4 ms·
At the risk of sounding like I'm actually going to abuse this capability... if it's done "relatively easily", how is this done?
by wfunction 10y ago
At the risk of sounding like I'm actually going to abuse this capability... if it's done "relatively easily", how is this done?
- lucaspiller 10y agoI switched to a different SIP provider as they were cheaper, but my number was still held at the old SIP provider and couldn't be ported. I explained the story and asked if they could 'virtually' add that number to my account so outgoing calls would come from that number. They just switched on the feature to enable me to set the caller id to anything as it was easier for them.
- MichaelGG 10y agoThis is also a fun attack. Find a provider that does this. Request to port a target number (a bank or an escort service or whatever). Port will stall for a bit, in the mean time, the service provider activates your number internally, so their own dialers route to their "version" of the number. Now you get all the calls from that provider to that number. Forward them to the actual destination (using an unrelated provider) and no one will notice for a while. Except, you get all the calls and media.
- nmjohn 10y agoBasically, because there is no verification/validation surrounding caller id - https://en.wikipedia.org/wiki/Caller_ID_spoofing https://en.wikipedia.org/wiki/Caller_ID_spoofing
- cantrevealname 10y agoWhat's known as "caller ID" is just an add-on that phone companies glued onto the system to have a feature to sell to the public. Another such feature is ANI[1] which was originally meant for billing purposes but is a feature sold with toll-free (800) numbers. It is much harder to spoof, but even ANI is not guaranteed to be present. I would really love to hear a telecom engineer explain why the true origin info isn't accessible to the called person. A telephone call is a two-way connection -- the path in both directions must be known otherwise you won't have a two-way conversation. A telephone call is not email or an old-fashioned letter. Both of those are one-way communications, so if the intermediaries don't carefully track the email or letter as it progresses through the pipeline, you have spoofed email or untraceable letters. But at the lowest level of the telephony protocol, the true and correct path to the originating caller has to exist. Otherwise your voice won't travel to the other person. I'm curious to know why that really deep reverse route has never been made available to public (as an API or a purchasable feature or in any other form). [1] https://en.wikipedia.org/wiki/Automatic_number_identification https://en.wikipedia.org/wiki/Automatic_number_identificatio...
- MichaelGG 10y agoOutbound traffic (placing a call) is entirely separate from the inbound path. This is similar, in a way, to IP. You can send a packet with any source IP from basically anywhere on the Internet. The difference is that with IP, any return packets are routed separately, to the source IP. With a call, return voice just goes along the established channel. Each provider along the way will know who they received the call from, but cannot verify that the number belongs to them. This is by design and used in many cases. Call forwarding, for instance. Or even just the basic case of using multiple providers to route outbound calls. Some might be cheaper than others, so you need to select on a call by call basis. Also, think of international calls. How is Idaho Telco XYZ supposed to be able to verify that this call from Zambia really belongs to ZambiaCom XYZ? And vice versa. Also note that there's simply no requirement to even having a number. You could just be placing outbound calls (like SkypeOut). Or no one to one mapping: an office sharing one number for outbound calls, or a single telemarketer changing numbers call by call as they dial for different customers.
- amjd 10y agoMost VoIP providers let you use any number as the caller ID with a simple SMS verification. So, if you were to have access to someone's phone for a few minutes you could possibly verify it and use the number for making calls and sending text messages from the VoIP service. I believe the SMS verification is something that companies use to avoid liability alone, technically they can use any number as the caller ID if they choose to.
- Buge 10y agoSome friends and I used to make prank calls with fake funny caller IDs using https://www.spoofcard.com/ https://www.spoofcard.com/
- finnn 10y agoMy SIP provider passes whatever number I send, for most of the numbers. No talking to them required. Particularly fun for Android phones that do Google Maps lookups for caller ID, so calling from 2024561414 shows up as "The White House" Just for fun i went ahead and verified 2024561414 with the demo of this thing. It gave me a nice little check mark showing that I was definitely the White House
- wfunction 10y agoSorry, what's an SIP provider? I've looked it up and still don't understand what it is. Is it a residential service? Can anyone get it? Is it some form of VoIP? Or a classical phone line? I've seen it in multiple places but don't understand what it is or which companies it relates to.
- HappyTypist 10y agoTwilio, Plivo, etc.
- taf2 10y agoThey are higher level then telco and prevent spoofing
- Symbiote 10y agoIt's the open standard for VoIP. It's used in many places, but mostly offices. An office might have an exchange system, with features like voicemail and routing different types of call over different networks. I have a personal account which gives cheap international calls, which I added to my android phone. I can receive calls at my SIP address, from anyone on any provider. When I make a call, I'm given the option of using the mobile network directly, or SIP. Naturally, neither the phone networks not the big tech companies want you to use SIP. They'd rather you used normal calls, or their proprietary system.
- StavrosK 10y agoCan you recommend one that works well? I want one that hopefully provides a Greek DID, I want to be able to make calls from my Android to landlines over my home Internet connection, as you describe, but I haven't managed to find a good (read: cheapish) provider.