5 ms·
Any telco people here that can explain the technicals of how or why it’s still possible to spoof a phone number? Is this just how the whole system works? When
by nnf 5y ago
Any telco people here that can explain the technicals of how or why it’s still possible to spoof a phone number? Is this just how the whole system works?
When I use Twilio, I have to prove to them that I control a phone number before I can use Twilio make outbound calls or send SMS messages that appear to originate from my number. This suggests to me that the system is built with assumed trust, like email was originally. Is everything too ingrained at this point to add some type of authentication that would prevent this type of spoofing? Something similar to a CAA record, where the owner of a phone number could say “legitimate calls from this number will only originate from $TELCO and $SMS_PROVIDER” would be nice.
- djbusby 5y agoThere are some PSTN gateway providers that you can basically makeup your outgoing CID on. Les.net used to let me do that for example - no validation. Twilio is doing their own enforcement to help their reputation.
- wildrhythms 5y agoThese gateway providers, in addition to simply spoofing the outgoing number, will also sell blocks of legitimate domestic numbers to the scammers- knowingly- to use for callback numbers. Truly disgusting https://www.justice.gov/opa/pr/district-court-enters-permanent-injunction-shutting-down-telecom-carriers-who-facilitated https://www.justice.gov/opa/pr/district-court-enters-permane...
- djbusby 5y agoYea, I wasn't tryna call anyone out, there are legit use-case and I like Twilio approach and yet, it's so easy so fake a CID :(
- DaiPlusPlus 5y agoThe PSTN is frozen-in-time: despite SIP and fancy intra-3G/4G/5G tech everything else is built around Signalling System 7 from 1975: https://en.wikipedia.org/wiki/Signalling_System_No._7 https://en.wikipedia.org/wiki/Signalling_System_No._7
- makeitdouble 5y agoNot telco, so I hope there will be better answers. Phone numbers are basically identical to IP numbers in their use, and they are declared by the emitting party. Just as you can spoof IPs in the packet headers, you can spoof the telephone number at the tranport level. We could upgrade to more secure connections, but the whole point of using the telephone network is because of the legacy. I can't imagine a telco putting significant money into improving the network when no customer will pay more for that (right now arguably, spammers are their first class customers ).
- josephcsible 5y agoBut for IPs, don't we at least have reverse path filtering available?
- jimktrains2 5y agothat doesnct work for publicly available services and the initial routwr passes the traffic. This is how things like dbs and ntp amplification attacks work: you spoof your origin ip and have the server generate traffic to the targwt/spoofed ip address.
- thedufer 5y agoThe big difference is that if you send a packet with a spoofed source IP, the reply won't get to you. The phone system allows you to set up a full two-way channel without the receiving party ever needing the correct identifier for the caller.
- hereforphone 5y agoThere is an effort underway to fix this. https://en.wikipedia.org/wiki/STIR/SHAKEN https://en.wikipedia.org/wiki/STIR/SHAKEN There is not much motivation to fix PSTN (and cell networks that rely on or emulate PSTN) as it's being phased out. So things move slowly.
- wmf 5y agoSS7 and TDM may be phased out but phone numbers and phone calls will still exist. It seems like the replacement protocols (SIP?) are still copying SS7 security flaws exactly, with STIR/SHAKEN as a bandaid on top instead of a fundamental fix.
- nostrebored 5y agoYes, the ability to present CNAM in SIP will continue to be a thorn for ages.
- karlshea 5y agoUntil my half dozen robocalls per day end I don’t believe this will actually help. I guess I’ll find out in 11 days.
- hermes8329 5y agoBecause the phone companies are not held accountable for facilitating it If they were this would have been solved yesterday
- ipython 5y agoAgreed. The joke is ultimately on them, though, as a new generation of people grow up and their only experience with the pstn is that every incoming call is fraudulent. What good is having a phone number at that point? It’s just a liability. Most likely the only reason a young person will ever have to interact with the phone system is to call 911 for emergency services. Ultimately the spam problem will kill the pstn as we know it.
- perl4ever 5y ago"A gracious hello. Here at the Phone Company, we handle eighty-four billion calls a year. Serving everyone from presidents and kings to the scum of the earth. So, we realize that, every so often, you can’t get an operator, or for no apparent reason your phone goes out of order, or perhaps you get charged for a call you didn’t make. We don’t care!"
- willhinsa 5y agoWe don't care. We don't have to. [0] From the 1976 SNL sketch, starring Lily Tomlin. [1] [0] https://i.imgur.com/VDdfwNQ.png https://i.imgur.com/VDdfwNQ.png [1] https://vimeo.com/355556831 https://vimeo.com/355556831
- wildrhythms 5y agoIf there was ever a public service job where I could receive scam reports, and trace every single scam text and call back to its source and take action against the gateway carriers allowing these scams to enter domestic copper, I would apply immediately. So much time, needless worry and anguish imposed on innocent people who simply want to trust a communication protocol that should be trustworthy.
- RNCTX 5y agoFunny you mention that. I'd say based on personal recollection that in "public service" you'll likely find people in on the scams. Former congressman from NOLA, Bill Jefferson, orchestrated scams involving securing minority-preferred business loans to found rural phone companies. Those rural phone companies would then pay him back by getting pre-arranged contracts from African countries like our phone scammer friends in Nigeria. When hurricane Katrina hit, they found $90,000 in cash in his freezer. Was pretty close to the $100,000 in cash that the DOJ had videotaped him receiving from the Nigerian government's vice president a few days before. https://www.nola.com/news/article_ed0819a4-9aab-5510-b68c-4102c326608a.html https://www.nola.com/news/article_ed0819a4-9aab-5510-b68c-41...
- LinuxBender 5y agoSS7 was not really designed with any security. It assumed only telcos would be using it and that stopped being true in the 1980's/90's as the bar to entry for getting your own SS7 link was lowered. Even if SS7 were retrofitted to support this type of validation it would be negated by the fact that numbers are portable. A number can legally originate from anywhere. Validation will have to occur out of band by some other means or by replacing or deprecating the telco network entirely.
- closeparen 5y agoThe authentication you’re talking about is called STIR/SHAKEN and it’s an ongoing retrofit. I will describe the status quo based on my brief time in a business VoIP form. The concept of a “phone line” with a fixed number belongs to residential service. Pretty much any business premise has a PBX on it, and that PBX is connected to the PSTN by a bundle of circuits including some voice channels and some signaling channels. Some number of inbound numbers may be routed there. Or not! But that has nothing to do with the signaling on outbound calls. Now for a small business it would probably be sensible to limit outgoing caller IDs to the inbound numbers routed there. In a larger business, PBXes at different sites are connected to each other by an enterprise network, and to the PSTN through different telecoms in different regions. You may have branch offices that only receive calls via the enterprise network, but make outbound calls on local transit. You may route a call from elsewhere on the enterprise network to exit to the PSTN via that branch office, for cost or redundancy reasons. That’s how Twilio itself works. Lots of IT departments have internal Twilios, in that sense. The upshot is that you need a fairly sophisticated cross-telecom standard for establishing authorization to present a number on caller ID, and no one got around to building or driving adoption of that until pretty recently.
- ecf 5y ago> Any telco people here that can explain the technicals of how or why it’s still possible to spoof a phone number? Because couriers offer spoof calling as an under-the-table service to spam caller organizations. I have no proof of this, but at this point in time my opinion of telcos is so low that I will assume it is happening until I find out explicitly that it’s not.