The most insane "robocall mitigation plans" that telcos filed with the FCC
arstechnica.com
arstechnica.com
I'd like to know too. I am sure that spammers will try every delay tactic in the book, and while I am glad to hear that a deadline is approaching I am not pleased to learn that they were able to buy 20 months of time over the last deadline with a low-effort windows print test page. At this rate, actual lawyer tactics will buy them 20 years of delays for them and spam for us.
This mindset goes back to the AT&T antitrust breakup. It was decided that phone companies would not be allowed to reject each other's traffic, because the larger ILEC's (incumbent local exchange carrier) would find reasons and excuses to cut off the CLEC's. This would be more or less a death penalty to those businesses, and the ILEC's had exactly zero reason to want the CLEC's to exist at all, so there was a lot of fear and rulemaking to prevent this.
Fast forward 30 years and the details have changed, but the mindset is largely the same. The fear is still quite real, and that's why phone spam isn't treated like email spam. If i.e. verizon cuts off incoming calls from a random CLEC in a midwestern state, that business is just over, done, that's that. It would be impossible to restore the business after your customers left, which they would do more or less instantly; there's no court remedy that would fix it. Great pains are taken to ensure that such an action is legitimate.
The rules are oriented around the idea that the ILEC's were evil antitrust actors, and the plucky CLEC's are the competition we need to protect from big ILEC's heavy hand. In a world of spam, that mindset is backward. And that mindset is changing, but because of the reasonable concerns, it's taking longer than we expect.
"Finally, he noted that the FCC might have been hesitant to take an action that could harm customers. "One reason to be hesitant is that it's not just the bad actor network that gets cut off," Feld said. "Any innocent customers get cut off. This really goes against the entire mindset of the FCC. Generally, the FCC is about making sure that networks stay operational and that calls go through."
Plenty of those seem to be non-US providers; perhaps their attitude is "Oh, some foreign regulator. Not my problem". But the regulator isn't actually regulating these providers; it's just listing the ones that (claim to) have a mitigation plan, however feeble.
I just meant that someone is going to wake up, and realize that it's their problem, personally.
Or not.
Ah I see. I was just trying to cover my bases to avoid splitting hairs over what compliance desk means and get to the point about these companies probably not being sophisticated enough to comply (or appear to comply).
> I just meant that someone is going to wake up, and realize that it's their problem, personally.
> Or not.
The or not is kind of what concerns me, because this might be the end for a lot of these companies. Rather than just cutting people off, the FCC should take a role kind of like how the Fed does, but for telecom. Take over the carrier, continue operations, assist the legit subscribers with moving onto a compliant carrier and then shut it down. I'm not sure how number portability is affected when a carrier just shuts down, but it might not be pretty.
A lot of people take the "shouldn't have signed up with spammy telco!" stance here as if everyone has the gift of knowing how to vet a carrier. Hopefully not too many people (and ideally no people) get hurt by this sort of enforcement.
I got the impression that a lot of these firms are overseas. E.g., SIA Tet seems to be Latvian. The FCC can't just direct these companies; but they can "advise" (lean on) domestic carriers not to deliver their traffic.
The present telco network is very much operational. We don’t need an extremist response to spam from the FCC that causes making a phone call to acquire ‘aml attributes.
An element of our younger siblings' (Gen Z) entire culture is a fear of/avoidance towards making and taking phone calls. Communication ecosystems have been built and crossed to the other side of the chicken-and-egg/network-effect hump l because POTS is so bad.
The only people left with landlines that lack caller ID and 'suspicious caller' filtering are the elderly, where they're continuously preyed upon by spammers.
A shame, since if there was one thing the landline phone network was, it was reliable - in a way that cable can't even hope to match. Too bad that it got to be reliable for scammers as well.
This isn't the network losing relevance, she's literally still using it. She's just gatekeeping with her contacts.
I'm not saying we don't need to clamp down. But the downside of clamping down too hard is the calls from contacts in her address book not getting connected. That, and HN being littered with stories about people who are--for some random reason--unconnectable due to no fault of their own. That's the natural response if you let the "throw everyone in jail for the most minor infraction" crowd into the building.
I am sure that a few of them are genuinely clueless, but at some point we have to cut them off to get their attention and I don't see how 20 months will help over 2, not when the ask is "make a plan."
More recently I've recieved a lot of calls from regular people "calling me back". I reached out to my provider a few times, especially about the spoofing, but they claim theres nothing they can do, which I highly doubt.
I was a bit inspired by Cory Doctorow's "Red team blues" wherein the protagonist carries a burner, but has her main number behind an Asterisk server forwarding allowlisted numbers to the active burner.
Anyone know of anything like this? Ideally very DIY and FLOSS?
I imagine you could do some cool stuff with Whisper and LLMs, either wasting their time (like lennytroll mentioned elsewhere), but even better some autonomous bastion asking the caller to explain their reason for calling and letting the owner validate the answer through speech-to-text in an app, then decide wether to let it through or to "let me tell you in great detail about my grandchilds vacation to Mauritius"-land.
It's a weird opposite world we live in where companies hide behind endless teleprompts, but citizens have no such shield
Basically: if ( in_allowlist() || called_twice_in_a_row() ) { allow_call() } else { respond_with_beep_beep_problem_please_retry_your_call() && hangup() }
...all humans (eg: doctors offices, appointment schedulers/verifiers, etc) are like: "huh, phone system must be f'd up right now" and call right back. All mechanically dialed spammers just $PHONE += 1 and continue dialing. Son kept an eye on the "called twice" and added them to the allowlist (or maybe you could just auto-add if they ever call twice, and then validate / name / prune new entries once a week or so?)
I am using https://gitlab.com/xynngh/YetAnotherCallBlocker right now, but my country wildcards doesn't protect me against spoofed domestic calls - Forking and extending with this approach might work! TY
The hope is that it results in some self-reflection for the caller, though it hasn't reduced the number of calls.
I'd be curious to hear how your approach works out. Ultimate best scenario would be to get completely removed from their lists - but I've almost given up hope on talking sense, and my provider, leaving Fire versus Fire.
I don't think there is any action a consumer can take to reduce the number of calls or get removed from a company's lists. There is no incentive for the company and the person who calls is as much a victim of capitalism in that moment as you are. Just two people wasting each other's time as a result of the operation of a corporate machine.
One problem with this method is that your burner will still accept incoming calls from any number, so you'd lose caller ID information if you want to make sure only your VOIP server can call you. Of course you can just set it up to send you the caller ID through some other channel - like a text message.
But anyway you can make a really simple lua script that looks at a text file to see if the number is allowed, then forward it to your burner. In FreeSWITCH you just do something like <action application="set" data="allowed=${lua(allowlist.lua)}"/> and act on that variable accordingly. Then you can use whatever command line tool you prefer to add and remove numbers from the file.
If you need some help, drop a burner email and I can reach out.
I guess I'd have to decide wether the bastion should forward or channel/tunnel the call. My knowledge in telco and VOIP is very limited, do you know if there's any way to identify a number one has been forwarded to? If so, complete isolation and using some other channel to transmit the caller id would be preferable.
That is really kind of you to offer, thanks a bunch!
Do you mean like the calling party being able to find out what your burner number is?
I think that information could be revealed if you do a SIP refer. To be extra careful, you'd want to answer the call on FreeSWITCH/Asterisk and then bridge it to your burner number through whatever gateway (e.g. Signalwire, Flowroute, Twilio, whatever SIP provider you choose). The calling party will just see that they're calling your bastion.
It can also be revealed if you have the default voicemail set up on your burner, since a lot of voicemail systems will read the number out to the caller.
Why would your SP be able to do something about someone else on another network spoofing your number and calling a random third-party that is also possibly on a different network?
The whole problem here is there is nothing in the legacy phone network to validate that calling party information is accurate (at least, between service providers.)
> contained only the company's business address
> a signature page on company letterhead with no substantive content or context
> a .PNG file that depicted a corporate icon
> contained only a signature
I reckon spammers were not pleased.
I'm pretty sure that's a photo of the lid of someone's chest freezer.
Is there a way to do that?
I guess all these protocols or FCC rules are worth shit because they do not care. Sure they will block canabis delivery notifications I get every two month but not scam call which get like 40 per month.
If every single iPhone user, for instance, wasted 10-30 minutes of time for robocallers, stringing them along, the economics of the robocalling fall apart. If Android also does the same thing, then even more so. That "industry" would self-destruct within months.
Whether the carriers would allow this though, when they stand to lose so much business, that's another story.
[1] https://support.google.com/phoneapp/answer/9118387?hl=en
Here's a DIY solution: https://www.lennytroll.com/
And a $2/month batteries-included solution: https://jollyrogertelephone.com/
That would mitigate nearly ALL robocalls.
I reckon it would be beneficial to discover why such a thing was allowed in the first place, and for what it is commonly used aside from robocalls.
It's a legitimate use, but comes with a high potential (and reality) of abuse.
The Telco knows exactly which line that call originated from, and knows who is responsible for paying for that connection.
I'd certainly delete old numbers used by people I'd want to be able to contact me, that's a bit of a downside.
Did you know that people lived before phones? It's still possible!
I would much rather live in a world where where _real_ messages dominate our channels of communication. A world where I can contact people "out of the blue" without suspicion of scam or fraud.
Yes, it achieves the desired outcome, but it has rather adverse side effects.