The sheer volume of calls that go through a phone network, and the lack of a central system to locate the true source of a call, means it's somewhere between prohibitively expensive and impossible to validate and verify the metadata of every call coming into a telco's network.
Isn't that what the SHAKEN and STIR protocols fix? Maybe the telco can't validate every call, but even if they at least told me when the metadata has been verified would be great. Most of my legitimate calls originate from another US number and all of those should be verifiable.
The FCC for example still exempts "small rural phone providers" I believe? Adoption is growing though, but it's hard to say how fast and by who.
It's honestly a cost/benefit thing.. Changing fundamental infrastructure at telcos is super hard and expensive and most will not do it until they are forced to by law.
This is true, but also it does not prevent tracking down the source afterwards. As in, telcos normally have enough records to check a given chain provider by provider. We could still fine the right entity if there were correct laws for it available.
Believe it or not, most non-US telcos don't have (or rather don't choose to have) the capacity to inspect and log every single phone call, because it's not a cost they want to bear for the tiny fraction of calls they might need to look at later.
In the US the govt forces major telcos to either log or copy calls over to the NSA, so it's different but they're never going to use that very sensitive expensive setup to go after scammers.
Even if they did, let's look at what would happen:
A US telco takes a call log that came into their network and tries to work back through the chain of international telco providers that routed the call, to find the source.
It's only a matter of time before they reach a telco in the chain that says "we don't have those logs sorry".
Plus, each telco along the way will charge the US telco for retrieving and providing those logs. No one works for free.
And then even if they get to the source, guess what? It was probably a fraudulent account with a stolen credit card, at a virtual reseller where no human interaction ever happened to set it up.
Sad trombone.
Sure, nobody works for free, but if requests for source become a thing that happens, there will be systems to retrieve it with less work as well. It doesn't need to be a long record - keeping the last couple of days for complaints handling may be painful, but not "too much traffic". If adtech can save all our clicks for analysis, telcos can handle the short term lookups.
> It's only a matter of time before they reach a telco in the chain that says "we don't have those logs sorry".
That's the whole idea - the blame for that specific call falls on them then. Get fined, next time don't lose the logs, sorry.
> Plus, each telco along the way will charge the US telco for retrieving and providing those logs.
Make it a requirement for reporting so they can't - similar to how DMCA safe harbour works. Either you deal with your customer, point at a source peer, or become the responsible party.
> a stolen credit card, at a virtual reseller where no human interaction ever happened to set it up.
That's fine. Close the account and if it repeats too often for the reseller they can get fined until they implement better fraud checks (or prevent large volumes of calls without human interaction). This is not a novel problem - that's why you can't spawn 500 GPU instances on EC2 right after you open an account.
Edit: Back of a napkin - Verizon claimed to handle 800M calls a day some years ago. Logging the 2 source, 1 destination numbers, peer ids and date in binary format, which is all you need for handling complaints, gives you <40GB per day. That's searchable with grep on a laptop. It's definitely not too much data for a telco.
I've been working with or at telcos for more than a decade and I am still regularly amazed (not in a good way) at how complex, messy and byzantine a lot of the internal systems are, never mind anything that needs to talk to another equally (but differently) byzantine telco somewhere else.