4 ms·
The sad thing is if the clipper chip was ubiquitous today that could have killed the ability for spammers to spoof numbers. Some days I can get a dozen robo cal
by dosman33 5y ago
The sad thing is if the clipper chip was ubiquitous today that could have killed the ability for spammers to spoof numbers. Some days I can get a dozen robo calls, each with a different spoofed number. People that want non-backdoored crypto could still do so.
I'm still blown away at how hard it is to get people to use any encryption, even people who work in infosec/etc. If nothing else, 2020 was a great year for the uptick in using crypto to communicate with non-technical fam and friends.
- breput 5y agoRobo calls should be filtered at the network level. The Clipper Chip would have done nothing to prevent this. There is actually encryption technology[1] available that would solve this or at least make it traceable and blockable. But here we are. [1] https://en.wikipedia.org/wiki/STIR/SHAKEN https://en.wikipedia.org/wiki/STIR/SHAKEN Edit: Also the political situation at the time was that if Clipper was adopted, all other encryption technology would be outlawed. It was a very scary time.
- dosman33 5y agoThe key word here being "should", and they are clearly not filtering at the network level. I can tell, I still get spoofed robocalls... The clipper chip provided end users the ability to cryptographically prove callers were who they claimed to be independent of the network operator, which is a key need of a crypto system. Robocalling with spoofed ANI has been a problem long enough that I think we can safely say the network operator is 100% complicit with this activity now. The phone company could track down kids war-dialing blocks of numbers in the 1980's in order to make sure they were not telemarketers not paying higher telemarketing fees. Do people really think the phone company is not getting a cut of these robospoofers?
- toast0 5y agoYou don't need a clipper chip to trace nuisance calls. You need an authenticated network that records the origin of calls, and hopefully passes that through when calls are forwarded and makes it simple and worthwhile to report nuisance calls and aggregates those reports and takes meaningful action against the origins. Anyway, we're getting shaken/stir or whatever RealSoonNow(TM), so we'll probably have better CallerID. I don't think it'll be enough to solve the problem, without a reporting mechanism, but I guess we'll see in the next couple years.
- warkdarrior 5y agoWould you want the same capability on the Internet? If not, what makes Internet communication different from POTS communication?
- lmm 5y agoInternet connections have a more-or-less reliable source IP (spoofing does occasionally happen and we take measures to mitigate it), IP ranges have owners and if an address is consistently used for abuse (attacks, spam email, ...) then people do report this to the owner of that address?
- geocar 5y ago> IP ranges have owners and if an address is consistently used for abuse (attacks, spam email, ...) IP ranges have registrants. Servers usually are assigned IP addresses temporarily by the registrant, or by someone the registrant has assigned the block of addresses to by some other means. This means differs from region to region. In the US the responsible party is ARIN, and registrants can reassign addresses using a database called SWIP. In the EU both registrants and their partners use the same database called RIPE. I have never registered addresses in other regions. > then people do report this to the owner of that address? Yes. Registrant again, but yes. And if you don't get satisfaction, then you can (and should) escalate all the way to the region's authority.
- mjevans 5y agoI would want to require: 1) That the source IP address be from a range 'controlled' by the operator of a given AS. This might be proven, semi Out of Band, for a duration by a PKI challenge with a key representing that authority. (Allows distributed services on the same IP anywhere. Fulfillment can be asynchronous if UDP.) Edit: This would also be how to securely claim an AS route; you might still need a link authorized for this level of service. 2) The mentioned feedback mechanism should be coupled with 'do not forward me anything from IP || net/mask for X time' via a similar mechanism. A reason might be provided, reasons of clear abuse MAY be aggregated and used to isolate misbehaving hosts / networks.
- hmfrh 5y ago> Some days I can get a dozen robo calls, each with a different spoofed number. I live in the EU and have literally never gotten a robo call in my life. It's a political problem, not a technical one.
- jrochkind1 5y agoThe US government intentionally made it inconvenient and infeasible to include encryption at a key time in technological development, and I think it had lasting consequences. Yes, if the internet community had acceded to their demands to use the clipper chip, that would have been one route to them lowering the barriers they had put in place to encryption. They also could have just recognized that widespread encryption was in the national interest without the clipper chip, instead of deciding it was opposed to it.