FCC threatens to disconnect Twilio for illegal robocalls
commsrisk.com
commsrisk.com
1. Commio and its subsidiaries Teli and thinQ (commio.com and teli.net)
2. Telnyx (telnyx.com)
If the FCC reads this comment: look into those two. In particular, both companies do a poor job of policing their resellers/affiliates. Even when a recipient is savvy enough to find the source OCN and report it to them, the spammers just move from one reseller to a different reseller of the same carrier.
Both carriers know this and look the other way, since it's cheaper than than investing more resources (content blocking, tighter velocity limits, carrier-verified opt-in) or removing the resellers who repeatably sign up spammers. Twilio was in the top 5, but as a % of their total traffic, nowhere near Commio/Teli and Telnyx.
(And if the FCC is reading this, a wish: add a "SPAM" or "ABUSE" SMS keyword that carriers are required to process. Operationally, it would behave similar to "STOP", with a couple differences: it would be entirely processed by the carrier; the carrier would be required to respond with the name and full contact info of both the carrier and their customer; and it would give responsible carriers a way to hear about/act on abuse complaints. Right now, 10DLC spam is so hard for regular people to track that abuse mostly goes unreported.)
Been getting spam texts out the wazoo and have felt powerless to do anything about it beyond delete them
Doesn't help if there are no domains linked, and I'd still love to attack their SMS instead because I suspect that's harder to replace.
Is there any way to send the SSL-encrypted webpage to prove to the SSL provider that the website came from them though?
I guess in my case they could open the link, but that may not always work.
He was trying to scam her with the promises of riches
This summer, sparks fly in the romantic comedy of 2023: "Phish into my Heart"
Cinema when I grew up was calling into advice radio shows because someone couldn't sleep on their architect-affordable houseboat in Seattle.
None of that exists anymore.
You'll need either access to an SS7 routing system or, more likely, an HTTP API that exposes 10-digit number routing info. Google for '10 digit OCN lookup' or 'realtime CNAM lookup API' and you'll be on the right track. You need one that handles mobile number portability. Most APIs charge a small per-query fee because it's not static data. Any one number can be ported at any time and the only way to know is to see where (in SS7) it's actually routed.
And be aware that there's a fair number of gotchas. I have a lot of experience in the telco world[1]. The two big gotchas are:
1. Inbound and outbound carriers can be and often are different, and outbound caller ID can be spoofed. The source number on an SMS from a 10-digit number (a "10DLC" SMS) is much, much less likely to be spoofed than the caller ID on a robocall. You can fairly reliably report source numbers on SMSes.
To keep it simple, consider starting by reporting SMSes.
For robocalls, expect that many robocall CIDs are spoofed, and the most interesting robocalls are the ones that ask the recipient to contact them at the same number. Or, where both the CID and the callback/contact number are DIDs from the same carrier.
2. Number portability means that all the old static databases (LERG and NPA-NXX-Y Number Pooling[2] databases) aren't enough. One phone number might be routed to one carrier and the sequentially-next number might be routed to a completely different carrier, and either of them might change the next day.
This is just the start - there are other gotchas and a pretty significant learning curve. Stay polite and professional, assume good intentions, and assume you're wrong about something.
[1]: Back in 2010, I made the first free, public REST API for looking up phone data: https://www.slideshare.net/troyd/cloudvox-digits-phone-api-l..., https://www.prnewswire.com/news-releases/cloudvox-launches-f...
[2]: https://nationalnanpa.com/ and for thousands-block reports, https://www.nationalpooling.com/ -> Reports -> Block Report by Region
We at Plivo also provide such an API which incorporates number portability for US: https://www.plivo.com/docs/lookup/
Plivo's API above is updated on a daily basis for portability information.
Caller ID as you mention for voice calls is quite easy to spoof, however with the STIR SHAKEN rollout, the intention is to make carriers accountable. SMS however with 10DLC is almost impossible to spoof the number.
For Twilio: Per https://www.twilio.com/docs/lookup/v2-api/line-type-intellig..., include the query parameter "Fields=line_type_intelligence". That param will make the API response populate the key "CarrierName".
For Plivo: As noted in another reply, Plivo's Lookup API returns carrier info. Per https://www.plivo.com/docs/lookup/api/response#response-exam..., responses include the carrier name by default.
https://support.twilio.com/hc/en-us/articles/360050891214-Ge...
The ThinQ side of the house seems to let dialer traffic slide: https://lowendtalk.com/discussion/183904/lowend-sip-trunking...
Ie Passport/valid driving license.
Not fool proof and comes with its own set of problems. But it’ll likely get us most of the way.
- Slowly increase velocity limits on new DIDs/TNs. Often, examine the outbound content before raising limits - is it something anyone would request? where/how?
- Require the recipient to have opted-in on the same carrier (ie, no importing lists)
- Don’t let the affiliate/reseller sign up customers on their own. Centralize onboarding/KYC.
- Verify the end customer’s government-issued ID.
For texts:
- Block (and flag/escalate) based on message content, like the domain name/URL they’re linking to or a pitch phrase they’ve used.
This never happens. Lots of PPP or bank fraud investigations go nowhere because the perpetrators used fake IDs all the way down. No company is actually checking the governments database of drivers licenses or state ID cards. Only recently did eCBSV come out which would allow companies to digitally check that an SSN actually exists (mostly to stop synthetic identity fraud) but that still doesn't stop identity theft.
DID: Direct Inward Dialing is a method organizations use to route incoming calls to specific private branch exchange (PBX) systems without an operator. Organizations purchase DID numbers from a telephone company or service provider and assign them to individual extensions within the organization.
TN: Telephone Number, this initialism is interchangeable with DID.
DLC: Installations using Digital Loop Carriers connect analog phone lines of individual users into a single signal sent on single lines to the central office of a phone company. The combined signal is separated into original signals at the central office.
A 10DLC A2P SMS is an SMS sent from a 10-digit number and triggered by API (or anything else automated). Maybe the SMS is your doctor’s appointment confirmation system or an online retailer telling you your order has shipped… or maybe it’s a spammer. If it comes from a 10-digit phone number instead of a 5-6 digit short code, that’s 10DLC.
In the last year or so, a registry for 10DLC A2P numbers has emerged (https://www.twilio.com/docs/sms/a2p-10dlc, https://support.bandwidth.com/hc/en-us/articles/442382643458...), but adoption is mixed, enforcement is low, and end consumers/recipients don’t see any of it.
There’s also “Person-to-Person” (P2P) 10-digit SMS, like you texting a friend. Those can also be used to spam (hook up a computer to a consumer SIM), but it’s much less common, especially in the US. Most US-originating SMS spam comes from 10DLC A2P numbers.
That said, I've got no idea if they actually do anything actionable with this data. It certainly doesn't seem to have reduced my spam volume. Now I just let Android Messages filter the spam out.
I wonder if that's what the iPhone's "Report Junk" button does with text messages.
For some reasons, my iPhones on AT&T always offer the option to report a text message as spam, but my iPhones on Verizon do not. Another curiosity.
"In the list of messages, touch and hold the spam message, then tap Report Junk. Or, if you’ve opened the message, scroll to the bottom of the message, tap Report Junk, then tap Delete and Report Junk."
I've read that "Report Junk" does the equivalent of forwarding to 7726, but I don't have a way to verify that (more: https://www.bandwidth.com/blog/apples-ios-16-update-and-what...).
In the case of 7726, I’m further confused that there seems to be no acknowledgement of this source of ambiguity. Do they want to know the source of the spam, so I should manually add it to the message? Or are they just training a content recognition model and by sending anything other than the original text verbatim I’m throwing it off?
Also, when the forwarded spam contains a URL, iOS often automaticity chops off that part of the message and shows an unhelpfully truncated version of it below the message in a separate bubble. Is iOS treating the forwarded spam as trusted data and probing the spammer’s URL, tracking parameters and all?
Most likely they just use the reported message to train their spam filter, not to block the particular sender number of that message.
I have never had a spam SMS or call in Norway, while on Malta it's a regular occurrence, thought not as bad as described by US folks.
Every single time the subject of robocalls or spam texts is brought up on HN, someone claiming to be from Europe shows up to ask why it's a U.S.-only problem.
Then people from Germany and France and Greece and the U.K., and elsewhere in Europe show up and say how they have to deal with it, too, and it's not just an American thing.
In my RSS feed are several European news sources, and they all talk about robocalls occasionally.
Who are these apparently very few people in Europe who allegedly have never dealt with telephonic spam, and why do they always feel the need to talk about their personal situation when it has no bearing on the discussion at hand?
You state that you "hardly ever receive unsolicited SMS or phone calls."
I'm in America, and I too get unsolicited messages "hardly ever": about one unsolicited SMS per month, and spam phone calls about six times a year on my work phone, and maybe once each year on my personal phone. Don't delude yourself into believing that every phone in the nation is flooded with spam all the time.
I have two phones, and usually just put the one for the country Im not currently in on a charger and hide it away in a drawer, and take it out only when Im packing to go to the other continent again.
The Canadian phone usually gets 50-100 spam messages and missed calls during the 2-3 months Im not using it.
The Czech phone has never had a spam message or missed call on it ever.
I dont see why strories like this would have no bearing on this discussion. Its relevant, anecdotal evidence.
But carriers recycle numbers, often pretty quickly after someone ends their service. The number on the Canadian phone of yours may have previously belonged to someone who plastered the number all over the internet, and used it to sign up for a bunch of things run by people who had no qualms over selling their customer data to spammers.
So no, these stories are not particularly relevant or useful, because they can never take into account the full history.
And you just took the info I provided, and added another piece of the puzzle. The observation that more spam exists in US/Canada still applies, is supported by my anecdote, and explained by your analysis. To me, very much proving this info is indeed relevant to the debate.
Unless we want to go super meta about relevance and usefulness.
I learned new things, thank you.
One of the reasons I can imagine is that the Bundesnetzagentur is actually pretty quick about disconnecting abusers.
Here in Germany at the very least this isn't the case as robo calling as well as unsolicited cold calling to private households can be fined with high fines of 10k+ Euros per call. I've maybe had two calls like this in the last 20 years.
It‘s definitely no so bad that people don‘t pick up for unknown numbers/callers anymore, which seems to not be uncommon in the US.
This mirrors the experience of everyone I know. When an active robo-scam-call campaign was happening to people it made national news.
That's a very large difference with the typical US experience...
Used to get a lot of phone spam before the telephone preference service (TPS) came in, but not since. Quite a bit of spam in relative terms when running a business landline in a retail shop; tech support scams, service switch scams, invoice scams, but only about once a month.
published their contact information in a public database (like company registry),
given their contact information to a company and unwittingly checked the "agree to use for marketing purposes/share with third parties" consent
are included in a high profile data breach of some kind
are the unlucky, statistically unlikely victim of spam from a new source that is yet to receive punitive action
How is this avoidable specifically in Europe you say? Breaches affect us here just as much as anywhere else, specially since most breaches are user/client lists from large corporations most people can't afford to stop dealing with.
> are the unlucky, statistically unlikely victim of spam from a new source that is yet to receive punitive action
Unlikely? Given the rate at which scam and spam calls have increased in my country as data breaches built up, and this has been going for long already, I doubt they're getting much punitive action here.
Don't use your main phone/mail for registration, so you can avoid spam on it.
> Unlikely? Given the rate at which scam and spam calls have increased in my country as data breaches built up, and this has been going for long already, I doubt they're getting much punitive action here.
I'm not talking about data breaches, that's covered in previous point. I'm talking about punitive action towards spammers that dial random numbers, etc. as they're easily identifiable by the operator
AIUI, this is because in the US they don't set aside different prefixes/area codes for mobile/cell numbers, so when they were first introduced and mobile calls cost more, it was unfair to bill callers extra because they had no way of knowing they would be calling a mobile number. Therefore, they put the extra cost onto the receiver of mobile calls. With this billing expectation in place, they put the cost of SMSs onto the receiver also.
It does mean that in the US, businesses sending SMSs to individuals are supposed to go through a "double opt-in" process and have really easy opt-out procedures, on pain of the FCC having some kind of punitive actions available. But I guess they must not be working, or something.
Or my info may be out of date?
That said, unlike in Europe, there are also effectively no truly free (i.e. no monthly fee) prepaid plans in the US.
So in a way, you could also say that users are still sharing the cost of inbound texts, although at an implied flat rate (blended into the monthly minimum that exists even for pay-as-you-go plans), rather than per message.
Technically, the FCC cares about as much about unsolicited robocalls as they do for unsolicited SMS messages for the TCPA. And the penalties can add up quickly; $500-$1,500 USD -per violation-, not per person you violated the TCPA (IOW, if your automated system sends 10 texts to 10 people that it shouldn't have, it's potentially $50,000-$150,000 and not $5,000-15,000).
The upshot for -consumers-, is that there are lots of hungry TCPA lawyers that will happily take your case. Some people even try to file claims themselves, even if it may not be fully legitimate[0].
The issue with robocalls, versus SMS messages: I've found that even if you follow the TCPA 'Script', you'll at best wind up in a weird state in the robocaller's system where they will still call you, but the system immediately disconnects. On top of that, the numbers are often spoofed anyway[1] so it's difficult to get the right number. AFAIK SMS messages, it's harder to spoof the number.[2]
[0] - 'Illegitimate claim' can range from "Somebody didn't pay attention to a box they checked on an online form" to "Welp this guy's going to jail for stalking... I guess stupid criminals do exist."
[1] - IDK if SHAKEN/STIR will help much, but here's hoping
[2] - OTOH There is a real problem with numbers getting 'poached', even if they are already registered with a VOIP carrier that follows all the proper processes around porting. One bad actor makes it easy to mess up the system.
That explains all the weird messages apps show about verification SMS "incurring charges"! Back in high school I avoided so many apps for no clear reason because I was afraid I needed to pay a fee every time I used these apps and only found out years later that none of that stuff would've cost me anything.
A service where you have no real say in the charges you need to pay when someone else contacts you through it sounds so crazy to me! I'm pretty sure most people in most countries don't get charged per SMS anymore, though.
The US environment led to prices trending to under a penny to send an sms or make a one minute phone call. IIRC, FCC rules say telephone carriers can no longer charge other telephone carriers for calls at all, the wholesale price is zero (+ connection costs).
On the other hand, in Europe, sending an SMS or calling a mobile phone for a minute is closer to 10-20 cents. That's a lot costlier, and then you've got a lot more languages to support, and different payment preferences per country. Easier to just target English and the US.
The interconnection rates used to be an important source of income for mobile operators (some of them would even pay their prepaid users, not paying any monthly fee, a bonus per incoming minute of calls!), but these days, mobile and landline interconnect rates have almost converged, as far as I can tell.
E-Plus also hasn't existed as an independent entity for quite some years now; they were acquired by Telefonica/O2 in 2014.
Seems like Twilio is charging quite the margin there, based on vastly outdated pricing...
I don't understand what do you mean by that. If the sender and recipient are both in US how does this make sense?
If you call outside your local area, that's a bigger charge, at least historically.
But, cell phones are more expensive to run than landlines (historically, anyway), so the question becomes who pays that extra expense when someone calls a cell phone. You can do caller pays, and then typically have mobile numbers in a separate part of the numbering plan and cell phones receive free incoming calls; or you can do recipient pays and mobile numbers are usually mixed into the numbering plans and cell phones have to pay for incoming calls.
As time goes by, costs go down, but caller pays carriers have an income stream from incoming calls that's harder to drive down with competition. Few people are going to switch carriers so it's less expensive for others to call them. Especially if retail plans tend to bundle things.
But for recipient pays carriers, there is competition among carriers to make it less expensive for their customers to receive calls, and now most US carriers offer unlimited talk and text on retail plans on most plans, even low cost plans.
But that's not something particularly unique to the US?
High cost is an effective anti-spam technique, but it also raises costs for legitimate business uses.
I'm paying €8 for 10000 minutes, 10000 texts and 100Gb of traffic per month.
https://slate.com/technology/2022/04/spam-calls-why-ajit-pai...
1. PEERLESS NETWORK OF OHIO
2. PEERLESS NETWORK OF FLORIDA
3. PEERLESS NETWORK OF CALIFORNIA
4. PEERLESS NETWORK OF CALIFORNIA
Nothing from Twilio, but Peerless Network certainly stands out. I see they describe themselves as "A Disruptor and Aggressive Innovator".
https://techcrunch.com/2022/07/26/us-and-european-comms-plat...
Once you have an actual company behind the robo calls you can sue. Telecoms providers should be required to be helpful in providing information when abuse is reported or be liable themselves as if they were responsible.
It seems like a solvable problem but nobody is actually solving it.
This would be used for doxxing people. Anyone you text can get all the information they need to swat you.
Most of us companies, work quite hard to deter these spammers at sign up and later using automated systems to analyze usage patterns including content filtering, but its quite a cat and mouse game.
Something that has worked for us has been to restrict signups to only work emails. It does have it's disadvantages but we have been able to limit the random gmail id signups at scale by bot/spammers that abuse the system for use cases like robocalling and more.
I friend of mine used to work for them in the early days and had some pretty terrible stories about what it was like working there.
Fraud, abuse, and unwanted calls are unacceptable, and, like the many companies standing between companies placing calls and consumers receiving them, we take all such reports very seriously. We offer a Report a Number link on our website so any unwanted call placed using a number we sold can be investigated, traced, and action taken to shut down the traffic.
Commio (thinQ/teli) was a member of the Federal Communications Commission’s task force to combat fraud and robocalling and we are an active member of the working groups resulting from that task force. In addition, we have implemented STIR/SHAKEN protocols to help stop fraudulent calling from spoofed numbers, and are also set to launch one of the first branded calling solutions to enable brands to fully sign and vet their calls, preventing spoofing once and for all. 2025 is going to be one for the record books.
Who is Commio: Commio does not make any calls to consumers and generally only provides a network interconnection “bridge” between a calling party’s telecom provider and a called party’s telecom provider. We provide voice interconnection services to other telecom carriers, enterprises, and cloud platforms. We provide service to virtually every major national carrier in the United States. We also provide interconnection services to VoIP providers. We essentially carry phone calls between all of these telecom companies. As part of our service, we also provide telephone numbers to VoIP providers, who then assign these numbers to their end-user subscribers. We provide phone numbers to these VoIP providers because regulatory restrictions limit their ability to obtain their own phone numbers.
How We Can Help: Commio does not provide service to individuals and, by law, is prohibited from knowing the identities of our customers’ end users. Because of this, we must forward most abuse reports we receive to the service provider to whom we have assigned the number in question. We will promptly send your report to the appropriate service provider and request they promptly commence an investigation.
Please also note that our services are not exclusive, and just because a number comes back to Commio (thinQ/teli), it does not mean we carry all traffic for the originating provider. Our service-provider customers have the option to use other carriers to transport some or all of their calls. When our service-provider customer sends voice traffic to another carrier, the call does not touch our network.
In some cases, we can provide you with contact information for our service-provider customer. If that option is available, Commio will send you an email with the service-provider’s contact information so that you can work directly with them to resolve your complaint.
Sometimes, our customers will investigate a report and determine that the calling number has been “spoofed.” Caller ID spoofing occurs when the caller inserts a falsified number into the call stream so that your Caller ID shows a phone number that did not make the call. When this occurs, neither we nor our customer will actually know what number or person made the call. Please understand disconnecting a spoofed number will not stop the calls you are receiving because that number did not make the call – it is simply fake Caller ID information sent to your phone.
If you need additional information about spoofing or stopping unwanted calls, the Federal Trade Commission (www.ftc.gov) and Federal Communications Commission (www.fcc.gov) have both posted information and tips on their websites to help consumers including information about call blockers, the national Do Not Call Registry (www.donotcall.gov) and how to report numbers associated with scam calls.
I would also strongly urge you to contact your local law enforcement agency for assistance if you receive fraudulent, abusive or threatening communications and you are concerned about your safety.
Troy, thanks for listening, and feel free to reach out to me anytime: tim (at) commio.com.
Late last ever, they started sending me warning notes insisting that I fill out all kinds of paperwork for my "business" if I wanted to continue sending SMS messages. None of the paperwork made any sense for a hobbyist, but they insisted. It was clear that this requirement was coming from outside of Twilio, so I wonder whether it was the result of earlier discussions with the FCC. Since I don't use the Light Phone any more (couldn't do without a camera), I just turned off SMS delivery rather than deal with all the new bureaucracy. But I still use them for another hack: I can call a Twilio number and leave myself a message, which they will then deliver to a hook on my web server, along with a transcription.
I'm impressed with Twilio technically, and I can sympathize. I wouldn't want to be caught between the FCC and a bunch of SMS spammers, especially if the spammers were customers.
Had the FCC implemented something like this the rules would be much more consistent and the fee structure would not be so exorbitant, but instead the big 3 have formed a cartel to attempt to control SMS messages in the USA.
I’ll get multiple texts from politicians on the same day when I’ve actively “unsubscribe and report as junk” for several years now. I’m political active but don’t want to be text spammed.
I’ve reached out multiple times asking to remove my contact or to add me to a global deny list and they say “that’s not possible, we don’t control who our clients send to” which is absolute garbage. But if they had that feature the people who pay them would get fewer messages delivered so they don’t want to implement it.
No matter how many lists I take myself off, there’s no way to prevent someone from adding it back on to a different list and these days candidates each have dozens.
It’s frustrating to lose agency like that and I’ve stopped donating through them all together :(
If you ask to be "removed from mailing lists", they will tell you that the only way to do so is to click the "Unsubscribe" link in the footer, and that there's no way to prevent yourself from being added to new lists.
But if you're persistent, they'll admit that there's another option: you can ask to be added to the "global block list", which they'll warn you is irrevocable. (I'm sure there's no good reason for the irrevocability, except to make people think twice about taking that option.)
Like you, I have stopped donating to candidates who use them.
Years ago I updated my voter record to remove the email address and phone number, and by the next election, my text, voice, and email political spam dropped to near zero.
I run a few projects that interact with their API for SMS. I recently had to go through some extra hoops to 'verify my business' with them, due to the newer carrier regulations. But overall, works how I expect it to and with minimal issues.
- Vonage: https://www.vonage.co.uk/communications-apis/sms/ - CM: https://www.cm.com/en-gb/sms/
---
Some of the interesting parts:
Dear Mr. Lawson:
We have determined that Twilio Inc. (Twilio) is apparently originating illegal robocall traffic on behalf of one or more of its clients. As explained further below, this letter provides notice of important legal obligations and steps Twilio must take to address this apparently illegal traffic. Twilio should investigate the identified traffic and take the steps described below, including blocking the traffic if necessary, and take steps to prevent Twilio’s network from continuing to be a source of apparently illegal robocalls. Failure to comply with the steps outlined in this letter may result in downstream voice service providers blocking all of Twilio’s traffic, permanently.
... Applicable FCC Rules. This letter is based on FCC rules that apply to originating providers like Twilio. First, under the safe harbor set forth in section 64.1200(k)(4),4 any provider may block all traffic from an originating provider that, when notified by the Commission, fails to effectively mitigate illegal traffic within 48 hours or fails to implement effective measures to prevent new and renewing customers from using its network to originate illegal calls. This letter provides notice under section 64.1200(k)(4) and describes the mitigation steps you must take. Second, section 64.6305(e)5 permits providers to accept calls directly from an originating provider only if that originating provider’s filing appears in the FCC’s Robocall Mitigation Database. As explained below, if Twilio continues to transmit illegal robocalls, the Bureau may initiate proceedings to remove Twilio’s certification from the database, thereby requiring providers to cease accepting calls directly from Twilio. Third, sections 64.1200(n)6 and 64.6305 prescribe various additional obligations for mitigating and preventing illegal robocalls. We remind Twilio that failure to comply with any of these obligations may result in additional enforcement action pursuant to the Communications Act and the Commission’s rules.7
... If after 48 hours Twilio continues to originate unlawful robocall traffic from the entities involved in this campaign, downstream U.S.-based voice service providers may begin blocking all calls from Twilio after notifying the Commission of their decision and providing a brief summary of their basis for making such a determination.15 Furthermore, if after 14 days, Twilio has not taken sufficient actions to prevent its network from continuing to be used to transmit illegal robocalls, then downstream U.S.-based providers may block calls following notice to the Commission.16 U.S.-based voice service providers may block ALL call traffic transmitting from Twilio’s network if it fails to act within either deadline.Second: At a larger scale this is the balance between providing a service that is cheap and ensuring your service isn't used for nefarious purposes.
What happens next is that there will be more stringent identification needs, and then apps like MySudo get into trouble...
What's key here is that robocalls are so universally loathed by everyone that dealing with it has extremely widespread bipartisan support. Coupled with the authentication technology to actually source the offenders, the FCC knows on this particular issue nobody in government will slap them down for doing what needs to be done, and they have the information to do it.
Government agencies can be very effective when they know that an action will not be questioned politically.
How would it be possible for them to police every action of their customers? I expect actions to be brought against the individual violators, and then escalated to Twilio, and handled appropriately. As is the case here.
It would be different if they actively support systemic violation, but I don't think that's the case?
However, to defend Twilio... I have about a dozen numbers, all for little automations, and the past 6 months they've been REALLY heavy handed about requiring them all to be registered and a bunch of other requirements. I get a ton of emails like "Register your 10DLC numbers to avoid unregistered fees", etc. They've been tightening the requirements, too. At first it was 3,000+ messages/day, now it's my 1-message-a-day-to-the-same-number accounts they're cracking down on.
The number of VOIP callers I want to contact me: 1 (my doorbell (I assume it's VOIP, not sure))
The number of non-US callers I want to contact me: 2 (family members who could just contact me in other ways)
Even if I have "agreed" to let some company contact me, like the phone company or my ISP, I'd still rather not receive calls from them.
But non-US callers can get US numbers. Do you want the phone company to fax over a passport scan of everyone who calls you?
If a phone company does not provide information about all the hops, then all calls from that company should be blocked as well. Ideally phone providers would not be allowed to forward calls from such a network at all.
I also don't think anyone should be able to send me physical mail without me approving each individual piece of mail through some sort of digital service that I would likely ignore.
The Traceback Consortium conducted tracebacks and determined that Twilio was originating apparently unlawful robocalls on behalf of MV Realty through its dialing provider PhoneBurner. The Traceback Consortium notified Twilio of these calls and provided access to supporting data identifying each call… Twilio told the Traceback Consortium that PhoneBurner had obtained called parties’ consent for the robocalls. Neither Twilio nor PhoneBurner provided the Traceback Consortium with evidence of consent.
https://www.forbes.com/sites/kenrickcai/2020/02/11/twilio-je...
https://www.twilio.com/press/releases/twilio-joins-state-att...
https://www.twilio.com/press/releases/twilio-achieves-full-c...
The second Twilio press release (Twilio Achieves Full Compliance with STIR/SHAKEN Protocols to Combat Illegal Robocalls) is dated July 22, 2021.
The FCC complaint has calls dated July and August of 2022.
The FCC is taking a firmer stand and threatening those that support robocalls all the way down the chain. All CPaaS providers need to do a better job managing their customer vetting processes.
Its not “guilt by association”; Twilio has, under the relevant laws, a positive obligation to prevent illegal use of its platform on pain of disconnection.
The title could make it clearer, both interpretations could come from it.
Note that this isn't a "we didn't know about this" and is part of the "this is what you sign up for when you're a telephone service provider."
47 CFR § 64.1200 - Delivery restrictions. - https://www.law.cornell.edu/cfr/text/47/64.1200
> (4) A provider may block voice calls or cease to accept traffic from an originating or intermediate provider without liability under the Communications Act or the Commission's rules where the originating or intermediate provider, when notified by the Commission, fails to effectively mitigate illegal traffic within 48 hours or fails to implement effective measures to prevent new and renewing customers from using its network to originate illegal calls. Prior to initiating blocking, the provider shall provide the Commission with notice and a brief summary of the basis for its determination that the originating or intermediate provider meets one or more of these two conditions for blocking.
There are some other fun things in section (n) about the requirements for a voice provider.
> (n) A voice service provider must:
> (2) Take steps to effectively mitigate illegal traffic when it receives actual written notice of such traffic from the Commission through its Enforcement Bureau. In providing notice, the Enforcement Bureau shall identify with as much particularity as possible the suspected traffic; provide the basis for the Enforcement Bureau's reasonable belief that the identified traffic is unlawful; cite the statutory or regulatory provisions the suspected traffic appears to violate; and direct the voice service provider receiving the notice that it must comply with this section. Each notified provider must promptly investigate the identified traffic. Each notified provider must then promptly report the results of its investigation to the Enforcement Bureau, including any steps the provider has taken to effectively mitigate the identified traffic or an explanation as to why the provider has reasonably concluded that the identified calls were not illegal and what steps it took to reach that conclusion. ...
> (3) Take affirmative, effective measures to prevent new and renewing customers from using its network to originate illegal calls, including knowing its customers and exercising due diligence in ensuring that its services are not used to originate illegal traffic.
https://www.twilio.com/blog/2016/02/tracking-call-status-how...
This has been going on a while.
I guess it was taken care of.
> Our system is currently down due to upstream telephone carrier issues
> A quick Saturday evening update - outbound dialing was fully restored and stabilized Friday. Whisper/Barge was restored late Friday evening. We anticipate click-to-call will be restored before end of day Monday, if not sooner. SMS, Inbound, and number purchasing is expected to be restored by end of day Wednesday, if not sooner.
The game of whack-a-mole continues!
Last year, after receiving several spam texts from numbers that were registered to Bandwidth.com (which was already difficult to discover), I sent an abuse report. I was not only told that Bandwidth.com couldn't do anything about it (other than forward the report to the reseller), but also they couldn't even tell me who they were reselling services to due to privacy reasons, and did not even know who the end customer was. They advised me to contact the police... To report text message spam.
That is a cunningly devious misdirection!
Then, along comes scam callers and illegal telemarketers. They have the capability to spoof arbitrary phone numbers to call you, which you as an individual do not have. Then, even if you do discover a real outgoing number that traces back to them, they can hide their true identity behind this bullshit “privacy” excuse.
OCN = operating company name, name of company that has the number CNAM = Caller-ID name is textable -y/n nntype = mobile or landline
Most of these guys will charge you 10-20% less than bandwidth.com or Twilio will in return for slightly lower reliability. nCLI means you can't set caller ID because the call is coming over GSM, i.e. a simbox type setup. TDM usually means they are reselling traditional phone lines meant for businesses. If you think this already isn't being used to facilitate scams you'd be wrong: https://globalvoipforum.com/threads/offering-russia-for-fore... (unless by "forex traffic" they mean promoting Interactive Brokers). That's an example I found in 5 seconds. Go on some Facebook groups and you will find people offering grey routes to call America for "Amazon traffic," "bank traffic," "crypto traffic." I never really took the time to investigate what those terms mean but it does not sound good to me.
You can buy jigs on aliexpress that hold 128 SIMs and round-Robin across 8 GSM radios.
It’s not all for spam per se. Some countries/providers charge a ton for international incoming calls, so bypassing this by IP and making calls in-provider only saves a lot of $$$ for gray-market connectivity.
And it’s cheaper for setting up of in-bound calls too than a business line.
https://m.aliexpress.com/item/32947688074.html?spm=a2g0n.pro...
Or 32 SIMs with 32 radios:
https://m.aliexpress.com/item/32819345650.html?spm=a2g0n.det...
Seems like quite a reasonable request. Put in an effort. Outline what those processes are and stay on top of them.
They might fine the companies running the robocallers/callcenters if they're in Germany, but they're absolutely never touching the providers who are happily supporting the criminals and instead throw their hands in the air and say "guess we can't do anything".
The same applies to the large scale phone fraud though, which quickly gets into tens to hundreds of millions of euros per year. Police won't do much because the criminals are outside Germany and cooperating with e.g. Turkey is hard, and with India it's impossible. Phone companies don't care because they're making money and the regulator is asleep at the wheel.
Let's just make the phone companies liable for damages where they can't produce the customer (no KYC) or the customer is international. They'll quickly figure out who is legit and who isn't when it actually hurts their bottom line.
The land line calls were mostly spam, mostly from established companies, and some scams. A side effect: they went from 70€/month to 15€, 22€ after the first year.
I had got them a 35€ contract (land/fiber + 2 cellphones) three or four years ago, but somehow Movistar managed to creep the bill to double and had announced that it will start charging 120€ this year. Because reasons.
The cost cutting can be immense as you mentioned. Plenty of people have ancient contracts that they never changed.
This would result in prepaid sim cards going away which would create a lot of problems for homeless people and illegal immigrants.
Especially in regards to expensive numbers, some critics go so far and say they got an "employment ban". They are not soft at all. But obviously they can only react.
But they don't. You can check their actions: https://www.bundesnetzagentur.de/DE/Vportal/TK/Aerger/Aktuel...
They're fining ~20 companies per year for spam and have shut down a few numbers and stopped billing on a few foreign premium numbers. Other than that: nothing. They're simply ignoring the companies that are complicit.
If they're not the right organization to enforce rules, that's fine, let's create one that does and hasn't been closely embedded within the industry for the past decades.
If such functionality were well-implemented, you'd be able to disable it for a limited amount of time if you're expecting a call, and then the setting would kick back on automatically.
Apple and Google could work together (or even 100% independently) to tackle this at the handset endpoint level, yet there is no serious investment. They both have the data to create extremely robust solutions that could kill such life nuisances once and for all. Why do they continue to sit on their laurels rather than treating this as the serious abuse it is?
I get more text-message and phonecall spam than ever. Whatever [meager] measures have already been attempted are completely insufficient and have failed.
Imagining a future where my children perceive this as normal doesn't seem right. What can we do about this?
iOS does. It’s called “Silence unknown callers” in the phone app settings.
I expect android has this as well.
The iOS texts are especially bothersome because they appear on every device and machine hooked up to iMessage.
I just looked and Android does have this setting buried under several slices of the phone app settings layer cake. It's better than nothing but I'm unwilling to accept that this is respectful to end users. It's really hanging all out non-experts to dry, when they absolutely should be in control.
What if your mother had an accident and is in the hospital, should the hospital send you an email and ask you to allow incoming phone calls? Could they even, if your spam filter wouldn't let their email through?
And if it's straight to voice-mail, you'd still need to spend the time to check it, albeit maybe you could check when it's better for you.
They could screen it with a voice assistant, but I doubt that'll work well, spammers will just set their systems up to say stuff that gets them through the screening and then switch to the spam once they get to you. And when the assistants catch on, it has lots of fallout because suddenly your kids' school can no longer reach you because the assistant flags everything about schools and kids because spammers have abused it.
Google and Apple both have more than sufficient data to train ML models which could provide a thorough solution.
Could Twilio simply add a boolean to their 'make a call' API endpoint where the user has to declare that they have, in fact, obtained consent to call a particular number?
That would provide no technical barrier against fraud, but it may suffice as a legal CYA for Twilio.
Actual FCC C&D letter is at https://www.fcc.gov/document/fcc-issues-robocall-cease-and-d...
Key takeaway, there is no safe harbor CYA of the type you suggest, they need (and basically immediately) to take effective steps to prevent robocalls that are factually illegal, they don't have the option of getting CYA certificates from their users to insulate them if the users keep making illegal calls.
While I'm certainly far from being a contract lawyer, it looks to me like the FCC is interested in receiving evidence of consent for the offending calls, if it exists:
>The Traceback Consortium conducted tracebacks and determined that Twilio was originating apparently unlawful robocalls on behalf of MV Realty through its dialing provider PhoneBurner. The Traceback Consortium notified Twilio of these calls and provided access to supporting data identifying each call, as indicated in Attachment A. Twilio told the Traceback Consortium that PhoneBurner had obtained called parties’ consent for the robocalls. Neither Twilio nor PhoneBurner provided the Traceback Consortium with evidence of consent.
And:
>If Twilio has evidence that the transmissions identified in Attachment A were legal calls, present that evidence to the Commission and the Traceback Consortium.
In any event, if consent to place calls is required, then there has to be some mechanism for call origination services (here, Twilio) to demonstrate receipt of that consent. My question is, what exactly does the FCC require as proof of consent?
Presumably someone was spamming service sign ups using my number. Any clue why?
The verification codes were typically 6 digits, so if they did this with a million other numbers, they would "get lucky" about 400 times, but that seems unlikely to me to be what they were doing.
Also hall of shame to SeetGeek for allowing 50 sign up attempts in as many minutes all from the same number; every other service stopped well before that.
Surely if they disconnect Twilio then the robocallers will just move on to another service? And the only people who will be negatively impacted by this are those who want to use Twilio legitimately.
I'm really struggling to understand the sentiment here.
It's also very likely they had previous communications between the FCC and Twilio, and possible that, like many tech companies, Twilio refused to delete a customer without an official order.
I guess that they are not obliged to deal with it at least in most countries. I honestly don't know much on this space but this article raised my curiosity.
Get rekt Twilio.