9 ms·
T-Mobile says it blocked 21B scam calls this year
- BitwiseFool 5y agoI'm thankful my phone number's area code is from a different part of the country. All the spoofers use the old area code thinking they are tricking me into picking up. But I know that no one from where I lived in 2006 is calling me.
- shostack 5y agoInterestingly, my mechanic sends invoice links over text. Mine didn't come through so they asked if I had TMobile. Turns out, T-Mobile charges businesses a fee (I want to say they said something like $250/mo?) to allow messages through even though I opted in and wanted this communication. Seems a little bit like they introduced a "solution" but then can simply charge to profit off letting people through the solution?
- woofcat 5y agoRealistically every carrier should be doing this. I have no idea why I'm even allowed to get calls from V11109011700119 on my cellphone. They're so clearly scams / spam that every carrier globally should close these down.
- lolinder 5y agoMost calls I get have my local area code, sometimes even the same first 6 digits. You can't just block phone numbers because phone numbers are self-reported. Spammers will just keep switching.
- _jal 5y agoI get a lot of that too. I haven't lived in the geographical region associated with my area code in over a decade, so I don't actually know anyone with the same prefix. So they may as well use "I am a spammer" as their Caller ID.
- profmonocle 5y agoI saw something interesting the other day. This company called me twice within a few minutes. The first call came from "+1 844-###-####", but it was automatically blocked as spam by Android. The second call was from the same number, but it was formatted as "+844#######". That one wasn't blocked. I wonder if formatting the number this way allows them to circumvent spam lists, but doesn't trip anti-caller ID spoofing mechanisms?
- LostJourneyman 5y agoThis is a call from Memphis TN with a badly formatted ANI. The format that you would recognize would be +19011700119 or (901) 170-0119. 111 or 011 are country code prefixes in the North American Dialing Plan. The "V" may mean verified (which would be an artifact of STIR/SHAKEN, ironically), if you're using XFinity/Comcast... but likely is just an artifact of a bug in the code used to set the headers. The fact that the 901 is prefixed with a 0 hints that the PBX/SBC used to place this call was configured for international use and they missed some localization settings, which could be the culprit for the weird formatting.
- ipython 5y agoThis is fascinating, thanks for sharing. I noticed that I get a lot of spam calls from “Russia” (country code 7) because my local number is in an area code that starts with 7. I figured that the caller totally screwed up their caller ID. I find it hilarious that the callers are trying and failing to appear as if they are in my local area.
- woofcat 5y agoThis is really interesting to me. I've basically just silenced all those calls and my life is much better for it. Interesting that they're in theory passing STIR/SHAKEN.
- petee 5y agoWell its all obvious now; each carrier has their own "SUPERspamGuard!®" so there is little incentive to fix the problem anymore. It is just another selling point to get customers who are fed up with their previous provider. We need to fine companies that continue to route these calls. It is not like tracing is impossible.
- deadalus 5y agoSpam Callers must be identified and banned (preferably) by a global task force that is funded both by the cellular service providers and the governments. This is a global problem and no single country or company can be expected to fix it on their own.
- petee 5y agoOr neighbors need to agree on policing, for example any company/country that lets 10% of its phone traffic be spams just gets disconnected from the network flat out. Want your service back? Fix your house first. I'd be shocked if most of the US's spam doesn't come from within. I'm not against attempting a global body to regulate, but I doubt it would work. We can't even get internet providers to ensure their traffic isn't spoofed, and that's just firewall rules. Edit: maybe not shocked, but personally the only out of country voices I hear now are when I call GoogleFi support.
- mojuba 5y agoThe question is, are phone operators even interested in doing this? Marking robocalls as such - sure, but blocking altogether - I don't think so. Something interesting happened I think a few years ago, when a hosting company in the US that turned out to be the major hoster for spammers went down for technical reasons and the world went spam free (by 90%) for a couple of days. You'd think it was obvious what to do... but nope, once the hoster was back everything was back to normal like nothing happened.
- petee 5y agoI agree, I don't think they have any incentive to, and it would take strong regulation to force them. We would also have to stop pretending that calls are some 'divine message' that can't be interfered with, and be morally ok with cutting off an entire country if they won't curb spam.
- shkkmo 5y agoIt seems easy to me, pass a law that says if a telecom can't trace the source of a call to where it entered their network, they are legally liable for the content of the call.
- criddell 5y agoI really thought rolling out STIR/SHAKEN was going to fix this problem. I don't notice any difference. If anything, I'm getting more robocalls now.
- wincy 5y agoI found installing NoMoRobo and paying the $5 a year has helped considerably.
- LostJourneyman 5y agoSTIR/SHAKEN has barely started to be rolled out, and most major carriers don't fully support both protocols. Realistically the reason you've not seen a difference is that... well there's not been a change. The TRACED act stipulated that large carriers have to have it implemented by June 2021 (and several have... mostly) and that smaller carriers have a 2 year extension until 2023. The problem is that "smaller carriers" has a much looser definition than you think, which includes the phone systems used by most corporate businesses and most cheap/easy SIP providers (like NICE inContact, OnSIP, RingCentral, etc). That said, it'll be a couple years before you see the silver bullet you're looking for, and even then it'll be a couple more before all the kinks are worked out. (There's still some unanswered questions about attestation in smaller regional/local carriers. Also international partners aren't complying with the standard, so that increases the complexity.)
- criddell 5y agoThat seems backwards to me. Wouldn't big carriers be the ones who need more time due to the complexity and size of their systems? Shouldn't small carriers, like the ones you described, be able to roll this out almost overnight? I want my phone to give me the option to only let authenticated calls through and give everybody else a busy signal. Today, the ham:spam ratio of my phone is worse than my email.
- tyingq 5y agoIt's only really had any progress pretty recently. The "Traced Act" deadlines were only a few months ago, and I assume the carriers need some time to iterate on tuning it. Or maybe the FCC needs a few months of data before they can start smacking carriers around. I wouldn't give up yet.
- ct0 5y agoShould we be impressed? This shouldn't even be measured. How many didn't they block? Can we start blaming carriers for not blocking?
- cletus 5y agoThe phone system is a perfect example of why literally nobody other than a few tech purists wants federated communications systems. It astounds me how many still cling to what (IMHO) is an unworkable ideal. The only thing that has made email remotely usable is that the service is concentrated in a few providers who spent a huge amount of effort to minimize the spam. It's classic tragedy of the commons. Obviously we don't have authenticated caller identity in the phone system and you can argue that would solve the problem of spam. No argument it would help but I very much doubt it would solve it. For awhile you were able to IM Gmail users from outside Gmail (through XMPP). This was unsurprisingly shut down because the likes of Microsoft (Hotmail) didn't reciprocate (ie Hotmail users could message Gmail users but not the other way around). Spam on phone networks continues because bad actors profit from it. For example, spam traffic is "laundered" with legitimate traffic so the exchange itself isn't blocked by other parties. It also gives plausible deniability. These things are all inevitable consequences of federated communications systems.
- flyinghamster 5y agoThere was a period, over a decade ago now, where I was constantly getting scam calls from certain area codes and prefixes. Looking them up on TelcoData[0], the prefixes and thousands blocks were all from various phone companies I'd never heard of (and had nothingburger websites). It turned out that scammers had set up actual phone companies to carry their traffic. They were not only doing their usual scamming, but also raking in cash from the resulting incoming Caller ID lookups. These have either been shut down or have fallen under the radar. It's a shame that (just like TCP/IP), SS7 was designed in an era of good faith and didn't have security baked into it from the start. [0] https://telcodata.us/ https://telcodata.us/
- Kye 5y agoPhreaking is older than SS7. The story itself is as old as civilization. It was an era of naivety and exploitation of that naivety, not good faith. Unauthenticated protocols with no user-controlled access is always a bad idea. TCP/IP has firewalls.
- smarx007 5y ago
- flyinghamster 5y agoUnfortunately, only the basic detection works when you're on prepaid. The calls will come in, but you'll at least be warned. No, I'm not going postpaid, especially given their history of data breaches. Still, I like seeing "Scam Likely" when a robocall comes in. Too bad they insist on engaging my voicemail - my least time-wasting option is to just pick up the call and immediately hang up. I'm extremely lucky that my cell phone gets only a few of these a week, but that's annoying enough.
- tzs 5y ago> Unfortunately, only the basic detection works when you're on prepaid. The calls will come in, but you'll at least be warned. No, I'm not going postpaid, especially given their history of data breaches. T-Mobile prepaid is odd. It is almost like it is an MVNE using T-Mobile's network rather than a part of T-Mobile. When I switched from postpaid to prepaid, for example, the T-Mobile mobile app stopped working. It says "Sorry we're not ready for you yet. We're working on improving your app experience" and suggests using the website instead. Checking on their forums, I see it has been doing this for years. They used to say they were working on it, but they stopped saying that. Still, I find it worth it because of the savings. I just need voice, text, and a small amount of data. The cheapest postpaid I see at T-Mobile that would be open to most readers here is $60/month for 1 line [1]. Verizon and AT&T seem to be a little above that. My prepaid T-Mobile plan is $15/month (around $17.something with taxes and fees, which are included in the $60 for the postpaid plan). [1] They have a plan for people 55+ which has about the same features for $40/month (plus taxes and fees, which are included in the $60/month plan). This puts them way ahead of Verizon and AT&T, whose "senior" plans are only available to Florida residents. WTF is up with that?
- 300bps 5y agoI was with T-Mobile until three months ago. I used their Scam Shield service - the app is still actually still on my iPhone. I received about 25 calls per day on average that slipped right through their service. Senior health coverage, car warranty, etc calls. All using spoofed caller ID. All using the same technique of call screeners in India or similar that then forward the calls to US companies buying the leads. I actually had a conversation with a U.S. based insurance agent that was buying the leads and told her of the spoofing and other shady techniques they use. Her response was, “They supply good leads so I keep buying them.” Anyway, I switched to Verizon and it is no better. I ended up setting my phone in Focus mode 24x7 and whitelisted almost my whole contact list. It was either that or change my phone number. Can’t concentrate on work when you’re being called every 20-30 minutes.
- ipython 5y agoGood work identifying one of the purchasers of leads. Sue them under the tcpa which will cost them money - and land you a few hundred dollars for your time. Best of all, it will dissuade them from buying said “good” leads.
- exabrial 5y agoFun little fact: Not a single one blocked was an auto-warranty call to my phone though.
- annoyingnoob 5y agoCame to say, and its not enough.
- wilde 5y agoCensorship! /s
- jonathanmayer 5y agoHi, I previously served as CTO of the FCC's Enforcement Bureau, where I worked on then-Chairman Wheeler's Robocall Strike Force. I'd like to offer a few observations that might be of interest. * T-Mobile, like the other carriers, is offering a numerator and not a denominator. These call filtering services are plainly valuable, but it's difficult to evaluate how effective they are based on current public evidence. * It isn't a coincidence that the top robocall destinations include locations that are popular for retirement. These scams disproportionately target and take advantage of older customers. * Call authentication (STIR/SHAKEN) is helping, and will continue to become more effective. The FCC did not push carriers to rapidly adopt call authentication during the last administration; Congress eventually stepped in with the TRACED Act, and the FCC has since made STIR/SHAKEN a top priority.
- shkkmo 5y agoIt seems ridiculous to me that I regularly receive calls that are clear indicators of illegal activity but that nobody is being held accountable. Why is there no way to find the people who are making these calls and why are the phone companies not liable for allowing these calls to be made without accountability?
- annoyingnoob 5y agoPrior to VoIP it was easier to trace the source of a call. With VoIP, the call could come from anywhere. Also, that VoIP service may have been resold several times and the end of that chain might look like a shady foreign entity with fictitious names. You kill one shady reseller and 3 more pop up.
- ipython 5y agoIt’s a lot of work and honestly the telcos don’t care. Even if and when you do find them, what can you do? They’re calling from halfway around the world - so “impersonating a us government employee” is not a law you can enforce on a citizen of another country.
- shkkmo 5y ago
- logitjoy 5y agoThese companies should open source the spam filter. Let mission driven developers deal with spam filters.
- AnimalMuppet 5y agoDo you want spammers contributing code to the spam filters? If not, then how do you prevent it?
- pseudolus 5y agoIt makes me feel old to realize that I grew up in a time when, if the phone rang, you could pick it without hesitation because the other person on the line was a genuine caller. Things don't always improve with time.
- KoftaBob 5y agoConsidering the old school trope of the 70s-late 90s of the telemarketers calling during dinner time, it being a real person doesn't mean they weren't someone trying to sell something.
- tyingq 5y agoThere's one call I get once a month or so that's a pretty convincing robot. It's a guy asking for donations for some sort of police association. It seems to try to use the robot to gauge interest, then sends you to a real person if you say the right things. They don't change the pitch script at all, though, so I recognize it in the first few words now.
- ipython 5y agoIt’s probably a soundboard system. It’s a sneaky way that telemarketers can “technically” say they’re not robocalling you because there is a person behind the soundboard listening to you and clicking buttons to send the response.
- AnimalMuppet 5y agoI don't care. I don't want a call from telemarketers, whether or not it's a robocall.
- ipython 5y agoI don’t care either. However the telemarketers and scammers are hell bent on making sure the laws are written and interpreted in such a way to benefit them and not you.