The FCC wants to criminalize AI robocall spam
theregister.com
theregister.com
Telcos already know where the connections come from and who to bill for what. Someone just needs to mandate it.
I'd suggest it be optional on a per-customer basis, perhaps with a whitelist.
E.g., the only international calls I ever want to receive comes from family members' cell phones when they're traveling.
I'm 100% okay with blocking all other international calls. If something is that important, they can send me something via mail, FedEx, etc., or send a message courier to my house.
Just make it so you can opt-in to an exception and nobody will care. If you live in the EU and want to call me (as if you know my number, and have reason to call me) you won't have a problem. If you live in Russia you might have a problem - but I have no reason to think anyone in Russia will ever call me so I don't care. The few people who do have friends in Russia can add an exceptions and those exceptions are not enough for spammers to bother operating at all anymore.
This already works: a staple of these threads is some European user who has sender-pays service expressing surprise that this is a problem because it’s so rare in their experience. Those countries can still receive international calls.
I'd also suggest that there be a rebate per spam call delivered. Say, $10/call to the customer.
Telcos could seek 10x that from the upstream who peered the call.
That is, there's a protection and credit to both the end-recipient and the telco provider, which might make the politics of such policy or legislation more widely palatable.
I've thought about that type of spam refund scheme many times and I like it but the potential problem I see with it is the unintended effect of even more spam that you can't ignore by the companies you already have a business relationship with that bill you monthly.
E.g. You get a monthly bill from Comcast to pay for cable tv. With a new hypothetical "spam refund" law, they now abuse it to their advantage by adding a new "Customer Information Updates" fee for $5 to the bill. (They won't call it "marketing fee" or "promotional fee" but something innocuous like "information fee".) The cable company can now can send you more spam by using the "spam refund" law against you.
But... the customer can get a "rebate" on that extra $5 fee by responding to spam and "refunding" it back to the cable company. If the customer chooses to ignore the spam and never refund it, the customer ends up paying the $5 extra fee on the monthly bill. The customer is now paying oneself to to receive more spam that they can't ignore.
A potential spam refund scheme needs protections to prevent abuse like the above.
No, people don't want to pollute their contacts listing by adding every company they have a billing relationship as a new entry to "manage spam". It's visual pollution to have "Comcast" as a useless entry alphabetically in between "Charlie" and "David" just to offset a new spam rebate scheme because Comcast is abusing the law. And if Comcast has multiple identities such as creating "Comcast Updates" and "Comcast New Channels", etc to further abuse the spam rebate scheme for more customer "engagement", you're doing even more digital housekeeping and adding more entries to the contacts listing.
Another problem is that the smartphone's "contacts listing" is a special area that has downstream interactions with other smartphone settings to manage/filter notifications and sounds. E.g. "silence notifications not in contact listing" or "block calls not in contact listing". By adding Comcast into the contacts listing, they can become even more invasive in your life by polluting alerts on your home screen and making your phone ring.
The spam rebate idea can have some weird unintended side effects if such a scheme (or law) is not crafted carefully to prohibit abuse and make life worse.
Yes, we would need to update how we handle transactional emails. No, this would not need to be difficult or even frequently user facing.
This presumes a few advances, such as reliable caller-ID systems (this is presently not the case for North Amercian dialing systems). Friends who are innundated with robocalls noted that they'd received a call spoofing an entity with whom they do have a relationship, however it was clear from the call characteristics that it was not a legitimate call --- among other factors, the caller identified themselves as being from a different entity, which is a pretty low bar.
The problem of mega-services (financial, comms, federal government, etc.) being subject to spoofing simply because so many people have interactions / relationships with them is an extant problem. But odds are pretty good that your local water / sewer / trash / gas / electric service will be less universal, and knowing that they're calling when they do in fact call is useful.
It seems you're associating a contacts list with a friends list. That's not the case. Your contacts are, well, your contacts, and different contacts have different roles. Among other factors, you might set, say, different contact rules, priorities, and ringtones for, say, immediate family, work, casual social contacts, and business entities. The latter would generally not be permitted to call outside regular business hours, and you might specifically restrict them around mealtimes or other inconvenient times of day (redirecting to voicemail or another messaging service, say).
The Public Access to Court Electronic Records (PACER) system charges 10¢ per page. Every month, balances under $10.00 (edit: apparently it's $30.00 per quarter) are forgiven. It strikes me that a similar model could be employed. Are there people who send more than 100 unsolicited texts per month? More than 200?
And to be clear I'm not talking 'normal' as in 'median' I'm talking 'human using their thumbs'. Even if you spend all day every day hunting down craigslist bargains and coordinating swaps
Keep in mind that egregious robocall providers have been making billions of calls annually (55 billion in 2023: <https://www.techdirt.com/2024/01/16/americans-received-55-mi...>), whilst a typical instance was unable to pay a $10 million fine (<https://therecord.media/ftc-settles-with-company-that-facili...>). At that rate, a per-call ding of only $0.0002 (2 hundredths of a cent) might prove sufficient. A penny-per-call penalty should actually be relatively effective against the lowest of the bottom-feeders, though a higher rate would afford additional protections.
The American phone pricing model, charging for "airtime" is absurd
It means that a spammer can pay $10 for 1000s of calls while the same customer receiving the call pays much more than that per minute
It is frankly ridiculous
They already can. There's an internal "billing" code for every call so carrier knows who to bill for having carried that call.
They don't want to "prove who sent it" because all those billing transactions for carrying those calls add up to significant profit, and they don't want to kill that profit if they don't have to.
Politicians think they’re above everyone else, which evidently in this case they’re literally above the law.
Actually, there is a solution: Say that you are back in Europe and a EU citizen. The GDPR applies to them too.
If he is not "in the Union" and the processor or controller processing his data is not "established in the Union" then GDPR does not apply. See Article 3 [1] for details.
Because of that, a lot of folks enter my email address as theirs; often accidentally (they forget the numbers, afterwards, or somesuch).
One lady made donations to her local ASPCA, and used my email address.
They sold me to some of the craziest, most radical-left organizations on earth.
I get hundreds of emails, every day, from these outfits. Some, are absolutely barking mad. Many, are fake emails from politicians.
Even I can't stomach some of the crazy in these emails, and I lean left[ish] (I'm quite centrist, which means leftists think I'm MAGA, and rightists think I'm commie).
Needless to say, unsubs only make it worse.
All because one lady goofed, when entering her email, for a local animal assistance org.
Any idea how GDPR works for EU citizens who reside in the USA?
E.g., suppose I want Facebook to forget about me, but I'm using a U.S.-based ISP to tell them that. Does Facebook have any legal justification for rejecting my request?
Note that data generated only from your time in the US about your activities when in the US probably can still remain.
It doesn't. The cases it applies to are given in Article 3 [1]. It applies to these cases:
• Processing of personal data by entities that are "established in the Union", regardless of where the processing takes place.
• Processing of personal data of "data subjects who are in the Union" by entities not "established in the Union" if it is related to those entities offering goods and services to data subjects "in the Union" or those entities are monitoring behavior of those data subjects that takes place "in the Union".
• Processing of personal data by an entity not "established in the Union" is they are somewhere where Member State law applies "by virtue of public international law". (Anyone happen to have a list of such places?).
GDPR does not even mention "citizens". Every place it talks about data subjects it uses "in the Union".
Note that this works both ways. People who are not EU citizens are covered if they are "in the Union".
One issue that corporations should be concerned about, is if they contract a dialer company to initiate their calls, and that company moonlights to scammers, they get blocked, so the legit corporation gets blocked for being a scammer.
https://www.fcc.gov/rules-political-campaign-calls-and-texts
The UK government sent a white paper to every household with their opinion on it. If there wasn't a special case for this, many households wouldn't have received this. these things can be abused, but paraphrasing patio11 "the optimal amount of fraud(/abuse) is non-zero" [0]. The argument for this applies in this case to.
[0] https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...
Anyone with the mentality ‘this junk mail is more important that your junk mail sticker’ can go fuck themselves - similar behaviours in the physical realm include rape.
These people said they didn't care, and they're literally in the news saying "why didn't anyone tell me?"
> similar behaviours in the physical realm include rape.
There's stretching an analogy, and there's comparing junk mail to rape. This is a first for me.
Then they should either read the news or remove their no junk mail sticker? Attempting to suggest that political mail would have swayed brexit is stretching the analogy pretty thin, too.
This is an important point, because the exemption of political activity is due to the protections of political speech. Imagine if it were not this way, the party in power could simply fine or even arrest their opponents for trying talk to people over the phone. This happens every day in nondemocratic countries. This protection should not extend to AI though. AI doesn't vote. AI doesn't have a voice in a democracy. So allowing AI to benefit from this exemption should not be permitted. I tolerate PEOPLE calling me, because I am a voter and they are voters and we must all discuss the direction our laws should go or who our representatives should be (when we have time). But AI should have no place in the political process. Not for robocalls, not for choosing representatives, and especially not for lawmaking.
Yeah, that would never happen in a democratic country…
I also don't want random people to be able to call me and yell at me about politics.
Enabling phone spam is in no way required for a functioning political system (not that we have one of those.)
Phone spam doesn't inform people on issues, doesn't create meaningful debate on issues, and has no value in strengthening democracy.
Every single candidate that sends me spam loses my vote permanently.
Calling your neighbour is different to being paid to text or call thousands of people daily.
If there exist AI robocalls that start spoofing my friends and loved ones... ugh, I can just imagine the hassle of doing due diligence for every voicemail going forward. (This does kinda remind me of the scams where someone pretends to be a kidnapped distant family member, cries in the background of the call, and asks for ransom money....)
Which isn't a reasonable option for a lot of people assuming there are alternatives.
I do get messages from offices I don't have in my contacts database that I generally want to receive. Ignoring total junk is mostly fairly painless at least for me.
At present, junk callers virtually never do, though that of course may well change.
I'm ... strongly antagonistic to voicemail myself. But even if you don't check/listen to messages, simply noting who's left a message is a pretty good screening method. For most medical comms, you're unlikely to have a meaningful message left other than "call back" in any regard, so enabling but not listening too hard is viable.
Many medical systems now have some sort of electronic patient record which includes medical staff (MD, RN, PA, etc.) messages, though that's no silver bulet either.
Won't work. I have both elderly relatives and young children, and it's possible to get calls about them from just about anyone in their respective facilities. It's not possible to try to find and list the phone of everyone who ever watches over them. Including substitutes and temps and so on.
It is frustrating, though, that they require you to provide an exhaustive list of people who can contact them but they are under no such obligation to do the same for you.
Per another comment, my suburban hospital system has merged with one of the two big city systems and as a patient the electronic health records system saves quite a few phone calls and faxes being sent around. But there are still some calls.
Unfortunately, it's often older people with a greater dependence on healthcare providers who are also targeted by robocallers, fraudsters, and telemarketers, often to devastating effect.
That should cut off most robocallers, shouldn't it?
I get almost 0 spam calls on my GV number, but my carrier number is garbage. I swear they sell my ph# to spam orgs on registering.
I'm confused by this part. How is AI not already included the current law of "artificial or prerecorded"?
The FCC chair here is not saying "we should make a new law saying AI is artificial and illegal for robocalls" but saying "in our opinion AI calls are already classed as artificial under this well-tested law. Please go out and sue some people under the TCPA, here are tools to do that and we'll support your efforts in doing so."
Basically the FCC thinks the existing law covers it, but, it hasn't been tested in a court yet.
Most are easy to detect, simply because they're foreign numbers.
What is worse, are the spoofed numbers. Because it could be related to work, I have to answer those.
I've lost count how many times I've called someone back, mere seconds after missing the call, only to get some frustrated person on the other end:
"I'm so sorry, people have been calling me all day, asking why I've tried to call them"
"I don't know why my phone number is being used for this"
"What, I didn't call you? You must have the wrong number"
etc.
It really was fun listening to callers freak out when they realized what was happening.
I stopped answering my phone a the 12 per day peak. I figure if it's really important they'll leave a message.
Sure. How should they collect that from the overseas scammers who called you?
Internationally sourced calls should be opt-in, this would solve the non-political portion of the spam problem. Almost no one needs to receive calls from overseas.
For example: government forces me to have health insurance, and health insurance is unable to satisfy my needs online - DON'T FORCE ME TALK TO YOUR ROBOTS. These don't typically recognize my voice, and frankly speaking "How can we help you? You can say anything" sounds like an insult to me. Many of the businesses don't even offer touch-tone navigation anymore. It used to be that "Say blablabla, blablabla, or blablabla" meant you could use "1", "2", or "3" respectively, but now even that is no longer working in many cases.
Hire f*ng human, or don't offer phone line at all.
[1] https://www.tz.de/muenchen/stadt/hallo-muenchen/callcenter-b...
What is new is now AI can fake voices and conversations. This makes the cost of such SPAM is lower, and also you can frame someone else. Both of these give incentive to find work around to the current systems (no system is perfect)
Many of these scams are run out of India and Nigeria. They teach English as a second language fairly young. That lets them cheaply target English speaking countries. I am not saying it is because of that but if I was running a scam center (I am already looking for 'the easy way') I am not targeting something where the pool of people I draw from need to know another language. One scambaiting call I watched they had gave the person running the scam had a laptop from about 10 years ago with 4GB of RAM and a very low spec processor. In other words cheap and easy to get. Low monetary risk with high monetary reward.
The core issue is the system allows spoofing and poor verification of who is getting blocks of numbers. Also low enforcement of laws in originating countries. The laws actually force the telcos to sort of do this too. As they in many cases must route. But the reality is we have bad actors that we do not want to route. But that same tool to not route could be used for reasons like what many tech companies currently use to get rid of people they do not like for whatever reason.
That's absolutely bonkers. "Corporate greed" is a fuzzy, unprovable, politically-charged and highly unlikely to actually be true catchphrase that means nothing. The fault lies with the US government - there's nothing that prevents it from acting in the interests of their representatives and implementing anti-spam laws, like you did in Germany. There's no difference between German companies and US companies that somehow makes one "greedier" than the other, either. This comment is a nothingburger that, quite honestly, does not belong on HN.
If regulation had been sane from the beginning maybe this discussion wouldn't be necessary (I can't imagine robocalls are legal in many other places? I haven't gotten one in my entire life).
And long distance rates were horrible, and there were none of these independents.
Back then, there wasn't a reason, because such call devices cost hard cash per call. And it's really only gotten super bad the last decade.
Because money. Duh.
a) Unless it's a core part of what differentiates party A from party B, voters won't pay that much attention (compared to other issues), so parties can have the same (lack of) policy that favors the companies, to keep those donations flowing.
b) If the parties all have the same policy, there's no-one the voters can vote for to work in their interests on that issue, so they'll vote for whoever they were going to vote for anyway on the other issues.
Only with IP calling is calling from country to country cheap enough that robocalls can be worth doing.
10DLC = 10-digit longcodes; in the US (well, NANP), "regular" phone numbers are 10 digits long. This is as opposed to shortcodes, which are usually 5- or 6-digit numbers (though there are some that are shorter) that are sold to specific customers after an approval process where all US mobile carriers have to sign off on their use cases. If you spam, you get your shortcode revoked. They generally cost on the order of $1000+ per month, while you can usually get a longcode for $1/mon or less.
Over the past few years the US telcos have (due to regulatory action, not of their own choice) started requiring that anyone using 10DLCs for A2P use cases need to register: who they are, how responsible parties can be contacted, and what they plan to use the numbers for. Don't do this and your messages will likely be silently dropped.
More discussion: https://news.ycombinator.com/item?id=39220462
Then there's multiple use. There's no/minimal difference between a script doing automated support callbacks and spam calls. You take a list of numbers, dial and connect the other end, handle hangups, do some reporting on connection success/failure. The completely isolated "other end" is either a person or an automated message or a combination of both.
There's really no reason to deal with any code here specifically, rather than just making the result illegal and enforcing that.
Where have they been all this time that regular spam calls have been a thing lmao
Conceptually (meaning, all details are not covered here):
- The caller/message-sender pays a per-call fee
- For example, $1.00 flat fee
- If the caller is in your address book, the charge is $0
- If you call them back, the charge is $0
- If you approve the caller, the charge is $0
- The person receiving the call earns a portion of the fee (30% ?)
- Etc.
If implemented correctly, on average, no legitimate caller pays this extra per-call or per-message fee. Machine learning could be used to augment effectiveness and reduce or eliminate fees when two people or entities know each other.For example, a company receives tons of customer service calls. Most callers might be unknown to the company (think Amazon customer service). There has to be a mechanism through which callers don't get stuck with a $1 fee just for calling to get support. This is where a detailed design of this type of a solution would be necessary.
What this does do, I think, is create a situation where it would (should) cost spammers millions of dollars to reach millions of people with unwanted calls or messages.
Another element of this is that consumers would make money from these stupid calls or texts. They should. If someone wants to consume somebody else's time, they should pay for it.
Which brings-up another twist to this idea:
Maybe people should be able to set a rate for unsolicited calls or messages. I could, for example, set my rate to $10 per minute and a 15 minute minimum. If you call me and I don't know you, the cost to talk to me or leave a message is a minimum of $150. If I call you back, the charge is negated. I can also tell the system not to charge you. Etc.
Upon making a call, the caller hears:
"This number charges a $150 for anonymous calls. Press 1 to accept."
If it is a message, they receive a reply: "This number charges a $150 for anonymous messages. Reply YES to accept."
The receiver gets a pop-up that might say: "Unknown caller: <insert name or number>."
"Accept and charge $150 fee"
"Accept and charge $0"
"Cancel"
Details would have to be worked out, of course. There are lots of ways to implement something like this such that legitimate callers are not charged any fees. Legislation and a technical infrastructure would be required to drive such a system.The reason this nonsense persists is because the cost is low and potential return on investment is high. If that equation is flipped, the nonsense stops.