20 ms·
My own phone number is now spam texting me
- mysterydip 5y agoLiterally just got one of these. Very annoying
- senectus1 5y agoI have a series of sms from a local Bank/Super company called "ANZ". today I got an obviously scam sms from the SAME number/source as the official ANZ sms' SMS is a junk protocol. it just needs to be banned entirely. its got no controls or protection whatsoever.
- ungamedplayer 5y agoBut we use it for 2fa. Can't wait till spammers figure out how to abuse spoofing and 2fa.
- daneel_w 5y agoThe problem isn't the SMS "protocol", but that operators still haven't been able to find an amicable solution to regulating sender names/numbers that doesn't interfer with legitimate usage, e.g. commercial businesses doing EBR texting to their customers. The problem isn't entirely comparable to that of caller ID spoofing for phone calls, and is legally and technically more complicated than you imagine.
- m1gu3l 5y agosemi related: is anyone else seeing hotmail addresses bypass apples ios known number feature?
- kylehotchkiss 5y agoMuch like 3G is being shut down, maybe SMS should be shut down too. It’d be easier for carriers to make sure the last email address holdouts make accounts than trying to play wackamole with such an insecure protocol. Then we don’t have to worry as much about SMS unfortunately being used so heavily for web auth
- rhinoceraptor 5y agoThere's no viable replacement, much like there's no viable replacement to email. There are plenty of other ways to accomplish what SMS and email do, but you will always need SMS and email. And the world is not creating standards like SMS and email anymore, at least with any widespread adoption success.
- jedberg 5y agoI'm not sure about that. I almost never use SMS anymore. When I'm messaging with someone on an iPhone, I use iMessage with my email address as the identifier. When I'm talking to someone on Android I use Google Messages (again no SMS). The only time I actually use SMS is when I'm getting a text for a service like my car is ready for pickup or my table at the restaurant is ready, but those could easily be switched to IP based notifications, especially since they are already coming from a computer.
- rhinoceraptor 5y agoSMS is simply the lowest common denominator. If you want to send someone information given a phone number, SMS will work. That isn't true of iMessage, Google Messages or even RCS. Any method other than SMS or a phone call, requires more information than just the phone number.
- jedberg 5y agoThat's not true. With just a phone number I can send an iMessage. Their number turns blue when I type it in letting me know that they have an iPhone. This type of support could easily be added for Android, which would cover most use cases. My point is you're right no replacement exists today, but the technology does and could easily be expanded if the phone companies agreed to phase out SMS.
- tjoff 5y agoJust because apple has a terrible system doesn't mean the rest of us should suffer. Of course the technology exist, it's not like sms is some marvel that humanity could never reproduce. It is just that noone has the right incentives to do it properly or with users interest in mind.
- nikanj 5y agoThe article says the operators are losing the war on scammers, but are they really fighting it? SHAKEN/STIR has been delayed time and again, and all signs point to operators seeing it as an additional revenue stream (”Pay $5.99 per month for Real CallerID”), not a tool to curb spam
- radicality 5y agoHuh, only read the headline and the first few sentences so far, but just got a text exactly like this few hours ago! Going back to reading the article, hopefully it’s not some zero-day.
- asteroidp 5y agoWorse. It's the system working as built and intended
- newman8r 5y agoFor a long time, you could get into any voicemail account by spoof calling that phone number to itself - most of the time they weren't password protected.
- hedora 5y agoThere is / was a similar gmail security vulnerability, where emails "from" you went into your sent box. This was supposedly used to forge harassing emails from work accounts, which provided proof of false accusations.
- vinnymac 5y agoI received this exact text message today. I’ve since deleted it. Additionally hours later I received a text about smoking weed. Both links in these text messages, after further investigation, brought me to Russian owned sites as the article described.
- paxys 5y agoVoice calls and texts are ironically the worst aspects of owning a phone these days. I recently decided to just use my phone permanently on airplane mode while at home, and the overall experience has been a lot better. I wish I had the ability to block all calls and texts while on cellular data as well. All my communication can happen a lot more effectively over iMessage, Facetime, WhatsApp, Messenger and more.
- hedora 5y agoThink that's bad? Our kids have tablets with 5g data (they were basically free...) I managed to lock them down, except they still get spam texts. There's no way to disable incoming texts, even though they're supposedly data only devices.
- grecy 5y agoI have a data-only SIM in my iPhone that does not have a phone number. It can not make or receive calls, it can not send SMS messages. I still get SMS spam on it.
- throwaway98797 5y agoI’ve silenced all unknown callers on my iPhone. I rec folks do the same. I undo this anytime I get a good delivery tho
- MiddleEndian 5y agoYour phone company knows the originator info of your calls and texts (or at least enough hops until they reach some even more untrustworthy than normal phone provider). They simply don't give you that info and instead show you an unverified caller ID that anyone can basically set to anything by whoever is contacting you. Blame your phone company and the FCC for not solving this (and for not providing you with the data to solve it yourself).
- sb057 5y agoFWIW the FCC nominally levies a fine of up to $10,000 per caller ID spoofing incident: https://www.fcc.gov/spoofing https://www.fcc.gov/spoofing
- encryptluks2 5y agoExcept, when it comes to prosecuting people they usually make a deal where they pay a $50k fee or whatever, or they just don't have jurisdiction over the spammers and they'd rather sanction Russia than sanction India or other countries that are originating a lot of the SMS and robocall spam.
- spencerf 5y agoThis is only valid if it’s a US company and many of these are originating outside of the US. Many shady companies outside of the us simply ignore the fines.
- hedora 5y agoSimple solution: The fine is payable, link by link, to the next person in the chain by the party that forwarded the message. So the phone company can pay the subscriber the $10,000, and collect it from whoever they got the text from. I guarantee you spoofing would be solved immediately if this change to the law was scheduled for 12 months from now.
- mcv 5y agoBanning foreign calls/texts that spoof local numbers sounds like a really easy and obvious thing to do.
- nyanpasu64 5y agoWhy can a SMS spoofer use any number they want, but I can't get a second phone number to create Discord accounts without being tracked?
- fredophile 5y agoProbably because discord will send a text to the number to verify it. Spoofing a number is easy as long as you don't care about receiving replies at that number.
- joecool1029 5y agoYou can, just register prepaid phone line with top-up cards purchased in cash from a store. If you use a Google Voice or other VOIP service, this shows up as VOIP and they won't let you use it. Annoying but it's the cheapest/easiest workaround I know of.
- aidenn0 5y agoCall ID spoofing is annoying yet plenty of people don't understand it. I get called at least once per month from (a different each time) someone in the same exchange as me saying they had a missed call from me. Presumably they got a spam call from my number, as I get about 5 spam calls per day with caller-id spoofed to a random number in my exchange.
- hedora 5y agoOne day I got really angry calls on my cell phone (number XXX-YYY-ZZZA) from the owner of a lost phone with number YYY-ZZZ-AAAA. They were apparently calling from a land line in area code XXX, and didn't know how to dial long distance on a touch tone phone. I tried to explain that they needed to dial "1", then their number to reach their lost phone. They kept calling, then screaming about how I stole their phone and to stop screwing with their head; they knew how to use a phone. After about 5 minutes, I gave up and blocked the number.
- notRobot 5y agoI was on a group call with a bunch of friends a couple nights ago. My Indian friend was telling me that they have very little spam SMSs and robocalls. They speculated that it is because in India the person making the call or sending the text is the one who pays for it. So spamming is expensive. Also, apparently spoofing numbers is unheard of in many countries, the US seems to have it particularly bad. If anyone here is familiar with the technicalities of how this stuff works, what are your thoughts on the hypothesis?
- wielebny 5y ago> They speculated that it is because in India the person making the call or sending the text is the one who pays for it. Wait, what, do people in US pay for receiving texts or calls?
- jedberg 5y agoYeah, we do. It sucks because we pay for the spam calls. Most cell plans now include unlimited incoming calls and texts, so it's not really a problem, but the sender does not pay anything either, which is a problem.
- mcv 5y ago> Yeah, we do. It sucks because we pay for the spam calls. If the robocaller/spammer doesn't pay for it, I think that explains why these things are so rampant in the US. In Netherland, it's only the caller who pays, and robocalls and sms spam are extremely rare here (at least in my experience). Although these days, many phone subscriptions come with unlimited calls and texts, so the caller/texter doesn't pay either. Somehow this doesn't seem to have lead to an increase in spam and robocalls.
- namibj 5y agoThey are unlimited(fair use applies).
- unsignedint 5y ago
- lathiat 5y agoAbout 6 months ago here in Australia I had a run of getting spam called by a number which was the same as my number but off by 1 digit. Seemed like a clever method to peak peoples interest but made it pretty obvious to me it was spam.
- deleted 5y ago[deleted]
- mnw21cam 5y agopeak -> pique.
- pjerem 5y agoCan someone "eli5" why this possibility of spoofing even exists and is allowed ? What are the legitimate use cases of this feature ? EDIT : thank you all for your answers ! I suppose it’s the same thing that allows you to receive messages from "SOME BRAND" and … why not. But this could be easily regulated. I don’t understand why anyone can spoof anything they want. Also, I don’t understand why my iPhone don’t allow me to block messages from "SOME BRAND" as if it was from any other sender.
- ggm 5y agohttps://datatracker.ietf.org/wg/stir/documents/ https://datatracker.ietf.org/wg/stir/documents/ its not exactly ELI5. The CLI (Caller Line ID) field of a "incoming call" message isn't adequately policed. This is sort-of baked into how telephony works. It's stupid, and it should have been thought about more. The CLI field isn't how the call routes, its just how the caller announces who you are. Telephone call routing uses other data fields, its part of SS7 and the other signalling systems the phone network uses. The field which comes up a mobile call, inside "payload" isn't how it routed. Imagine some company has the indial range 667 2200 to 667 2299. If you dialled from your assigned handset 667 2241 the CLI can say 667 2200 so it looks like you come from the switch (in this example we assume the company's PBX operator is on 2200, and you publish 2200 as the incoming call number) so people don't learn your office handset: thats why they permitted it. I have no idea why they allow to to "lie" above your indial group range. But they do. STIR is how in a VOIP world people are approaching the fix. But really? the FCC and other national regulators have to tell the telco to stomp on the fakeout, when people inject calls into their system. This has parallels with "envelope sender vs RFC822 header" in email. Or spoofed source if your ISP doesn't do BCP38. Guess what: SPAM is a problem in email (duh) and spoofed source is how DDoS can happen. "telling lies" in end-to-end communications is not helpful.
- marcus_holmes 5y agoIf this is baked into telephony, why we don't have this problem in Europe? (genuinely curious why this happens in the USA but not here)
- dimgl 5y agoHappened to me this morning. Completely freaked me out.
- jlmorton 5y agoOne of the very best features of Android Messages is that you no longer get spam texts. The combination of Pixel and Google Fi means you never get spam calls, or spam texts.
- nieve 5y agoApparently the spam calls and texts I get don't exist? That'll make them less annoying in the future.
- jrockway 5y agoThe good news is that Verizon has all these grand plans to intercept your browsing data and use it to target ads, but they can't even implement the most rudimentary spam protection on SMS, so I don't have high hopes that they're going to make any money by spying on everyone. One could argue that since the more messages you receive, they more you pay, they have no incentive to reduce spam; whereas with ad tracking, as long as they find some advertiser willing to pay 100 million dollars for a 1% increase on click throughs on their overpriced toothpaste, they'll have a financial incentive to do a good job. So maybe we're actually really screwed. Sad that a cell phone company can't be just a cell phone company. They were pretty good at that.
- InCityDreams 5y ago"One could argue that since the more messages you receive, they more you pay,..." Laughs in €uropean. Btw €5.99 unlimited calls, unlimited texts (that the receiver doesnt pay for [maybe my US friends do....must check] 100Gb a month. Had the same tel.no for nearly 20 years, several different operators. My US friends are very jealous (though at least one has unlimited EU calls and texts).
- thatguy0900 5y agoPretty much everyone in the US has unlimited calls and texts. You have to go looking for obscure senior citizen plans meant to be emergency phones for anything that is charged by the text and minute. Our service costs way more than 6€ though
- darknavi 5y agoYeah, I'd say at the big three (four?) it's normally "unlimited everything for ~45€/mo". We get North American roaming but T-mo is the only one that does seamless international besides Google Fi.
- Animats 5y agoThe "STIR/SHAKEN initiative" was supposed to fix this.[1] There's now a whole system with signed certificates, much like SSL certs, to sign caller ID info. The info is at least good enough to find out which carrier generated the phony data. You should file a complaint with the FCC that your carrier has not clearly not properly implemented STIR/SHAKEN, since they badly mis-identified the source of a call. While calls from outside the US can be unsigned, the carrier should detect that the number is inconsistent with the source. There are "A", "B", and "C" level of verification. "A" calls are probably legit. The others, maybe not. If you're in California, try making a personal data request to your carrier for the detailed STIR/SHAKEN data for that call. [1] https://commlawgroup.com/2021/stir-shaken-robocall-mitigation-compliance-regime-what-is-it-why-is-it-important-who-must-comply-how-and-by-when https://commlawgroup.com/2021/stir-shaken-robocall-mitigatio...
- sillysaurusx 5y agoThe Federal Communications Commission (“FCC” or “Commission”) requires that all voice service providers (“VSPs”), with some exceptions discussed below, implement the STIR/SHAKEN caller ID authentication framework in the Internet Protocol (“IP”) portions of their networks by June 30, 2021. So stoked that there’s finally a way to fight back against robocalls, and that carriers are being forced into compliance. Thanks for pointing this out.
- karlshea 5y agoMy impression is STIR/SHAKEN is only for voice calls, not SMS. I'm no longer getting almost any robocalls on Verizon as of a couple of months ago when they "turned on" STIR/SHAKEN. What I am getting instead is the same volume of spam text messages.
- deleted 5y ago[deleted]
- 2143 5y agoOver here in India there's a DND (Do Not Disturb) registry [1]. The link [1] links to Telecom Regulatory Authority of India (TRAI) website. You sign up to DND by dialling a number that is dependent on your carrier (therefore you need to do this separately for all your phone numbers [3]), and go through the "Press 1 for English [2]... Press 2 for so and so... " etc. Takes a couple of minutes. Once I signed up, the number of marketing and similar silly calls/messages have been nearly eliminated. Maybe something similar — something that allows people to opt out of such calls/messages — can be implemented in USA. [1] https://trai.gov.in/faqcategory/unsolicited-commercial-communicationsucc https://trai.gov.in/faqcategory/unsolicited-commercial-commu... [2] The language question because there are plenty of languages in India. [3] Tangent: do people not use multiple phone numbers in USA? Like, I wanted to buy an iphone but it does not support multiple SIM cards (unless you convert one of the SIM to an e-sim [4] which I'm hesitant to do because if I later switch back to an Android phone that does not support e-sim, I'll have to go to my phone company to get a physical sim. Too many hassles. ). Also I'm told iphones sold in China has dual sim capability [5], but I can't go to China just to buy an iphone. [4] https://support.apple.com/en-ph/HT209044 https://support.apple.com/en-ph/HT209044 [5] https://support.apple.com/en-ph/HT209044 https://support.apple.com/en-ph/HT209044
- kwhitefoot 5y agoSame here in Norway. It is an offence to make an unsolicited commercial call to a number that has been on the register for more than a month. It can cost the caller 300 USD per call in fines. I have had perhaps two unsolicited calls in the last five years and one of those was from a number apparently in London, UK.
- jedberg 5y agoWe have that here too. Usually when you sign up your spam calls actually increase because spammers use the list of "banned numbers" as a list of "verified numbers of real humans". With CallID spoofing its so hard to track down that violators never get enforced. In India you have the advantage that the caller pays, which means you have a phone system that somewhat securely verifies who the caller is so they can be billed. In the US the receiver pays so there is no system in place to verify who the caller is.
- phendrenad2 5y agoI'd love to see a post-mortem of what went wrong here, but alas our lowly civilian eyes will probably never get to see it. We just get to sit here and hope we don't wake up one morning and blearily click on a zero-day message that gets past our mental defenses by coming from our own number. Don't click the link, citizen, if you do, it's your fault and therefore your responsibility to prove any fraud or identity theft. Fun times.
- k1rcher 5y agoReceived this exact text, word for word with the same suspicious phishing link, from my own number, a few hours ago.
- kwhitefoot 5y agoI have the impression that this sort of problem is bigger in the US than in other countries. Is this really the case? And if so is it because the US is simply a larger target or do telecoms systems in other countries do a better job of combatting it?
- pkaye 5y agoI think that English being the many language makes it a bigger target since it's a common second language spammers can learn.
- ratww 5y agoI think it is the ability to spoof caller id, mixer with the fact the US is a rich country, mixed with the fact a large part of the world speaks the language.
- 7steps2much 5y agoIn other countries the caller pays for calls/texts. The way I understand it that isn't the way it works in the US (something about callers not knowing if they are calling landlines or mobile phones?) For example, over here in Austria you can tell exactly what type of "line" a callee uses and so you know in advance how much you have to pay (even though in practice most people have unlimited calls/texts). This means that when running a spam bot you will soon run into big issues because it simply doesn't pay off financially to send that many texts and calls.
- mcv 5y agoHaving the caller pay nothing and having the callee pay for the call does sound like it invites abuse, and discourages callees from even picking up the phone. In Netherland, it used to be that the caller pays. Technically they still do, but many subscriptions come with unlimited calls and texts these days. Phone numbers that cost extra money tell you that before they connect you.
- noduerme 5y agoSorry, I just scanned the comments and didn't find anyone mentioning this: It's really easy to spoof a phone number for SMS if you know which network the person's phone is on. Trivial if you know how. There's no black magic to this. At least, it was so a couple years ago. The last time I fooled with that for fun, I spoofed one of my friends admitting to another that he'd slept with the other guy's wife and decided afterwards he was gay. I managed to insert it from his phone number into our group chat as it appeared on android. (I think it might've ended up in a separate chat sequence on iphone). That was funny. There's no dark arts here.
- dfawcus 5y agoSo having read this, the answer seemed obvious: Send a text (iMessage) to myself on the phone. Then look at it, and block my own number. The phone then reported it would block calls, FaceTime, messages from my own number. Since I don't expect to ever need to call/message/FaceTime myself, that seems like a zero cost solution.
- temp0826 5y agoI'd be more worried about these spam texts coming from my number to my own contacts that I have previous conversations with than to myself. E.g. why wouldn't my grandmother click some link I sent to her? (My first thought was that these texts could just be from some malware on the phone itself, possibly with access to the contacts. But if it's actually an externally sourced spoof, that's obviously less dangerous...unless they somehow got my contacts I guess)
- bearjaws 5y agoThe main issue is OTHER people getting spam calls or texts from your personal number. I got one of the Android stock text messages last week for when you auto-respond to a missed call. 'sorry can't speak right now' from a phone number I never called. So a spam caller used my phone # to call, the person auto hung up with a response, and the real text message went back to my phone... It's absurd.
- ehmorris 5y agoThis will prevent your texts from syncing between your phone and other devices, like a MacBook. I learned this the hard way by debugging a relative’s text-syncing issue.
- rbut 5y agoI run a SaaS, whose users can enable sending SMS from their number. We have an agreement with a bulk SMS provider to allow us to do this (we had to show proof of our application, our mobile number verification process, and give our use case). When users send an SMS from within our application, we send it as if it came from their number. Then recipients can then reply directly to their phone. Our users love it. So yes, there are real use cases where the ability to do this is beneficial.
- WaxProlix 5y ago"Our users love it" is not the same as "yes,there are real use cases where...", which is not the same as "this is good and correct because..." Users can love or hate all kinds of things, and often those preferences are at odds with security or other best practices. Aspire to better.
- rbut 5y agoThe alternative is a shared number, which then requires logic to determine which user sent a message to X. When receiving a reply from X, you must determine which user to associate the reply to and then forward it to them. This can and does go wrong. Especially if multiple users are messaging the same recipient within a time period. If we have validated our users mobile numbers via a TOTP code, informed them that they are sending SMS as their number, then how is it different to an application like Signal or iMessage linking your messages to your mobile number? It's not. And that's why it's allowed with certain SMS gateways. The SMS gateways are doing the due diligence to ensure you are sending spoofed messages appropriately and only as the user who actually owns the number. Edit: The spammers are most likely using gateways who aren't doing these checks. The solution is to fine or shut these gateways down.
- ecf 5y agoThe solution is to completely rip out the ability to do anything remotely close to arbitrarily choosing which number is sent along with a text or phone call. Until then, every legitimate use case pales in comparison to even a single spam call taking a second of my attention in a day.
- yread 5y agoHappened to me with email. Even with DMARC active and set to reject 100% on my domain, outlook somehow found it a good idea to deliver those emails to my spam folder
- dghughes 5y agoMy elderly mother got a call from a Doctor for an appointment reminder saying "press 1 to confirm". It was one of those robo voice calls. What was disturbing is the doctor's name was nobody she knew or heard of. But the call mentioned a doctor's appointment she actually did have. The robocall had the day and time correct but the nurse there said they never called my mother they don't have any automated system to call patients. Mom almost answered the robo call if it wasn't for the ominous "press 1" which I tell her to never do. I put mom and dad on the do not call registry here in Canada but it doesn't help. Constant calls from Amazon, Visa, Revenue Canada etc. It's either the robo voice or someone with an Indian accent.
- grecy 5y ago> I put mom and dad on the do not call registry here in Canada but it doesn't help. I worry about my Dad with this. I tell him constantly to hang up no matter who they say they are as a matter of habit. If he really wants he can initiate a call with that organization to ensure it's actually them. Despite me saying this repeatedly, I've heard him give personal info over the phone to cold callers offering discount electricity rates.
- deleted 5y ago[deleted]
- diebeforei485 5y agoIf she has an iPhone: Settings > Phone > Silence Unknown Callers It's a nuclear option but it works
- szczepano 5y agoThe problem with data protection acts is that they try to protect data and it won't work cause the data they try to protect is outside people houses. Everything that is outside house is public and we just need to assume you need to provide data about it so we can verify your identity like with public key. Just to give example, when you live the house anyone can ask you anything ex. ask your neighbour about your name, anyone can read your house number, can see you or take photo of you legally or illegally that's different topic but we should protect peoples privacy inside their houses instead of trying to protect something we can't cause everyone see us how we are when we leave the house. It's basic public / private key problem. Everything outside house is public key and everything inside is private key. So with phone we shouldn't protect people identity, address and/or company name but protect people from disruption with calls they don't want to answer and give them ability to verify who was calling, by even seeing their photo cause yes if I'm your neighbour I can see you and if I move next to you next year I can see you too. Wow. There should be 2 call indexes one for contacts that should behave same as it's behaving now and second index for anything else that you shouldn't receive notifications but you can check this spam missed calls index and verify anyone that called you and add them to contacts - just how the old good paper phone book worked. This empowers people to be able to make decision if I want those people to call me or not, cause you can always call back and it should be widespread when you call someone first time expect they might won't answer your call same as if you email someone they might not answer cause your mail is in spam.
- yashkadakia 5y agoWe need a GIF of Nelson going "Stop spamming your self, stop spamming your self" https://getyarn.io/yarn-clip/921915b0-4a3b-4e96-beed-eb7b50a6f93b https://getyarn.io/yarn-clip/921915b0-4a3b-4e96-beed-eb7b50a...
- fortran77 5y ago_Calling_ a person from their own (faked) phone number was a tried-and-true technique for getting someone's voice messages back in the day. It used to be that voicemail PINs were optional, and if you called your own phone number, you'd get access to the voicemail playback menu. It's trivially easy to fake a caller ID, whether for voicemail or SMS.
- deleted 5y ago[deleted]
- kup0 5y agoGetting robocalls from spoofed local numbers in my area code. Extremely frustrating because they look more legitimate this way, like it's a local business calling me back or something. Provider: Boost Mobile (MVNO for Sprint/Tmo)
- johnklos 5y agoThe age of the traditional phone system is ended. Years ago, bills were introduced Congress that would've made falsifying Caller ID illegal, but certain people said it would be too onerous for small businesses. One bill passed in the House and was sent to the Senate, where it was promptly ignored (H.R.251 - Truth in Caller ID Act of 2007). Lots of people, both those who know nothing about technology and those who know enough to know better, say this isn't enforceable because too many people are doing it. Bullshit. Like spam, if you establish punishment for those who allow spam, you have a very simple mechanism for enforcement. In the old days, when we got spam, we'd forward it to the administrators of the system that sent it or the administrators of the network where it originated. They'd warn, punish, and/or remove the person / system responsible for the spam. These days, abuse@yahoo.com doesn't work, GoDaddy, Cloudflare and others won't do shit unless you find their web page for reporting abuse, then jump through hoops to shoehorn the spam in to their intentionally shitty web page, and even then they pretty much ignore it. Google just ignores everything sent to abuse@google.com. Imagine if every spam that's ignored led to a fine. It'd be chaos and mayhem, but within a year we'd be back to how things were in the early '90s. Of course that wouldn't affect spam from the rest of the world, but imagine if large US networks stopped accepting email entirely from Chinanet until they started acting on abuse complaints. The same can be done with Caller ID. You've got a T1 that lets you set your own Caller ID? Great. You might not get caught, but you can set what you want. Your upstream provider might ignore it, but they connect somewhere larger, too. So let's say AT&T customers are getting complaints about phone calls with false Caller ID, and AT&T looks in their logs and sees that they're coming from your upstream. Now your upstream is in trouble unless they fix it. If they don't, they get a nice hefty fine. How do they fix it? They force you to stop. If you don't, it's illegal, so they can contact the authorities. Or, they could just terminate you. This is just like egress filtering in the networking world. If your network is passing along lots of spoofed traffic and someone contacts you to tell you, and you just pretend it's not your problem, you should be punished. You shouldn't allow traffic to leave your network that claims to be from sources that aren't on your network. "But routing!" Bullshit. If it's coming on to your network from elsewhere, you should be required to say from where, so the originating network can be identified. However, businesses don't want to be bothered putting any time or energy in to this. Businesses rarely do a thing because it's the right thing to do, unless they can make it a marketable advantage. They need to be forced to do this by law, by threat of loss of money. Caller ID spoofing should've been illegal all along, and businesses which do nothing about it should be punishable. Because that's not the case, the old fashioned phone system might as well completely die.
- thatguy0900 5y ago"SMS phishing, or “smishing,”" Why does the media do this?
- daneel_w 5y ago"Journalists" are desperate to stand out.
- AdmiralAsshat 5y agoLiterally got this exact text this morning. Definitely seems to be a Verizon problem.
- yftsui 5y agoThis is a new level of spamming that this morning I got a text message from myself: "Free Msg: Your bill is paid for March. Thanks, here's a little gift for you: ${short link redacted}" The short link is hosted on Cloudflare which eventually redirect to a Russia TV website 1tv.com or 1tv.ru < HTTP/1.1 302 Found < Date: Tue, 29 Mar 2022 17:37:58 GMT < Transfer-Encoding: chunked < Connection: keep-alive < Location: http://1tv.ru http://1tv.ru < CF-Cache-Status: DYNAMIC < Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=yEU2D%2FlNvx216BeQ8TK2oONisk12pAzUW7FlYuTb2Uth9LIT8pcSQyKok1FASqproAoWqBc%2FHaje8lf8pihU2kTSzuoslYERPQvnvRSv%2FyHKIDQ3%2F8e1hSaYMKEn"}],"group":"cf-nel","max_age":604800} < NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800} < Server: cloudflare < CF-RAY: 6f3a605d595039ad-SEA < alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
- geocrasher 5y agoAround the same time you were posting this, I got the exact same message which was supposedly from my own number. Talk about pervasive.
- InitialBP 5y agoHopefully this will help some others deal with spam SMS. A few months ago I started getting huge group text spam to hundreds of emails that were almost identical to my own (changed obviously) if my number was : 123-454-9938 then i would get in a group chat with numbers from 123-454-9900 all the way to 9999. They were using email -> sms specifically which is a relatively new feature that allows you to text mobile devices on carriers that support email to SMS. [1] Super annoying - but AT&T at a minimum allows you to call and request that they disable this feature for your account. If anyone else is getting constant sms spam from email addresses this is the way. Disclaimer: I don't know and have not run into any issues where legitimate companies are using this feature yet. If so, then obviously you won't be able to receive those texts. At the moment there is no capability with carriers (that I've seen) that would allow you to create an "allowlist" of domains to accept texts from, but until that exists I won't be dealing with email to sms as it's just a huge cesspit of spam. 1 - https://www.att.com/support/article/wireless/KM1061254/ https://www.att.com/support/article/wireless/KM1061254/
- jasonladuke0311 5y ago> They were using email -> sms specifically which is a relatively new feature that allows you to text mobile devices on carriers that support email to SMS. I don't think this is true? In ye olden days of text messages, SMS and MMS were relayed via email, IIRC. I remember emailing pics to a friends phone using the MMS email address. The format was unique to each carrier but included the phone number, obviously.
- wildzzz 5y agoI used to annoy my friends by sending emails to their sms email address (1234567890@vtext.com or whatever) using open email relays. You could spoof the sender name as whatever you wanted and most sms clients would just show that.