It was ridiculously often in 2020/2021/sometime in 2022 maybe?
My understanding is that without STIR a gateway acting in good faith can't definitively identify malicious traffic, and a gateway acting in bad faith can claim any malicious traffic they forward appeared legitimate.
1) Deploy caller ID signing. <--We are here.
2) Deploy policies to make inter-telco tracebacks easier and increase liability for carrying too much spam.
3) Drop unsigned traffic and shutdown spam friendly portions of the PSTN (analogous to open email relays).
4) Use the tracebacks and KYC to deter robocalling operations from getting onboarded and ban current customers who are robocalling. And keep them banned when they open new sockpuppet accounts. It'll never be completely eliminated.
5) See 4.
Two-thirds of PSTN traffic is unsigned. https://transnexus.com/blog/2023/shaken-statistics-july/
Even if there is thorough, mandatory KYC for VOIP services, we will just have robocalls being routed through simboxes filled with prepaid SIM cards. The whack-a-mole game will move there and the carriers will lose just like they do in Africa and the Middle East where people use them on a giant scale to arbitrage termination rates.
it would cost a lot of money, especially if carriers limit the number of numbers you can call each month before an additional charge (100-200 numbers / month then extra fee ?)
> You can get local phone numbers for a trivial amount of money
and companies that provides phone numbers them can also monitor suspicious traffic.
I remember that when I first opened an account at Callcentric, they froze it until their support could reach me to ask a few questions.
Now, I've had it for a few year, did just a few calls, and I no longer have to go through that to subscribe to more services.
On a slightly different topic, cloud providers have learned to keep their IPs clean, even if you can get some for cheap. They just check what you're doing.
So it can be done !
Anything like this would still have to be affordable enough for call centers and businesses. A pharmacy can easily have 10-20 lines: A few for the cash registers, a couple for the office, and a bunch for the pharmacy (they might still have a fax line too). It is easy to see how a call center or a large department store (wal-mart) might reach 100 lines.
And on top of that, you'd somehow have to make this international and get other folks to enforce this - and this is assuming the scam call centers are following the law in ways that the country in question can actually enforce.
I always like the sound of the simple solutions, but every time I get look into these details, I can understand why they don't just work.
The telcos might be a common carrier, but as the end user I sure as shit should be able to block calls originating from providers I see abuse from constantly. I'm looking RIGHT AT YOU, TxtNow.
Cell phones surface the SHAKEN/STIR attestation status to the user via a checkmark in the telephone UI.
If you want to programmatically act on that data to filter calls... Android provides access to the attestation level via the android.telecom.CallScreeningService API. (I can't speak to what iOS provides.) For VoIP, many providers will also either pass along the attestation level in the SIP headers or by appending some text to the Caller ID string.
If end users could directly and simply block carriers that waste their time by delivering shit calls, this entire issue would have worked itself out years ago. I just don't think that the current strategy of having the FCC yell big numbers at foreigners is really doing all that much...
I think all the IP based providers in the US have implemented SHAKEN/STIR. There is still a small amount of non IP based systems which FCC is looking for solutions. And international calls will take some time as other countries look into implementing similar methods.
The dangerous issue is that if a spam operator has 33% legit traffic, do you kill the spam operator and the good traffic with it, or what? Kill the traffic... innocent people harmed, or leave the traffic, spam continues.
Yes, we should with these long-time, serial offenders. Having legit traffic is just a fig leaf cover for them anyway. Any legit reseller clueless or negligent enough to accidentally stumble into business with these guys will switch providers as soon as their customer's calls stop connecting.
Also, no real telecom providers are routing meaningful amounts of traffic through these shady operations. Any legit traffic on their networks is mostly coming from fly-by-night, bottom-feeding telecom resellers in the same countries the spam calls originate from. Any retail customers of those resellers are probably paying ripoff prices for unreliable per-day or per-call service anyway. It's not people with normal pre-paid monthly service from any legit telco you've ever heard of.
Also end-users should get information from every hop, so we can block whatever we want with full information, client-side, uBlock-origin style.
You don’t get to facilitate in illegal shit and hide behind your legitimate customers. Likewise, if you are a customer of theirs and know they heavily transact with illegal services, it’s on you for getting blocked.
"too big to jail because they are too big to fail"
https://www.investopedia.com/stock-analysis/2013/investing-n...
And will probably have to jump to a more expensive provider who isn't subsidizing them with spammer revenue.
You are implying that "you" means the telco or FCC decides on behalf of "everyone." That is not the correct viewpoint. If the telcos are the common carrier, they dont get to decide. I am the customer; I get to decide. Problem solved. No additional regulation or debate is needed. This isn't hard.
I am the customer and I would love to see the data of which providers _originated_ each call that I'm about to answer. That would make it trivial to set rules about which ones don't even ring. But until I can have that data, I wish they'd just drop the obvious junk.
The telcos have this information, but they only usually relay the CallerID (which is user-specified, ie "spoofable") to the end user. ANI, RPID, and now SHAKEN/STIR information which does identify the origin and origin carrier are simply not passed to end users to do anything with, or at least I have not been able to get them to do it despite having capable interfaces.
If only we actually had that ability. The best mechanism available to me is what I do: if I get a call from a number that isn't in my phone book, I don't answer it.
"We" do, if people would ask properly for it instead of trying instead to break the customer/common carrier contract.
The carriers withhold information from customers that is useful to determine the nature of traffic and whether it should be accepted or rejected. The amount of metadata that accompanies a modern phone call is substantial, and the carrier typically relays only ONE FIELD to the customer.
Customers should demand access to all call/circuit/packet metadata that is necessary or useful to implement their own traffic policy. To the average person, I can see why it might seem that the carriers appear to be ideally suited to police this problem, but the correct way for them to do it without violating their obligations as a common carrier is to empower their customers with the information and the tools to do it on their own.
Spamhaus publishes information on network space which originates large volumes of spam.
Mail system operators use that information as they see fit.