5 ms·
We really just need telcos to stop allowing caller id spoofing. Doesn’t even need your name, but with a real number we could actually report these scams. You
by dec0dedab0de 4mo ago
We really just need telcos to stop allowing caller id spoofing. Doesn’t even need your name, but with a real number we could actually report these scams.
You can still allow people to hide it, but then by default every non-business phone should block calls with hidden numbers.
- smallmancontrov 4mo agoWhat ever happened to SHAKEN/STIR? I thought this was supposed to happen 5 years ago. Did they just chicken out on the prospect of actually shutting down telcos sending spam volume? I still get loads of spam phone calls, so clearly something went wrong (or slow enough to be indistinguishable from wrong).
- inigyou 4mo agoAccording to a defcon talk, spammers just make sure all their spam gets routed through legacy TDM systems which discard the shaken/stir header because they're too old to support it. The other side then re-adds a "we got this from somewhere that didn't support this header" header.
- coldpie 4mo ago> legacy TDM systems Easy fix. It should be opt-in to accept a call that is routed through one of these. I know they allow it so some grandma in rural France that still uses a dial phone on a copper line that hasn't been touched since 1962 can call her son in New York, but for the rest of us who are not in that situation, we can just blacklist all those calls and lose nothing. This would even fix spam for the people who opt-in, because so few people have grandmas in rural France that it's not worth it for the spammers to bother anymore.
- calvinmorrison 4mo agoI am, more in tune with "just get it over with" than ever. Ipv6? 25 years of this crap? should have just said, Jan 1 2001, all routers must support 64 bit ipv4 addresses. Like the chrome HTTPS switch over, JUST DO IT
- donaldjbiden 4mo agoYou mean 128 bit? That's called ipv6. It's ipv4 with 128 bit addresses.
- simoncion 4mo ago> Easy fix. It should be opt-in to accept a call that is routed through one of these. Easier (and correct) fix: Telecoms operators should not be permitted to provide transit to a call that's routed through one of these. > I know they allow it so some grandma in rural France that still uses a dial phone on a copper line that hasn't been touched since 1962... This doesn't make sense. Even my inexpensive Mikrotik switches can augment packets with the ID of the port that they originated from. I do not believe for even a second that Telecoms Grade switching equipment is unable to do the same. The fact that that grandma can send and receive calls tells you that both that that equipment exists and that it knows what port her phone is connected to.
- mschuster91 4mo ago> I do not believe for even a second that Telecoms Grade switching equipment is unable to do the same. The example should rather have been some telecom carrier in Africa or India. Telco equipment is expensive, the technology is ridiculously complex and getting companies especially in less well-off regions to replace aging stuff and updating it to modern standards is next to impossible. Think about it, the globally connected phone system includes countries where you get 10 GBit/s symmetric fiber in your home and it includes countries where people don't even have running water because they're so poor. The fact that we in Western countries can have a realtime conversation with someone in the Saharan desert or in an Indian village that requires days worth of travel [1] is nothing short of a miracle. [1] https://www.aljazeera.com/gallery/2024/5/8/an-election-booth-inside-a-forest-in-india-for-just-one-voter https://www.aljazeera.com/gallery/2024/5/8/an-election-booth...
- simoncion 4mo ago> Telco equipment is expensive... Sure, agreed. > ...the technology is ridiculously complex... Odd. I could have sworn that Caller ID, Customer-initiated Dialback, "Tell me the number of my most recent caller", and "Keep calling this number for the next half hour, and ring me if the call is answered" were features that were available on the POTS since the early 1990s. I agree that the tech's complex, but the R&D for the stuff I'm talking about has been over and done with for at least thirty five years. There are adult HN users who have never lived in a world without this stuff. > ...getting companies especially in less well-off regions to replace aging stuff and updating it to modern standards is next to impossible. I don't see how that's the problem of "The West"? If it's actually a problem, instruct "Western" telecoms to send a couple-hundred-million dollars in last-gen equipment, along with the techs required to install it and let them declare its original purchase price and the full cost of the manpower as a tax credit. > ...is nothing short of a miracle. If we ignore the existence of long-range radio, and if this were prior to 1965 or -at latest- 1970, I might agree. But, like, we've had satellite telecommunications for nearly sixty years, terrestrial microwave transceivers for a couple of decades longer, and short- and long-wave transceivers for far, far longer than either. Additionally... I don't know if you've noticed, but it's not uncommon to have a satellite phone in your pocket these days.
- inigyou 4mo agoIt is opt/in. There's three categories (according to that defcon talk): call originates from the number it says it does, call originates from our network but we're not sure about the number, and call came to us unverified (only allowed by regulation on legacy links). Now, operators of those legacy links make A LOT of money for operating them since they carry 100% of the country's spam traffic, and they're not going to shut them down just because you think they should. The government would have to make them do it and they'll pretend upgrading is super expensive.
- jrockway 4mo agoSure, but why do I care? Let them run the legacy links. Just don't make my phone ring.
- coldpie 4mo ago> call originates from our network but we're not sure about the number, and call came to us unverified I'm saying these two categories should be denied by default by my telecom provider, and the user must opt-in to receiving them. > Now, operators of those legacy links make A LOT of money for operating them since they carry 100% of the country's spam traffic, and they're not going to shut them down just because you think they should. Those operators are not my concern, they can do whatever they want. I want my telecom provider to block unknown/unverified calls by default. I have no reason to ever receive a call from an unverified source. Some people might, because they have business or relatives or whatever in such a region, and they can opt-in to receiving them if so.
- inigyou 4mo agoIf your telecom provider stopped carrying unverified calls you'd cancel your service because you'd miss a lot of important calls. If the government required it for all calls though...
- coldpie 4mo ago> you'd miss a lot of important calls Like what? Who is both a legitimate caller and also trying to call me through one of these unverified legacy services? If their calls stopped going through to a huge chunk of their customers (this is one of the reasons receiving unvalidated calls should be opt in, not opt out), why wouldn't they switch to a verified service?
- criddell 4mo agoI'm not certain, but I think on my phone incoming calls that fail SHAKEN/STIR show the caller id in red rather than black text. I'm on T-Mobile. It also shows "Number Verified" or something like that.
- smallmancontrov 4mo agoNow that you mention it, I believe I have seen a couple of red flagged calls, but I still get ~3 calls a day from a very aggressive business loan spammer, it's always a new number and never flagged.
- 9cb14c1ec0 4mo agoThat's because they are bulk purchasing numbers from voip providers, cycling through probably hundreds per day.
- derefr 4mo agoDo they actually need to purchase numbers to do that, though? I always imagined that there are certain shady providers ("grey-market Twilio" sort of idea) that just let you run single outbound call/text requests through a giant pool of numbers shared with other customers of the service. Perhaps specifically a bank of residential numbers plugged into banks of regular cell phones, like a residential IP proxy service provider.
- bityard 4mo agoSomebody at some point is purchasing them, probably not the spammers/scammers themselves. It's very unlikely anybody is placing spam/scam calls with regular cell phones when VoIP numbers are easy and cheap to get, and when VoIP systems are far easier to manage.
- tmp10423288442 4mo agoYou would think that someone is getting real cell phone numbers, for the same reason scammers value residential IPs rather than data center IPs.
- swed420 4mo ago> I thought this was supposed to happen 5 years ago. Did they just chicken out on the prospect of actually shutting down telcos sending spam volume? It would certainly hurt a consumption-based economy, for starters.
- philipallstar 4mo agoWhy would that hurt a consumption-based economy?
- twodave 4mo agoTelcos make money off of scammer activity.
- colechristensen 4mo agoMaybe in the same way that Office Depot makes money on the envelopes used in mail fraud
- swed420 4mo agoIt's a vector for advertising.
- philipallstar 4mo agoBut that's not a consumer initiative. Advertising can come from all sorts of places that the consumer doesn't like, and in economies where advanced levels of consumer choice are limited to the state bureaucrats.
- swed420 4mo ago> But that's not a consumer initiative. Seems irrelevant to the original point.
- philipallstar 4mo ago
- xnyan 4mo agoThe FCC issued a report on this very subject[1]. TLDR, there have been four exceptions to the SHAKEN/STIR requirements: - Providers that can't afford it implement it - Non-IP networks - Small voice service providers that originate calls via satellite using U.S. NANP - Providers that lack control over the network infrastructure necessary to implement Nothing is going to change as long as those holes exist. 1: https://docs.fcc.gov/public/attachments/DOC-416732A1.pdf https://docs.fcc.gov/public/attachments/DOC-416732A1.pdf
- 9cb14c1ec0 4mo agoThe can't afford it exception is disappearing soon, as it isn't true for any business. Total setup costs for STIR/SHAKEN are under $2000 these days. Providers that lack control over the network infrastructure (i.e. they don't have the ability to control the stir/shaken headers so by definition they can't spoof numbers) will likely continue to be a thing as changing it would force pretty much every small business in the VOIP industry out of business and allow only large companies to be VOIP service providers.
- singpolyma3 4mo agoJust because a call is a spam call doesn't mean it is spoofed. STIR/SHAKEN ends spoofing but anyone can ultimately buy a phone and make calls that are spammy.
- Zak 4mo agoSure, but with phone numbers that can't be spoofed, telcos can terminate service, and filtering technologies can block calls. Spam gets expensive if you have to buy new service every five calls.
- singpolyma3 4mo agoIt does. But the spammers still do it. Because eventually they hit one person who gives them a thousand dollars or whatever and it pays off.
- Zak 4mo agoPreventing spoofing doesn't have to make spam cost-prohibitive for every spammer to greatly reduce the volume, and it does not interfere with ordinary people obtaining phone service anonymously.
- iamnothere 4mo agoNobody is making spam calls with cell phones. Spammers use VOIP services and old TDM systems.
- DrewADesign 4mo agoThere’s SIM card banks for SMS spam… I’d be surprised if there wasn’t anything similar for calling. Not that I support this bill but it is a thing.
- rescbr 4mo agoFrom what I’ve investigated as a recipient of spam calls, I’ve been called from legitimate mobile numbers from my own mobile telco. The only thing that explains that are SIM card banks. Unfortunately there isn’t an easy way to report abuse to the telcos (and regulators).
- 9cb14c1ec0 4mo agoSTIR/SHAKEN up to this point has only been a self-certification that a telecom company has the right to use a number. What the FCC is trying to do is set up a legal obligation for the STIR/SHAKEN header to match a KYC verified identity. If the FCC implements this, I expect a lot litigation because of the burden and legal liability this would place on telecom and VOIP companies. There are other less burdensome approaches to preventing spam that the FCC has not tried.
- HappMacDonald 4mo agoI am constantly amazed how few people understand that preventing spam is below the last thing the FCC is actually interested in. First of all, the decision makers at the FCC profit from directly from spam, Christ. Secondly, the indirect value of spam to the FCC is that it helps to justify initiatives to ruin the privacy of ordinary people via the constant push for KYC. Just like "age verification", Flock cameras, license plate scanners, ubiquitous IoT with microphones and cameras, etc. Governments and corporations both profit from shredding every molecule of your privacy.
- Rendello 4mo agoI love a good tortured acronym: > SHAKEN system, short for Signature-based Handling of Asserted information using toKENs [...] > The name was inspired by Ian Fleming's character James Bond, who famously prefers his martinis "shaken, not stirred". STIR having existed already, the creators of SHAKEN "tortured the English language until [they] came up with an acronym." https://en.wikipedia.org/wiki/STIR/SHAKEN https://en.wikipedia.org/wiki/STIR/SHAKEN (Unrelatedly, seeing a slash used casually within the URL slug feels so wrong)
- idiotsecant 4mo agoI like backronyms because it tells me someone with a soul was involved
- Rendello 4mo agoLLMs are really good at making backronyms, in fact it might be one of the things they're best at. Try prompting any soulless overlord with "give me a backronym for <WORD> that relates to <SUBJECT>". So maybe it's bad backronyms that demonstrate the soul. I don't know who's idea it was to allow a computer to generate whimsy, that should be interdicted by a fourth law of robotics.
- idiotsecant 4mo agoAgreed. Aggressively whimsical chatbots should be in the Geneva convention somewhere.
- ranger_danger 4mo agoYou agree that LLMs are good at making backronyms yet they still make you feel like a human was involved?
- kylehotchkiss 4mo agoWhy do we even need to run on the 20th century system of numbers anyways? Why is there not a better call addressing system?
- saxonww 4mo agoWe don't, but the entire world currently does, and the amount of equipment deployed that depends on it is substantial. I would be willing to bet money that any "better call addressing system" would be a design by committee where this just gets litigated there. And we'd end up with either a system that requires KYC per-call, or has compromises similar to what we're complaining about now.
- 3RTB297 4mo agoHaving worked with telco companies, 99% of it is "Yeah, but this stuff still works just fine;) And if a government compels us to change our equipment for reasons other than national security, we're going to pitch a fit and demand financial incentives beyond reason." A lot of the pressure to boot Huawei from tech stacks globally ran straight into that wall and flopped. Even with national security at its back. Considering most of those same telcos are donors and employers of large numbers of people across many constituencies of almost every nation, usually no politician has or is willing to spend political capital to shoot themselves in the foot like that. And no nation with a national telco company runs it well enough to ever even dream of spending money for something like IP addresses, they typically barely keep the lights on.
- 9cb14c1ec0 4mo agoBecause the concept of numbers is so heavily baked into many systems. Momentum is a beast.
- HappMacDonald 4mo agoI suppose you'd like to replace it with Email since that doesn't have any spam, hmm?
- 4mo ago
- hsbauauvhabzb 4mo agoWhat valid purpose does hidden numbers have? Government departments in my country hide their caller ID. I find that abusive on its own but let’s not forget about the fact that now you have victims of domestic violence being forced to answer hidden numbers in case it’s welfare, or the cops, or their abusive spouse.
- carlosjobim 4mo agoCalling in an anonymous tip to the police and such.
- rescbr 4mo agoI’d say to use a payphone if you need to do that, but then my age is showing, as this is not possible anymore.
- hsbauauvhabzb 4mo agoMy country has online anonymous tips online, and pay phones. I don’t think caller id blocking would work with the police, they almost certainly have the ability to unmask your number if they want.
- carlosjobim 4mo agoAnd why would they want to do that? The police relies on anonymous tips.
- hsbauauvhabzb 4mo agoBecause they almost certainly have fake tip-offs, they’re not going to ignore those.
- reactordev 4mo agoand cut off a million dollar annum laundering scheme to provide such service to the scammer networks? nah... they would never.
- singpolyma3 4mo agoThis is already not allowed. If your carrier accepts a spoofed call they're already violating FCC recommendations.
- kbelder 4mo agoRecommendations aren't requirements; you're allowed to violate them.
- singpolyma3 4mo agoOf course
- saintfire 4mo agoAnd yet, I incessantly get spoofed numbers calling me from the same "central office code". Also resulting in people with the same code "returning my calls" and then getting angry that I say I didn't call them. Preventing number spoofing would help significantly with spam calling. At least the ones from local numbers.
- cyanydeez 4mo agounfortunately, the grift economy is hyper-meritocratic: If you can figure out a scam and it makes money, who are we, as capitalists, to stop you? You take out the lower rungs of the grift economy, then whose to say who can fleece the tax payer with a repainting of a reflecting pool on tax payer's dime. It's a slippery slope, really.
- bryanlarsen 4mo agoMedical offices hide their numbers for very good reasons: if you've got an abusive spouse, you often don't want the medical office in your call history. Which results in a lot of very important calls being ignored.
- MichaelDickens 4mo agoUnless I'm missing something, this doesn't seem hard to fix: just let users decide whether hidden numbers should be ignored or received.
- bryanlarsen 4mo agoDoesn't that make it more likely people are going to miss important calls from their Doctor's office?
- chongli 4mo agoJust send the call to voicemail. Doctor's offices always leave voicemails. Spammers sometimes leave voicemails, sometimes not, either way they're easy to filter out / ignore.
- advisedwang 4mo agoStopping caller ID spoofing doesn't have to mean caller ID is always enabled. You should be able to make a call with NO caller id, but not a call with somebody else's caller id.