6 ms·
> because there's no good reason that these robocalls can't be treated like a DoS attack The problem here is that the origin can be spoofed. You are imagining
by codexon 7y ago
> because there's no good reason that these robocalls can't be treated like a DoS attack
The problem here is that the origin can be spoofed.
You are imagining a system where a telco like T-Mobile connects the caller directly to you. That's not how it works. The connection chain could look like this.
bad caller 111-1111 -> A -> B -> C -> T-Mobile -> you 999-9999
All T-Mobile knows is that 111-1111 is calling 999-9999 and that the call was routed from C, it does not know about A, B, or the true identity of the bad caller.
That's also why spoofed attacks are also a problem on the Internet. These systems were not made with spoofing in mind, and it will cost a lot of money to get these companies to switch over to a new system seamlessly that can detect spoofing.
- gowld 7y agoHow much is "a lot", though? We already have $billions sloshing around in telecom.
- codexon 7y agoI don't know but I would imagine it would be as annoying as getting everyone to switch from ipv4 to ipv6 in 1 or 2 years.
- Scoundreller 7y agoSo then T-Mob calls the NOC at C. Tells them to get this stopped and they have 24 hours, or they'll depeer. 6 hour later, C's NOC calls B's NOC, saying to knock it off, and they have 18 hours or they're getting booted. 6 hours later, B's NOC calls A's NOC, saying to knock it off, and they have 12 hours to figure it out or they're getting booted. In under 12 more hours, A cuts off 111-1111. If peeringDB is to be believed, big providers all require their peers to have a 24/7 NOC number to call.
- EB66 7y agoI agree completely. I work for a small ISP and we sometimes do the same thing for significant bad actors abusing our network. A phone call to the NOC of the ISP hosting the abuser or the NOC of their upstream transit providers usually gets the ball rolling pretty quickly. That approach is obviously not very effective in a DDoS scenario, but as I understand it these robocalls typically originate from a handful of different VoIP termination services -- as opposed to tens of thousands of hosts in a DDoS scenario.
- Scoundreller 7y agoExactly. Creating a proactive system might be difficult, but the apparatus is all there for being reactive. Yet this has been going on for years, so I suspect shenanigans by providers too happy to continue charging their Tier7 peers for access.
- wpskidd 7y agoI think this a great challenge to propose to the HN crowd. Who wouldn’t pay for a system that truly eliminates the annoyance of spam calls? What about a private network that people could subscribe to that uses a decentralized social credit system? Or one that uses a monitoring gateway to track the number of calls originating from a number (either internal or external to the subscriber group), and treats mass callers with extreme prejudice. A blacklist of known spammers could be applied first as a default (rather than as an add-on app). If you wanted to get really creative, you could give subscribers the tools to add numbers to their own black list far more easily than they now can, and maybe even block whole geographic regions.
- dao- 7y ago> Who wouldn’t pay for a system that truly eliminates the annoyance of spam calls? Anyone in a region with sensible legislation.
- closeparen 7y agoHow does T-Mobile know there's a problem worth calling the C NOC about? One way is to see the frequency and duration of calls. Lots of very short calls indicate spammy behavior. So if you are B, you offer SIP trunking at below cost to legitimate customers, so that you can mix their call flow with the much more lucrative, 100% robocall traffic from A, and thereby stay on favorable terms with C. I worked in this business briefly, the economics are fascinating. Your average mom and pop restaurant is very likely buying its VoIP transit from an entity like "B" in this story.
- EB66 7y ago> How does T-Mobile know there's a problem worth calling the C NOC about? One way is to see the frequency and duration of calls. Or make it easier for consumers to report spam calls. For example, dial *666 after hanging up on the spammer and it reports the last call as spam. Enough abuse reports originating from a particular carrier and T-Mobile knows there's a problem. That's basically how it works for email spam and other forms of Internet abuse.
- foobarian 7y agoI would pay to have a "AT&T Certified" icon on incoming phone calls. Maybe the carriers can set up peering agreements and both AT&T and Verizon work. The vast majority of people I care about are on those carriers and I can forget about the rest. It's very hard to reform the whole system, but you have to start somewhere and this could be how.
- captncraig 7y agoThat is a really great idea. Every time this comes up it boils down to "phones are old and complicated, and there are a billion unique telcos". Great. But if I only do legit business over 3 of them, why not indicate if I am leaving the "trusted zone"?
- joecool1029 7y ago> I would pay to have a "AT&T Certified" icon on incoming phone calls. Call verification is already here and rolling out progressively. System is called STIR/SHAKEN. iOS supports it as of 13.something. The UX is terrible though, all you see is a checkmark after the caller in the call log. Android might have a better situation on some phones, this system is carrier dependent. More about it here: https://www.fcc.gov/call-authentication https://www.fcc.gov/call-authentication There are scenarios where it doesn't work. Calls routed through Google Voice to my T-Mobile line will never show this checkmark. Also, not showing it onscreen for unknown incoming calls defeats the purpose, really not sure what Apple was thinking.
- nathancahill 7y agoI wonder if Twilio will support that. I route my GV to Twilio and then to T-Mobile to run custom logic on incoming phone calls (like filtering out all incoming calls that match the first 6 numbers of my number). Would be nice to passthrough verification.
- harumph 7y agoI am already paying my carrier entirely too much. Paying them more to do something they ought to do by default is not something I would consider. We should use law to eliminate this problem.
- Aloha 7y agoHow do you determine what 111-1111 is? CID? ANI? Some other means?
- sytelus 7y agoIf T-Mobile doesn't know who is really the originator, how the cost of call gets attributed? Wouldn't this mean I can just use their network without paying them as no one know how to identify me?