telecoms platforms, is also useful --- it has its place.)
I'm also fearful that such a system will become captured by a single entity and not offer interoperability --- the long line of personal messaging systems offered by a string of Internet monopolies and would-be monopolies suggest the position has some appeal, if it's difficult to attain. MCI, AoL, Microsoft Messenger, Google's litany of extirpated chat apps, Facebook, Discord, Telegram, Signal, Protonmail, etc.
In its early years telephony was exclusive, and for much of its existence, expensive. Those cost barriers to usage meant that the worst abuses of the system were avoided (though the annoyance of telephone solicitation were still remarked on).
I'm not sure how or where volume increased, though Google Ngram shows "telemarketing" and a set of related terms taking off in the 1970s and 1980s:
https://books.google.com/ngrams/graph?content=telemarketing%...
> Sprawling networks can be upgraded with gateways and bridges where wholesale replacement isn't viable. Rural services (telephony, electricity, water, gas, sewerage, postal, ...) are often noneconomical and in the US there's a long tradition of either cooperatives or government-run (often municipally-organised) services, and/or steep subsidies.
this is really overly optimistic, you underestimate how moribund the traditional telco/copper POTS line/dialtone service is. the various ILECs around the USA and their patchwork of territories are putting the bare minimum into keeping some of this stuff running. nobody is going to retrofit custom gateways into their network.
they'll spend money on lobbyists and lawyers to fight back against doing anything other than maintaining the status quo instead.
I think that all those companies are dead or acquired now.
My British and Danish mobile phone numbers get less than one junk call per year.
The call volume went way down after a while.
I did make some vacation package scammers feel bad and hang up a couple times. Claiming that I no longer travel because I lost my legs In a car accident years back.
Family that can use the vacation package? Nope, they are all dead too. The last of them died in the same fiery crash.
They will give up.
If you engage with them they will continue to call. Do not speak to them, just answer the call and leave them listening to nothing.
# no call center supervisor will let their employee just sit there and wait for you to answer....your silence actually does cost them money.
One might even be "marked" as "listening the marketing material" which would end up getting more calls.
I grunt and listen for a response (if any). It's pretty easy to distinguish a human from a robocall nowadays. There was a brief time when a woman's voice would say "hello, uh, hello? can you hear me?" which got me once, but that was it because it played whether you made noise or not and was always the same.
American scammers usually laugh at that, but it instantly enrages Indian scammers. I think their mothers don't know, and would be ashamed if they did.
It’s an incoming call whitelist, others go to voicemail.
This makes this a non issue.
Blocking unknown is strictly better than blocking everything.
Automatically transcribed voicemails work in exceptional cases like you describe.
Some have battery backup and so kind of work the same as before ... for awhile.
what prefixes in blocks of 10000 numbers belong to what specific carrier is public info
prefixes that are assigned to a carrier like tmobile or that were a metropcs prefix before its full integration into tmobile are highly likely to be cellphones, though people can of course port away their number to a voip service or something, but more often they would just move to verizon or att.
How did they get your number?
It's an inconvenience if a company wants to use automation to return my call. I can turn this off, temporarily. As I see it, it's stupid of any legitimate company to imitate a robocall for any reason. I don't walk up to cops carrying a fake gun; they shouldn't behave like spammers.
(Also, I wish Nationwide would stop trying to sell to me over the phone. They're amazingly persistent.)
Those are not mutually exclusive. From what I've heard[1], the "extended warranties" are grey market car maintenance insurance that basically exclude everything you might expect from coverage, and anything that might be covered, it's reimbursement only, they don't pay up front. The only thing it is good for is liberating people of their money.
Sure they are. It's just that the phone scammers are living off of affiliate and referral fees.
shocked pikachu face. Which explains why Canada didn't provide any exemptions.
Also, I love this bit from Wikipedia:
> The name was inspired by Ian Fleming's character James Bond, who famously prefers his martinis "shaken, not stirred." STIR having existed already, the creators of SHAKEN "tortured the English language until [they] came up with an acronym.
"Signature-based Handling of Asserted information using toKENs"
CALEA rollout was before my time, I wonder if it had a similar rollout.
Every call has to talk to Google assistant first. Makes up for Google removing HDMI output.
Media Contact: Will Wiquist will.wiquist@fcc.gov
For Immediate Release
FCC CLOSES ROBOCALL LOOPHOLE FCC Robocall Response Team Has Taken Enforcement Actions, Built Nationwide Partnerships, and Proposed Innovative New Policies to Combat Scam Robocalls -- WASHINGTON, June 30, 2022—Starting today certain small phone companies must comply with FCC rules to implement caller ID authentication tools on their networks, just as large voice service providers are required to since June 30, 2021. Today’s announcement is the latest in a series of actions by the FCC’s Robocall Response Team to cut off the flood of unwanted robocalls hitting consumers and business phone networks. These small phone companies are suspected of facilitating large numbers of illegal robocalls and, as a result, the FCC rolled back an extended caller ID authentication implementation timeline granted to them in its original 2020 rules.
“Each time I get a robocall it reminds me that we can’t stop looking for ways to stop these nuisance calls and the scams behind them,” said FCC Chairwoman Jessica Rosenworcel. “Our team is working to aggressively and creatively find ways to fight back. We will use every authority we have, and we will go to Congress for more. We will not let up.”
How We Got Here: In 2020, the FCC granted voice service providers with 100,000 or fewer subscriber lines an extension of STIR/SHAKEN* implementation requirements, consistent with the TRACED Act. However, since then evidence emerged that a subset of these small voice service providers were originating an increasing quantity of illegal robocalls. As a result, in 2021, the FCC unanimously voted to shorten the extension by a year.
Recent FCC investigations and reports from the Industry Traceback Group indicate that, since STIR/SHAKEN was widely implemented across the largest providers’ networks last year, robocallers have sought to maintain anonymity and avoid enforcement and blocking tools by routing or originating their call traffic on the networks of these largely IP-based* small providers that have not yet implemented STIR/SHAKEN. This has allowed robocalls to pass from these networks to terminating provider networks without carrying forward accurate and standardized caller ID/traceback information.
What’s New: Effective today, a problematic gap in FCC robocall rules closed, requiring non-facilities based small voice service providers* to implement STIR/SHAKEN caller ID authentication standards on their networks. These providers are now required to implement STIR/SHAKEN caller ID authentication standards on the IP portion of their networks.
The Bigger Picture: Under Chairwoman Rosenworcel’s leadership, the Robocall Response Team was created to serve as an FCC staff working group that pulls together expertise from across the agency to leverage the talents of enforcers, attorneys, policy makers, engineers, economists, and outreach experts to combat the unyielding menace of illegal spoofed, scam, robocalls.
This effort has resulted in: · record-breaking spoofing and robocall fines; · closing gateways used by international robocallers to reach Americans’ phones; · widespread implementation of STIR/SHAKEN caller ID authentication standards to help traceback illegal calls and improve blocking tools to protect consumers; · the signing of robocall investigation partnerships with the large majority of state Attorneys General; · and unprecedented policy proposals to combat the rising threat of bogus robotexts.
###
Appendix of frequently used terms: · STIR/SHAKEN Caller ID authentication: Caller ID authentication, based on so-called STIR/SHAKEN standards, provides a common information sharing language between networks to verify caller ID information which can be used by robocall blocking tools, FCC investigators, and by consumers trying to judge if an incoming call is likely legitimate or not. · Non-facilities-based voice service providers: A voice service provider is non-facilities based if it offers voice service to end users using connections that are not sold by the provider or its affiliates. Instead, their voice service is transmitted over another provider’s transmission service. · IP-based telephony: IP telephony is shorthand for Voice over Internet Protocol (VoIP), which is a technology that allows a user to make voice calls using a broadband Internet connection instead of a regular (or analog) phone line.
Media Relations: (202) 418-0500 / ASL: (844) 432-2275 / Twitter: @FCC / www.fcc.gov
This is an unofficial announcement of Commission action. Release of the full text of a Commission order constitutes official action. See MCI v. FCC, 515 F.2d 385 (D.C. Cir. 1974).
In our case, someone's sister invited him to join their account. The text message was initiated by the sister but our system sent the SMS via our backend. We were sued because we allegedly sent an unsolicited text message and were considered an autodialer under TCPA guidelines.
We were able to win the suit, but it cost hundreds of thousands of dollars. The law needed a tune up, and if the court decision stopped this type of troll suit some good came of it.
I am not defending robocallers. I hope they die. I just highlight that sometimes these laws do need to be tightened up to stop abuse the other way.
June 24, 2021 - https://www.natlawreview.com/article/ripple-effects-supreme-...
> If you work in the Telephone Consumer Protection Act (TCPA) space, you are certainly aware of the landmark unanimous decision by the United States Supreme Court in Facebook v Duguid, in which the Court narrowed the definition of an automatic telephone dialing system (ATDS) to equipment that has the capacity to either store or produce numbers using a random or sequential number generator.
> ...
> On June 10, 2021, the District Court for the District of South Carolina held that the Aspect predictive dialer did not qualify as an ATDS because the evidence proved that the system could neither randomly nor sequentially store or produce numbers to be dialed
---
So, if you're working from a list of numbers, it's not an ATDS. It is only an ATDS if you're dialing random numbers or sequential numbers.
https://en.wikipedia.org/wiki/Facebook,_Inc._v._Duguid
> The Supreme Court's ruling was seen to be favorable to the telemarketing industry, since the decision narrowed the definition of an automatic dialing system of which are regulated under the TCPA. As few actual automated dialers in use at the time of the decision incorporate the random or sequential number generator, telemarketers would be able to use other automatic dialing systems that do not meet this definition to engage in their business, according to the National Consumer Law Center. The National Consumer Law Center as well as Consumer Reports expressed concern that there would be a significant increase in unwanted telemarketing calls due to this decision.
> Senator Ed Markey, one of the authors of the TCPA, along with Representative Anna Eshoo, called the ruling "disastrous", as the Congressional intent of the TCPA was "to ban dialing from a database", and announced the same day of the decision that they would be looking to introduce amended legislation to address the Court's decision.
> (1) The term “automatic telephone dialing system” means equipment which has the capacity— (A) to store or produce telephone numbers to be called, using a random or sequential number generator; and (B) to dial such numbers.
> (1) The term “automatic telephone dialing system” means equipment which has the capacity— (A) to store or produce telephone numbers to be called, using a random or sequential number generator; and (B) to dial such numbers.
It's part of a coordinated plan to "drown the federal government in a bathtub": the courts read legislation as narrowly as possible while congress is unable to legislate.
Here are some of the cases they brag about: https://edelson.com/inside-the-firm/905-2/
(1) The term “automatic telephone dialing system” means equipment which has the capacity—
(A) to store or produce telephone numbers to be called, using a random or sequential number generator; and
(B) to dial such numbers.
Anybody who's claiming the Court is playing games here clearly has an agenda of their own. Congress dropped the ball.In the current legislative session [1], just counting the first page of Senate (I think you're referring to the Senate) votes listed because I'm lazy, out of the 100 votes, I see only 10 that failed. And of those passing, I didn't actually count, but a very large proportion are passing with less than 60 yeas.
Although we see a lot of political crap going on, the Congress still manages to do a lot of business.
[1] https://www.senate.gov/legislative/LIS/roll_call_lists/vote_...
Legislation passing with less than 60 votes still had to pass the 60 vote threshold. Some senators vote for debate but against the bill.
Note also how many are just confirmations of Senate-approved roles.
Further, for your criticism of my methodology to hold water, it would be necessary to see the total number of votes decreasing over time. That's not what the record shows. Using the same resource, I looked at each of the last few years, and then took a few steps back in 4-year steps thinking that maybe there's something corresponding to the point in the presidential election cycle. Either way, I don't see it going down at all. Quite the opposite.
2021....528
2020....292 (not hard to explain the drop in this year, I think)
2019....428
2018....274
...
2014....366
...
2010....299
...
2006....279
The number of votes per year is clearly growing. And in the current session, at least, there's still a high proportion of votes passing, and of them many have a "yeas" count below 60.Yes, I very specifically mentioned that; that means some Senators voted for cloture, but not for the bill. Not unusual. It still needed 60 Senators to get to a vote, but only 50 to pass that vote.
> The number of votes per year is clearly growing.
Votes per year isn't the whole story. More votes on smaller-scope, less meaningful legislation isn't an improvement. You're not going to get any program like Obamacare, Social Security, the Voting Rights Act, the Civil Rights Act, etc. through this sort of Senate. Obama couldn't even get a SCOTUS nominee past McConnell.
And regardless of whether you like this or not, this was not the use case the law was implemented for, which is to stop robocallers.
I thought this post explained it reasonably well: https://www.manatt.com/insights/newsletters/tcpa-connect/the...
Seems like it's very new for small phone companies, but yeah I agree today seems to be a deadline.
So you're saying that, judging by the 3 spam calls I've gotten today on my (very large) phone carrier, these rules don't do very much.
Most spams calls have bene originating through those gateways for the past few months, so this deadline arriving shouldn't have any immediate impact.
Probably need such a broad dispersion and decentralization that you approach a rough high-level facsimile of a UBI before you really blunt the influence your parent post was pointing out.
We already have that problem with 435 people.
https://en.wikipedia.org/wiki/List_of_United_States_House_of...
It's harder to bribe more people, just say it.
There's also a lot fewer languages to deal with in the US, most random recipients can be scammed in English, and if you can also scam en Espanol, that probably brings you to 80%+ of a market with a lot of ability to pay over the phone. A good target market for many things.
Such things have been regulated by national and European law for ages over here, and the GDPR was the latest brick in that wall.
I recall that in particular Americans were very surprised when it passed, while for most Europeans it was simply the harmonization and continuation of very similar earlier laws.
While the GDPR (and predecessors and co-laws) is certainly not perfect, sometimes it works very well.
Yeah, my phone has been defaulted to silent for all callers that are not in my contact list for a dozen years no. I'll never go back to answering calls from people I don't know.
On very rare occasions I'll miss a call from someone I did business with that's not in my contact list, but they typically leave messages that I can respond to.
Link us to some sort of industry news site, or press releases, etc.
No, but that's why I'm skeptical about your claim; I don't think they'd tell you that either.
If they did, I'd encourage you to whistleblow.
As mentioned, there is concern about if the FCC can enforce these rules. But Robospam is bi-partisan. This is one issue I think even our dysfunctional government can agree on.
Technical competence isn't a strong suit.
Hope this curbs spammers ability to use Twilio like services.
https://www.congress.gov/bill/116th-congress/senate-bill/151
> This bill establishes rules and requirements to deter criminal robocall violations.
> Specifically, the Federal Communications Commission (FCC) must [do stuff related to caller ID]. The bill also implements a forfeiture penalty for violations (with or without intent) of the prohibitions on certain robocalls.
The job of the Court is not to determine what's good or bad policy, or to react based on people's wishes. The Court's job is to interpret the laws through the lens of the Constitution. If the Constitution doesn't give Congress the authority to do something (as it certainly wouldn't in your example, see Article I Section 8 [1]), it's the job of the Court to strike down the law no matter how many people would like the law.
They are 100% reacting to people's wishes, even if CWuestefeld thinks they are not.
You can’t have it both ways. Either you have a civil society with things like an FDA and an EPA, or you have none of that and a deeply dysfunctional country.