9 ms·
I worked on countering phone scams and robocalls at the Federal Communications Commission for over a year. This operation was a big win and an impressive intern
by jonathanmayer 8y ago
I worked on countering phone scams and robocalls at the Federal Communications Commission for over a year. This operation was a big win and an impressive international collaboration.
That said, the robocall problem is getting worse, not better. Robocall volume is at an all-time high: https://robocallindex.com/ https://robocallindex.com/
In many respects, the problem of telephone spam today is similar to the problem of email spam in the early 2000s. Litigating against spammers had limited efficacy, so the community developed blacklists, better filtering, and stronger authentication (SPF, DKIM, and DMARC).
Until the major carriers get serious about similar steps, especially filtering and authentication (i.e. SHAKEN and STIR), these fraudulent calls won't stop. And, in the interim, vulnerable populations will continue to be disproportionately victimized.
- sureaboutthis 8y agoHow about the FCC get serious about the problem and force the telcos to stop it. Obviously, as you say, they have no interest in doing it themselves.
- viraptor 8y agoPretty much this. With the current tech stack in telcos, the only way anything can change is if they're put in a "you're responsible for this call, unless you can point to who sent this call" situation. While the receiving / forwarding party can't validate the originating number, they can always point at the telco that sent the call in. Repeat until you find a company / person to fine.
- supertrope 8y agoJust like airlines get fined for carrying passengers who violate immigration policy. Thus they are effectively deputized to enforce the rules. That would root out domestic telcos who enable bad behavior. What happens when the origin telco is in another jurisdiction?
- viraptor 8y agoIt costs a lot more internationally, so I'm not sure how much of a problem it really is. While many people would hate this, the same rule could be applied with "if you're forwarding international connections, you're responsible". Bad interconnects would probably drop immediately with a moderate amount of chaos, while legit foreign partners are found who can filter traffic on their end.
- supertrope 8y agoMy service provider offers <$0.01/min. calls to many countries. I have a hunch that no telco wants to entirely block a foreign telco because they would lose money and because of the ensuing chaos. Robocall friendly service providers intentionally mix robocalls with legitimate traffic to avoid terms of service enforcement. e.g. Robocalls are laundered by splitting across n carriers so spam (identified by bad ASR/ACD stats) stays below each carrier's threshold. https://news.ycombinator.com/item?id=12339739 https://news.ycombinator.com/item?id=12339739
- bluGill 8y agoThen it has an international caller id. Most people get so few international calls that they will quickly figure out that it can't be real. If it had a locale caller id it is obviously spoofed because otherwise the call wouldn't have come in from the foreign telco. Once someone does this, legitimate telephone companies elsewhere will become interested as well, and may "play nice" so long as local laws allow it.
- viraptor 8y ago> If it had a locale caller id it is obviously spoofed because otherwise the call wouldn't have come in from the foreign telco. That is not correct. You can send legitimate calls with spoofed caller id between different countries. Many providers will let you do that. (as in, you can assign a caller id from country A to a call originating from country B to A)
- 8y ago
- majos 8y agoWhat's keeping major carriers from getting serious about these steps already?
- imron 8y agoThey indirectly make money from the fraud, so incentives are not aligned for them to stop it.
- supertrope 8y agoAnd there are insufficient dis-incentives. There are no competitors who offer a superior spam filtering solution and market it. If carriers became financially liable for robocalls by a government mandated date, e.g. 2020, they would find a solution. Even if was as simple as not getting paid to carry spam traffic (as opposed to an EU level % of global revenue fine).
- SOLAR_FIELDS 8y agoAnother trivial solution would be to offer some sort of voice CAPTCHA for phones - get asked question and provide answer in order to connect. Someone on here posted awhile back that they implemented their own and said it completely eliminated robocalls.
- walrus01 8y agoI have done this. I have my own VoIP system. One of my DIDs picks up and is a recording of me saying "I'm screening my calls for telemarketers and scams. enter code 5300 any time to be connected to $myname". If 5300 is entered, it dials out to the DID for my cellphone and transfers the call. No code, or no action, call goes nowhere. You can fairly easily make the code whatever you want or make it a multi step process.
- SOLAR_FIELDS 8y agoIf I remember correctly from the conversation I mentioned above: this is only implementable yourself with a VOIP solution and not an actual phone line?
- duxup 8y agoMy wife gets a call every day about how she is being sued..... every day a new nasty VM. I'm talking to random scammers more now because I'm looking for a job and I feel like I have to answer the phone even if I don't recognize the number. Man it is annoying.
- voodooranger 8y agoThe workaround I used for this was Google Voice. I put the Google Voice number on my resume and in settings told it to use my own GV number as the caller id. If I saw a call coming from the GV number I knew it was a response to my resume. For some reason my GV number doesn’t attract scammers.
- nasredin 8y agoPro tip for you: you can "port" out your number to your cellular provider. Zero spam for me for a long time. Yes, zero! Also see the T Mobile spam service. There's two you have to turn on IIRC. YouMail for voicemail is good too.
- duxup 8y agoThank you!
- Sangermaine 8y agoI have a GV number as my work number on my cards, site, etc. and I still get spam through it, though admittedly less than through my personal number.
- duxup 8y agoThat is a great tip, thanks!
- Waterluvian 8y agoSo what am I doing that I've never once had a telemarketer call me, other than my car dealership or phone company. Canada can't be special. Is it because I use a cell phone for everything?
- Scoundreller 8y agoCanadian here. The CRA has called me about their criminal warrants for my arrest many times. The Chinese consulate keeps telling me to call them back. But these are all on my work-phone and government agencies don't pay taxes anyway. My personal phone has been relatively safe for unknown reasons that I'm happy about.
- joecool1029 8y agoNot canadian but used to travel there a lot and had a nice collection of prepaid sim cards. Every new prepaid line I registered got tons of calls from debt collectors, to telemarketers, to scammers. So yeah it happens, though probably less blindly than US and more from information sharing.
- peterlk 8y agoDoes Google voice work for Canadian numbers?
- joecool1029 8y agoI don’t believe you can register a canadian number. You can sign up and use it as a voicemail though I think. If you are asking whether you can call and be called by canadians for free from american gvoice, the answer to that is yes.
- iamshs 8y agoNumerous calls here. Lately SMSes have started too. Sometime back, even WhatsApp messages from Philippines, but that spam stopped pretty quickly.
- walrus01 8y agoThe problem with fixing this is that, to extend your analogy, SS7 is like how SMTP worked in 1992 before anything like spf, dkim, dmarc, SSL/TLS. Adding extensions to it will break interoperability with the truly gargantuan installed base of old ss7 equipment around the world that nobody wants to pay to replace. It needs to be burnt to the ground and started over from first principles. But really, everything that we need can be implemented with pure VoIP. I just don't answer my phone anymore unless I recognize the incoming number. And caller ID is trivially easy to spoof. Thankfully nobody spoofs any of the numbers of my top 50 contacts.
- utefan001 8y agoI don't know enough about SS7 to understand if this is feasible, but it is clearly time for a call back based system. Millions of people signed up for the do not call registry. I am sure millions would sign up for a system where incoming calls trigger a call back. If your out bound call system doesn't support call back, don't worry because nobody wants to talk to anyone hiding behind the cloak of invisibility.
- walrus01 8y agoBuilding a callback system doesn't fix ss7 and is a bandaid slapped on top.
- Fjolsvith 8y agoLast year, a spammer spoofed with my business phone number as their caller ID. Mid-day, I start getting phone calls from people yelling at me to stop calling them, stop harassing them. Every 2-3 minutes, someone new and angry. After about 3 hours I had figured out what had happened and got ahold of my carrier and had them change my phone number.
- anonymous5133 8y agoI think the problem has gotten so serious that the traditional voice-based phone system is pretty much unusable. I don't even bother to answer the phone. Instead I have a voice mail message that tells people to send a text message instead. I can't be the only one who does something like this or has some other system in place to not have to deal with robocalls/scam callers.
- r00fus 8y agoNot sure what carrier you're using but T-Mobile in the US just released "scam block" ( I had "scam ID" turned on previously). In addition to marking calls as scam, now they simply block them outright. Getting approximately 0 scam calls in the past 2 days.
- chiefalchemist 8y agoI believe Google recently released something similar for Android. These calls are spam for phones. Certainly, there's an obvious pattern that can be identified and then neutralized.
- supertrope 8y agoEmail spam became tractable on the end user side with domain and IP address risk scoring. Caller IDs are so easily spoofable it's like open relay email servers of the past.
- chiefalchemist 8y agoWhen they spoof are they using otherwise valid numbers? That is, if you returned the call you'd speak to someone's grandmother? None the less, can't the phone providers detect the excessive outgoing traffic? And if it's a residential number can't that raise a red flag?
- daveFNbuck 8y agoDo you have a link for that? I have an Android phone, but I received a call marked as spam yesterday. I'd love to be able to just block those.
- raarts 8y agoSince you have expertise, maybe you can explain why this seems to happen in the US only, while SS7 (which many commenters mention as the culprit) is used all over the world. I live in Europe, but do not receive robocalls at all (zero), while when I enter the US, and put in my US SIM, I immediately start getting multiple per day.
- tpxl 8y agoAfaik they are mostly illegal, at least where I live.
- thunfischbrot 8y agoYou mean that they do not happen in the EU as they are illegal there? They are illegal in the US as well.
- tremon 8y agoThe EU regulators still have teeth.
- soundwave106 8y agoAlthough no law will prevents all scams, some European governments do have much stricter laws on when you can "cold call" period. In Germany, for instance, thanks to legislation passed a decade ago, I believe the customer needs to grant explicit permission in order for a business to be able to cold call, and no telemarketer can impersonate your phone number -- https://www.thelocal.de/20090804/21021 https://www.thelocal.de/20090804/21021. It would be interesting to see if there is a correlation with these sorts of laws, and the prevalence of phone scams.
- dragonwriter 8y agoThey are illegal in the US and often originate abroad, anyway, so legality under the law of the target country (or the source country, as most are illegal where they originate, too) doesn't seem to be a controlling factor.
- 8y ago
- cascom 8y agoDid you all have a sense for the scope of the problem in terms of number participants and market share? Is the bulk of the calls from a few larger networks, or is the bulk of the market one man shows?
- jimmydddd 8y ago@jonathanmayer Any idea why the landline companies don't address this issue? Do they make money from spam calls? I signed up for the Nomo Robo service, that I believe won an FCC sponsored contest to provide a partial solution. And I think the landline providers actively faught against its use.
- deelowe 8y agoI imagine a significant number of POTS lines are used by robocall/scammer operations, if not directly through third party VOIP services. Make not qualms about it, ATT still treats POTS as it's bread and butter. They will do whatever it takes to keep that cashflow coming in.
- toss1 8y agoThis is getting way out of hand, and I don’t know anybody who hasn’t the same observation, and has already changed their behaviour to NOT answer the phone by default. If the major carriers don't soon understand the magnitude of the telephone spam/scam problem and treat it seriously, They will soon be crippling their business. While this is been likened here to the email spam problem in 2000, back then, everyone in the computer industry took the spam problem much more seriously telephone industry does now. E.,g., Verizon gleefully offers a blacklist where you can block 20 numbers (nevermind that the spam calls typically have spoofed caller IDs) -- they think they’re good, and it’s utterly useless. They really need to implement a true Source ID (regardless of the presented caller ID), and a way to instantly flag calls as spam then do targeted tracking and prosecution. If they fail to do this or implement another effective solution, I expect they will lose a century-old line of business to new habits that work around the established habits.