4 ms·
Getting STIR & SHAKEN implemented so we have proper trust of the caller ID is going to be a massive undertaking for the industry as a whole. T-Mobile and Verizo
by StudentStuff 8y ago
Getting STIR & SHAKEN implemented so we have proper trust of the caller ID is going to be a massive undertaking for the industry as a whole. T-Mobile and Verizon have implemented it in limited forms internally, but they have no interest in making their implementations interoperate, let alone work with the other RBOCs, CLECs and their resellers (Twilio in this case).
STIR/SHAKEN also can break call forwarding, as a forwarded call may get stripped of the forwarded from header by an intermediary carrier, resulting in an unvalidated caller ID getting passed, causing the call to not ring the destination.
Overall, the telcom industry is stuck in the past, with security being a joke. TLS Registration & SRTP are rarely used, most carriers sling calls bare over the internet hoping for the best.
- CharlesColeman 8y ago> T-Mobile and Verizon have implemented it in limited forms internally, but they have no interest in making their implementations interoperate, let alone work with the other RBOCs, CLECs and their resellers (Twilio in this case). Why would that be? I know nothing of STIR & SHAKEN, but if it's meant to reduce spam, I would think all legitimate operators would want it to work in an interoperable way.
- jjoonathan 8y agoWhy would you think that?
- CharlesColeman 8y agoBecause individually they'll do a worse job of mitigating spam than if they try to mitigate it collectively.
- lotsofpulp 8y agoThey’ll collaborate, as soon as they figure out how to charge for spam filtering.
- mwfunk 8y agoThis is almost certainly true, but they might make more money if (for example) one carrier's half-assed spam mitigation technology is shown to work better than a competing carrier's quarter-assed spam mitigation technology. From the perspective of some analysts, collaborating with competitors over a technology that might otherwise be used as a competitive advantage is leaving money on the table, even if the end result is a worse situation for everyone. And from an analyst's perspective, shareholders are the company's customers, not the people who use their services. Which has a certain logic to it, but we'll see if these companies care more about their customers or their shareholders.
- w0de0 8y agoClear example of the prisoner's dilemma.
- sokoloff 8y agoDoesn't reducing spam phone calls directly hurt their bottom line?
- pfranz 8y agoDepends if they're thinking short term or long term. I think I've seen numbers showing phone calls are dropping already. Increasing spam will exacerbate that.
- AnimalMuppet 8y agoSo let's say that I've got a network that can carry calls. I rent access by the month. The fewer calls, the less infrastructure I need to be able to handle them, but the rent doesn't change. Why would I want spam calls on my network? Unless they're paying me by the call or something, that's the last thing I want.
- deleted 8y ago[deleted]
- sokoloff 8y agoSIP calls are generally billed by the minute by the carrier. Mobile calls also often have a per-minute charge by the network. That those are often sold as “all you can talk” packages is a consumer marketing bundling action, not necessarily perfectly reflective of the underlying economics.
- hermitdev 8y agoProbably not. Most charges are done per minute of talk time. An unanswered phone call would not generate a charge. If people are unwilling to answer the phone due to a high spam volume (such as myself), they're likely losing money from the spam. I only answer the phone from known numbers or if I'm immediately expecting a call. Everything else goes to voicemail. Carriera have an incentive to increase call acceptance, and that means cut down on the bullshit robocalls that are already illegal to cellphones, but rarely enforced.
- 8y ago
- kyrra 8y agoThe FCC has a page tracking the response by the major carriers[0]. Also, from what the FCC chair is saying, while nothing is forcing the carriers to play nicely, he is basically warning them if they don't work together to create/implement a spec to help with the problem, the FCC will force something (that probably won't be as easy to deal with). WSJ had a podcast interviewing him recently about it[1]. [0] https://www.fcc.gov/call-authentication https://www.fcc.gov/call-authentication [1] (interview starts 23 minutes in) http://www.wsj.com/podcasts/instant-message/20-tesla-got-a-brand-new-car/6603B252-8C58-4CAF-A7A0-25FEE391B3EC http://www.wsj.com/podcasts/instant-message/20-tesla-got-a-b...
- floatrock 8y ago> the FCC will force something (that probably won't be as easy to deal with) After the net neutrality debacle, including the FBI investigation into public comment fraud [0], I'm writing off whatever "corporate difficulty" Ajit Pai is threatening as a snowball's chance in hell. As long as he's chair, that agency is squarely in the "regulatory capture" box. [0] https://arstechnica.com/tech-policy/2018/12/fbi-investigating-identity-theft-in-net-neutrality-comments-report-says/ https://arstechnica.com/tech-policy/2018/12/fbi-investigatin...
- jpalomaki 8y agoIf the operators don’t act, maybe the traditional phone calls become obsolete and people switch to Facetime/WhatsApp/GoogleTechDuJour.
- bigiain 8y agoSome people might say this has already happened. For me, it's very very rare for an incoming voice call to be a friend - 99.9% of them are from businesses, and I prioritise them accordingly. I sometimes realise my phone is on silent, and think "Oh yeah, I was out to dinner or at the movies 3 or 4 days ago, and didn't remember to turn the ringer back on..."
- aero142 8y agoDoes my phone know if the caller ID is STIR/SHAKEN certified? I can already send numbers that are not in my caller ID to my voicemail directly. I would love to be able to do this for the unverified callerId numbers. Maybe if enough people did it, the phone companies would have to add it to prevent their calls from hitting the trash bin.
- kevin_thibedeau 8y agoGoogle should shame the carriers by putting a red padlock next to unverified numbers.