9 ms·
Understanding STIR/SHAKEN – New Anti-Robocalling Protocol
- Latteland 8y agoSounds like a nice improvement. It appears to be a web of trust scenario, where you trust anyone else who is verified. Eventually I'm sure some spammer will break through into the circle. I hope that if there is some spammer penetration (so much money here it's inevitable) every phone company should be able to track back where that last phone call came from and block them then.
- tyingq 8y ago"so much money here" I kinda wonder about that. Both the "semi legit" and "full on spam" calls I get just aren't credible. It's hard to imagine anyone falling for it. Or, I'll press "1" to hear their BS pitch, and go on hold forever. It's so cheap to do, that I suspect there's an endless queue of people trying to make money, but failing. But "failing" costs them almost nothing. So, maybe raising the cost of doing it will kill off the amateurs.
- Qworg 8y agoIf it follows spam, they'll just professionalize and focus on the most technically inept.
- bobbiechen 8y agoIt may be intentionally unbelievable - see the Microsoft Research paper about "Nigerian prince" email scams: By sending an email that repels all but the most gullible the scammer gets the most promising marks to self-select, and tilts the true to false positive ratio in his favor. https://www.microsoft.com/en-us/research/publication/why-do-nigerian-scammers-say-they-are-from-nigeria/ https://www.microsoft.com/en-us/research/publication/why-do-...
- tyingq 8y agoSure, but that approach requires a low cost per call/email. Things that raise the effective cost will make that approach less attractive.
- nerdbaggy 8y agoAnybody know who the CA is now for these? Couldn’t find much
- ocdtrekkie 8y agoSince I saw the URL https://certificates.clearip.com https://certificates.clearip.com in the link, went to that URL and it offers a ClearIP root certificate. ClearIP being a product from the company who wrote this blog. I wouldn't be entirely surprised if the carriers themselves were acting as the root CA for their given calls. There's no reason to tie it to the CAs on the Internet.
- th0ma5 8y agoAlways want to fill out the old https://craphound.com/spamsolutions.txt https://craphound.com/spamsolutions.txt form with these ideas. Like the open world / closed world AI problem.
- roel_v 8y agoIt's been 20 years and it doesn't stop being funny. I'm afraid I'm a 12 year old boy in the body of a 40 year old :(
- ComputerGuru 8y agoIt's still spot-on today, except perhaps s/Microsoft/Google/g (fully-encrypted Gmail comes to mind).
- raverbashing 8y agoBut then again, email spam has been solved for the most part That list is kinda defeatist and misses the fact that no solution needs to work 100% of the time
- tinus_hn 8y agoWe have paid for that in features though. You can’t really use your home connection as a mail server anymore, for instance.
- bkor 8y ago> But then again, email spam has been solved for the most part Only if you use one of the big email providers or if you pay to route it via some antispam system. If you don't and play around with e.g. Postfix and spamassassin then you'll notice more than enough spam.
- pwg 8y agoIf you use Postfix and CRM114 (http://crm114.sourceforge.net/ http://crm114.sourceforge.net/) you can achieve equivalent or better spam filtering than the "big email providers". I get maybe 1 spam every six months that leaks through. I simply add it to the crm114 filter as "this should be spam" and then no spam again for another six months or so.
- MagicPropmaker 8y agoA little trick that will work for "geeks" but won't scale is: - My personal phone number is in a remote area code, of a sparsely populated state, from where I don't know anybody. - Any phone calls that come from this area code are blocked (well, actually, they have a silent ring tone.) This gets rid of about 90% of the spam/robocalls because these days, 90% of them spoof a local areacode/exchange. Of course, if everyone did this, they'd stop doing it. But it works for now and makes my personal cell phone useful. I did have to do some finagling to get my carrier (T-Mobile) to give me a phone with an area-code of a different state. I don't have a lot of faith that STIR/SHAKEN will help in any real way. They'll just have to rent numbers from people who don't care about the law, and/or registered with bogus information so it won't be worth anyone's while to find them.
- cstejerean 8y agoHow did you set the ring tone for this entire prefix? I’ve been looking for some easy way to do this on iOS, I also have a phone number from an area code + prefix where I don’t know anyone and all calls from there are spam.
- MagicPropmaker 8y agoYou can do it on Android with "tasker"
- Moru 8y agoYou can block with wildcard in some android phones.
- beta_max 8y agoHow do you get a number for a specific area code?
- wahern 8y agoI've noticed in the past year or two that spammers have begun using area codes from the handful of friends & family I receive the most calls from, and not just my own area code. It stands out because at least a couple of those area codes aren't from major metropolitan areas. I don't use social media like Facebook or Twitter, but most likely an app on my phone or others' phones sold my contact info. I try to avoid installing third-party apps. Since I began using smart phones, I could count the number on two hands. But it only takes one bad app, and there are plenty out there. I don't doubt telco call logs are available on the black market, but apps are the simplest and most likely vector. I'm rather skeptical of going after Google and other big tech companies for anti-trust violations. The web is a big place. But it's much easier to distinguish Google's control of Android and the Android app market, both from a technical and legal perspective. And Google has deliberately made it difficult to limit app data access. I remember the brief period where Android by default provided a prompt of requested permissions and the ability to uncheck them before installing. They removed it because few people made use of it, few apps worked correctly without all their requested permissions, and most importantly Google was no longer worried about privacy concerns hindering Android adoption. But with the current attention being given to data privacy I believe the public is finally prepared to make effective use of such a capability. But now Google has even less incentive to provide such a simple and transparent opt-out prompt, so fat chance they'll bring it back without being legally forced. Tripe fat chance they'll make any of those permissions opt-in.
- m0zg 8y agoI do the following: I never give my real phone number to anybody other than people I directly know. Everybody else gets my Google Voice number, which is set up to directly go into voicemail without ever ringing. As far as I can tell, I receive 2-3 robocalls a day, so GV just blackholes them for me. Every now and then someone leaves a voicemail, and I read that, but it's very rare that a robocall leaves a voicemail because Google call screener requires them to enter a number to do so.
- Animats 8y agoThis clearly wasn't designed by telephony people. It's very web-like. The authentication info is bigger than the call data required to set up a call. Mostly this is for VOIP. Telcos with TDM or CDMA transmission have serious backwards compatibility problems. Ones who peer only with SS7 have problems but those can probably be overcome. One big problem is that there are off-brand telcos who specialize in services for call centers. "The Dialer Hardware is being hosted in our premises at Los Angeles - USA, where we have our own switch and termination facility with over 100 Carriers. We also have a redundant switch in New York connected to LA through a fat Fibre pipe."[1] Do those guys get to sign calls? Or what? [1] http://www.callcentersindia.com/showall-orig.php?value1=11268_Worlds_No_1_Predictive_Dialer-Concerto_Ensemble_Pro_60_on_Monthly_Subscription_basis http://www.callcentersindia.com/showall-orig.php?value1=1126...
- anilakar 8y agoWell, VoLTE and VoWiFi (urgh, that makes my eyes and pinky hurt) are using SIP already... Does this apply to end-to-end SIP calls only?
- michaelt 8y agoDo those guys get to sign calls? Or what? One of the current problems is a ban on robocalls exists (for calls to cell phones without consent, at least), as does a ban on IRS scam calls, Microsoft scam calls etc, but the bans can't be enforced because when a victim complains there's no way to trace the guilty party. After all, the caller ID was faked. So the call signing doesn't have to be "a body that will block all robocalls and scams" it only has to be "a body that can be sued and fined". You rotate certificates weekly and issue a certificate to any company willing to make a deposit of $X against possible fines. Then adjust $X until robocalls and scam calls with fake caller IDs stop happening. Of course, even if that stopped robocalls/scam calls with faked caller ID, profitable scams and robocalls would be able to use burner cell phones. So it's not a perfect solution by any means.
- tpxl 8y ago>there's no way to trace the guilty party Surely the telco can trace who made the call?
- Barrin92 8y agoInstead of all these fancy technical counter-measures I think this really ought to be a matter of the law. Why not ban cold calls, like in Germany? Is there anyone on this planet who actually enjoys constant advertisement and harassment on their phone? >According to Sec. 7 (2) UWG; telephone calls to consumers for sales purposes are illegal if the calling company is not in possession of an explicit and effective declaration of consent by the consumer. If the call is made to another business, it is sufficient to prove presumptive consent.
- Zarel 8y agoThe worst phone spam is already illegal in the US. The problem is, in the current system, it's impossible to figure out who's doing it. That's one of the things STIR/SHAKEN is supposed to fix.
- 6nf 8y agoAt least some of the phone spam is for real businesses / services, those should be easy enough to stop?
- viraptor 8y ago> it's impossible to figure out who's doing it It's really not. Not for the operator / law enforcement anyway. 1. Ask operator where that call came from. 2. If it's another operator, go back to 1. 3. You got the end user. They already have to have accounting/audit for billing purposes anyway.
- stendinator 8y agoI'm from Switzerland and I only ever get spam calls from the US or India - how come?
- anilakar 8y agoMost telemarketing and scammer calls originate from UK, Norway and Sweden here. I used to ignore foreign numbers completely, but being on-call nowadays and having customers abroad prevents such easy countermeasures.
- oarsinsync 8y agoAmusingly, the last batch of spam calls I got to a UK number were coming through with caller ID from Switzerland or Italy
- patrickg_zill 8y agoI read through a summary from a different source and I was not impressed. Any voip phone, and of course smart phone, can be easily set up for client side certificates. Landlines and anything else that can be accessed via SS7 methods are already secure in terms of identity. And that's it. Client side certs and you are done...
- lemcoe9 8y agoSIP over TLS (which uses SRTP) is great, but as soon as it hits a vendor downstream that doesn't support it, it immediately gets trans-coded into plain-ole-SIP and is just as insecure as any other VoIP call. This is not a solution by any means, because it assumes that the entire call path is TLS-enabled, which, in my experience, is impossible on the public telephony network.
- patrickg_zill 8y agoWell I am referring to the use of client certificates for identity. You might not need to have SRTP in the middle of a big telecom network, like one that handles millions of calls per day, just at the edges where you interconnect with others.
- thosakwe 8y agoI’ve noticed two main things about the many robocalls/spamcalls I’ve received (my carrier actually has spam blocking, and I haven’t received very many since activating it) 1. Most calls I receive from numbers not in my contact list are spam. They also usually just call once, whereas if it’s a legit call that I was expecting, but neglected to pick up, they’ll call again within a few minutes. 2. I’ll get robocalls from one area code at a time. I remember getting calls from 772 one week, 727 the next, 643 a few days later, etc. Obviously it won’t crush spam entirely, but I can imagine that fixing even just these two things would filter out a boatload if spam from reaching consumers. Oh, and calls from “Scam Likely” should never reach my phone to begin with.
- ovi256 8y agoThe first rule would have a short half-life, spam systems would just learn to call again. The rolling area codes you observed are already an anti-banlist mechanism. Maybe a loose superposition of short half-life rules would work, like it works for email spam.
- alphabetter 8y agoSeveral people have asked about the management of certificates for this solution. There is indeed a seperate certificate management body created called the Secure Telephone Identity Governance Authority (https://sites.atis.org/insights/secure-telephone-identity-governance-authority-launched-in-major-industry-effort-to-combat-unwanted-robocalling/ https://sites.atis.org/insights/secure-telephone-identity-go...). The Governance Authority will define policies on how certificates are to be issued. Any old certificate from a web CA won't be accepted by the system.
- tialaramex 8y agoFor what it's worth, mostly private CAs are garbage. Bad at the crypto parts, bad at the identity problem, bad at their own security. Just pretty bad. It doesn't really matter, because mostly bad guys don't see the CA as the weak point, if anything what is remarkable about the Web PKI is that we did a good enough job elsewhere that actual bad guys sometimes try to attack the Web PKI. Not often, but it happens at all. It's like finding out you did a good enough job securing your home that an actual burglar picked your front door lock! Yes, the burglar still got in because of course no door look is effective against somebody who knows what they're doing and has plenty of time to try - but still, apparently you actually did a good enough job that they weren't able to just climb in through a side window or force open a patio door. Go you. If STIR/SHAKEN turns out to have the CA function as its weak point then everybody involved should clap themselves on the back for an extraordinarily good job.
- _underfl0w_ 8y agoHopefully this CA process will have a better threat model - that is, one in which they're prepared for state-level malicious actors such as DarkMatter.