7 ms·
Anti-fraud tools can't keep pace with robocall scammers
- etchalon 2mo agoI genuinely don't understand why this is so hard to tackle. Phone numbers are a scare resource and the telecommunications networks heavily regulated with numerous central points of control. This bullshit is scaling because the companies which gate and sell that access have no obligations, legal or otherwise, to deny scammers access to their resources.
- ipython 2mo agoOne word: incentives. You're absolutely right- and telecom networks get us on both sides. They collect fees from the scammers, then fees from customers to block the scammers. Can't get any better than that.
- ozim 2mo agoso penalties for telcos have to be higher than they earn from scam calls. 2-5% of scams succeed but penalty should be there accounting for 95-98% that did not succeed. IANAL but I know failed attempt at robbery or murder is also prosecuted, failed attempts at scam are not, because people just hang up and move on. Then the reality is society doesn’t have enough resources to deal with "scam attempts" - well we have to focus on murder attempts an plain robbery
- inigyou 2mo agoI don't think we want telcos to block scam calls themselves. We want them to be forced to give the subscriber's actual address to the police.
- dredmorbius 2mo agoWhy not? And why would you impose a highly-intrusive personal-tracking system across billions of subscribers?
- inigyou 2mo agoBecause I don't want some stupid AI system to randomly decide I'm a spam caller. And you know every other country has full KYC for phone connections, right?
- dredmorbius 2mo agoWhat would be a sufficient appeals process or remedy action that might address your concern? What activities are you engaged in which make you think you'd likely be considered a spammer? What specific harms do you see occurring? Might these be related to your present line of business / profession / employment?
- inigyou 2mo agoSure, if someone gave me a false phone number to call them on, I could be declared a spammer. If I had to call more than 3 people a day ordinarily, I could be declared a spammer. I'm basing these on what already happens in the banking sector as a direct result of the regulation you want.
- dredmorbius 2mo agoWhat would be a sufficient appeals process or remedy action that might address your concern? What activities are you engaged in which make you think you'd likely be considered a spammer? What specific harms do you see occurring? Might these be related to your present line of business / profession / employment?
- inigyou 2mo agoYou have just copy-pasted your previous comment. That is a form of spam, and I'm flagging it as such.
- etchalon 2mo agoThey don't to block scam calls. They can easily limit who gets access to make them, making the resource itself precious enough no one would risk wasting it on a dial scam.
- mook 2mo agoI was under the impression that SHAKEN / STIR was supposed to do that by authenticating the phone numbers displayed against the telco that made the call. But as the other comment says, your telco earns money from scam calls and they don't want that to stop.
- dredmorbius 2mo agoIdentification is insufficient without accountability. SHAKEN/STIR identifies whether or not a given number is originating from a specific network, but without knowing whether that's an approved network, rejecting unapproved-origin calls, or tracking how much unapproved traffic a given network is emitting and penalising it for this, the information isn't actionable. "Measure it harder" doesn't solve problems. The information must direct meaningful action.
- inigyou 2mo agoSHAKEN/STIR has a loophole for calls passing through legacy trunks that don't support it. So now certain carriers made a business model off of routing your scam calls through those trunks so they won't have to be verified.
- dredmorbius 2mo agoWhich is why we turn originating / sourcing / routing calls into a risk. See: <https://news.ycombinator.com/item?id=49130932 https://news.ycombinator.com/item?id=49130932> There's a related issue apparently of small operators who can't afford (or haven't been bothered) to implement STIR/SHAKEN. Many of these are apparently small rural phone co-ops (its own interesting bit of telecoms history). There should be both support in providing them with such capabilities, and penalties for failing to do so, including liability for transiting spam calls to their own or other carriers' subscribers.
- inigyou 2mo agoWell then phone companies will stop originating/routing/sourcing calls. Do you want that? Your idea has been implemented for banks already, and the result is that machine learning algorithms randomly block transactions and close people's accounts for no reason.
- mannanj 2mo agoI think making noise is cheaper than reducing it. And I think this is also a problem at the habit/behavior level for people. Most people don't want to know how to set proper boundaries with people and technology and articulate what they want. Once you do that at least you can articulate what you want to come in at you or not. Without that you get stuck with a weird one-size-fits-all policy which definitely doesn't fit for me at least.
- otterpro 2mo agoI no longer can answer my phone. I get at least 20-40 spam/scam calls per day, and many are legitimate companies calling for loans and refinancing offers, which started after I got a home loan. I cannot seem to stop them from calling, and even though my phone number is listed in National Do Not Call Registry for many years, it hasn't worked at all. The only relief is that on my iPhone, I was able to block all calls not found in my contacts (ie whitelist phone numbers only). Now, my only worry is that I might get a call from someone who I need to talk to, but is blocked and I won't even know it. For example, what if I get an emergency call from police/fire/hospital and I won't even know it. I also tried using "Screen unknown caller" feature, but then, no one likes them and sometimes they think it is AI bot and they usually just hang up (which is great for spam caller but not for legitimate caller) My only solution that I could think of is to have a dedicated phone line just for friends/family/work, and a second line for banking/shopping/utilities/everything else.
- mannanj 2mo ago[dead]
- Hikikomori 2mo agoLive in Europe, last time I got a spam call 4-5 years ago it was my ISP asking of I wanted to add tv to my internet. Told them not to call me again and they didn't.
- victorbjorklund 2mo agoI live in Europe and I get scam calls and sales calls. Yes, legit companies spam call less in Europe due to regulation but scammers committing crimes don’t care about privacy laws etc it’s their least problems
- Hikikomori 2mo agoDont get those either, maybe just an outlier but GF don't get them either.
- stalfosknight 2mo agoT-Mobile’s Scam Shield works really well for me. But you have to get the premium tier.
- ipython 2mo agoFunny, the same telecoms that whine about how hard this traffic is to stop... are also selling a "premium" service to customers- who then manually tag unwanted calls so that the telecom can sell that data back to other customers...
- dhosek 2mo agoI don’t seem to be charged for Scam Shield on my account. I’ve had one unknown number call and not leave a message over the last month, which is a far cry from the 20–40 spam calls per day some people report.
- dredmorbius 2mo agoThere are both free and premium tiers: <https://www.t-mobile.com/benefits/scam-shield https://www.t-mobile.com/benefits/scam-shield> The free tier seems to identify but not block likely scam calls. T-Mobile's website skews sales-heavy, and doesn't feature much technical information. The premium features appear to be app-dependent, and may not work on feature phones.
- dredmorbius 2mo agoUnsurprisingly: telcos sell outbound dialing capabilities to business customers. For spam mitigations to work, the cost of selling that business must exceed its revenue. Some, and I won't mention AT&T by name, are very curiously opposed to any regulations touching this.
- dredmorbius 2mo agoThere are a number of options. My view is that carrier-based filtering (rather than on-device filters) are where effort must be focused. Much as we learned with email: if you're routing traffic for many people, mass-contact attempts and patterns become quickly visible. Individuals see only a minuscule fraction of traffic, networks see overall patterns. The other element is that carriers can act at the network level, noting how much abusive traffic arrives from given peers, and taking direct action against those peers. That could involve rejecting traffic outright, subjecting it to stronger challenges, and/or diverting it to investigative / law-enforcement bodies (I'd suggest both national and state entities) for both tracking and enforcement. Power-law relations mean that at any given time, a small number of networks will account for the overwhelming majority of spam, though which networks will likely change over time. The key problem with this is getting the carriers to act, which ... will probably involve a few carrots and sticks. I'll address those in another comment, except to mention bonding: <https://oag.ca.gov/consumers/general/telreg https://oag.ca.gov/consumers/general/telreg>.[1] Individual action will not solve this problem, but there are steps you can take. Most major US carriers now offer some form of robocall blocking. "Scam Shield" from T-Mobile, "ActiveArmor" from AT&T, "Call Filter" from Verizon. MVNOs (mobile virtual network operators) may or may not offer scam / robocall blocking themselves (though IMO they should, and should be required to). Some will identify spam calls, but those are still passed through to your handset. Beyond this, there are on-device apps which can be used, some are carrier-based (e.g., "Call Filter Plus", from Verizon, similar tools exist for Verizon and AT&T), some are third-party. These of necessity share your voice/text activity with third parties, which is its own concern and consideration. Full Android, iOS, and several full-featured Android alternatives (GrapheneOS, /e/OS, LineageOS, etc.) offer unknown caller rejection. Numbers not in your contact list are directed to voicemail. At present, few spam calls will leave voicemail, though some do, and as AI expands in capabilities, applications, and adoption this will all but certainly increase. I'd strongly encourage use of this. Feature phones / dumbphones ... have far less capability. Most cannot even reject unknown numbers, which ... seems a ripe target for legislation and/or regulation. Phone frameworks such as AOSP / KaiOS seem to afford little capability for even creating a call-blocking app. This and other dumb devices (e.g., traditional landlines) are a strong argument for carrier/network level mitigations. The company everyone loves to hate, Comcast/Xfinity, actually has one of the most sophisticated voice/text spam blocking systems, and one I'd like to see mandated to all carriers: <https://www.xfinity.com/support/articles/spam-blocker-overview https://www.xfinity.com/support/articles/spam-blocker-overvi...> It's risk based. It classifies calls into three categories: high, medium, and low risk. It adjudicates calls based on risk. High-risk calls are terminated entirely. Medium-risk calls are directed to voicemail. Low-risk calls are subjected to an audio CAPTCHA (enter a two digit value to ring through), otherwise are directed to voicemail. (It's not clear whether or not a whitelisted number will escape any treatment, perhaps subject to conditions such as originating from the appropriate/approved network for that call.) I haven't used that system, but in advising people still moving off landlines, or looking at VOIP solutions, it's making Comcast an attractive option. (I don't know what other VOIP providers, say, Twillo or Asterisk, offer, but suspect at least some have similar if not more-capable systems.) ________________________________ Notes: 1. California requires a $100,000 bond by all telemarketers in the state. The state has a small fraction of the incidence of robocalls of the worst US states. Several others have some bond. My view is that bonding should apply at the carrier level and be surrenderable to both contacted individuals and downstream peering networks, to provide both a strong financial penalty to abusers, and an incentive to downstream networks to pursue abusive calls.
- orev 2mo agoOne of the biggest concerns I have with phone scams is that the people most vulnerable are the elderly, and they don’t have the knowledge on how to block these calls (if a technical solution is the only option). And further to that, the elderly are also the ones who cannot block unknown numbers, because doctors’ offices seem to have random numbers they call you from (they may have a pool of numbers but it’s not reasonable to add all of them to contacts). Blocking all unknowns would block these important health related calls as well.
- dredmorbius 2mo agoAARP's magazine and bulletin[1] are pretty much filled with scam-awareness articles every issue. It's an absolutely major concern. ________________________________ Notes: 1. Incidentally, the first and second largest-circulation magazines in the US now: <https://www.magazineline.com/blog/most-popular-magazines-in-the-us https://www.magazineline.com/blog/most-popular-magazines-in-...>.
- pixl97 2mo agoIt being a major concern doesn't mean there's any solution around said concerns. Give me 100 old peoples phone numbers and I bet I could convince 10 of them that I am AARP trying to make them safe and eventually get money out of them.
- thewebguyd 2mo ago> because doctors’ offices seem to have random numbers they call you from This is a huge issue with scam/security awareness education. Too many legitimate orgs use the exact behaviors we tell people to avoid. Same thing with email, can't tell someone to never click links in emails when services keep relying on magic links, third-party notification domains, etc. SPF, DKIM, and DMARC do nothing because scammers will just typosquat. In the phone number example, most of those numbers too are unlisted outbound numbers, you couldn't even google them to verify. Half the battle is getting legitimate organizations to stop acting like scammers in the first place so that shady behavior becomes an obvious red flag again.
- DeepSeaTortoise 2mo agoThe solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the call in question entered his own network from. The last cooperative network in the chain gets stuck with the fee, forcing them to either reclaim the money from the malicious customer, the next network in the chain (in court) or pony up the money themselves. Result: All routes to non-cooperating networks get dropped within days to weeks and scam-calling stops being a lucrative business basically instantly.
- verall 2mo agoA lot of scams unfortunately operate right on the line of legality like the car warranty morons
- cj 2mo agoSure, but that's okay because you don't need 100% of spam calls to be recognized as spam for the incentive to do its job. The system still sounds like it could still work even if a large percent of calls weren't flagged.
- orbital-decay 2mo agoThis works both ways, if the detection rate is low then nobody would press a "lose $10" button.
- bckr 2mo agoI think we have to do something this extreme. We have to give the system a total makeover. Somehow we also have to keep it from being fully centralized and have the big brother problem on the other side. Unfortunately these two goals are difficult to get through at the same time, with the system that we have.
- LocalH 2mo agoCommerce should never have been made possible to happen on the internet. The moment it became possible to send and receive money through the internet, the end times began.
- dredmorbius 2mo agoOr phones, or telegraph, or mail, or roads, or ... Commerce and crime go hand-in-hand. The Greek and Roman gods of travel and communication were also the gods of tricksters (frauds) and thieves. The etymology of "Mercury" may be related to that of "merchant". (Hermes rather less so.) <https://en.wikipedia.org/wiki/Mercury_(mythology) https://en.wikipedia.org/wiki/Mercury_(mythology)>
- sdenton4 2mo agoI got an obviously-AI voice agent spam call yesterday. Had a bit of fun getting it to answer trivia questions (when was the treaty of westphalia ratified? answer in a rhyming couplet) as a precondition to handing over the keys to my bank accounts.
- nojs 2mo agoPerhaps the future of captcha is anti-captcha. What agent can resist responding with a rhyming couplet or inverting a binary tree?
- ozim 2mo agoDownside is they most likely are using stolen tokens, not paying themselves so it cost them next to nothing.
- pixl97 2mo agoRegardless, this forces them to steal more tokens. Any token wasted not getting money reduces the efficiency of the scam. The end goal would be increasing the token expenditure above the amount they scam from people.
- dpkirchner 2mo agoAnd recording your voice for fine tuning models they could then use to trick your friends/family/banks.
- dredmorbius 2mo agoAn ask: I'm trying to find out where substantive discussion by carriers AND other parties on mitigating phone spam (voice or text) is occurring. I'd very much appreciate replies here, email (see my profile), or hop on this Fediverse thread: <https://toot.cat/@dredmorbius/116984051310517623 https://toot.cat/@dredmorbius/116984051310517623> Broadband Breakfast does seem to be one of those entities. ATIS (<https://atis.org/ https://atis.org/>) is another, though as a telco alliance I consider it highly suss. (Submitter.)
- shadowtree 2mo agoHi - we're doing tree removal in your area. Call us back at 1-800-SCAM Cheap messaging is as annoying now as calling. Ruining the phone experience overall. Soon Apple will have to do something.
- f1ay 2mo agodontscamgrandma.com is probably apropos to share here for the elderly / vulnerable affected by scam proliferation. It's a trainer that roleplays people through getting the confidence to hang up and call their loved ones back. Full disclosure I'm the founder, and I've got a couple dogs in this fight
- bickfordb 2mo agoMaybe this is a pipe dream, but wouldn't it be better to retire the legacy phone voice and messaging system altogether. If 99.9% of us have internet phones, why aren't we using PKI, decentralized protocols, crowd sourced reputation to communicate instead of POTS phone numbers, SMS/iChat and relying on the carriers to police spam.
- tacocataco 2mo agoRedundancy in case of natural disasters.
- dredmorbius 2mo agoThe traditional (POTS-based, circuit-switched, fully-analogue system) has largely been retired. Even where existing POTS twisted-pair service exists, it's generally VOIP until the last few hundred metres, if that. In much of the US, the push is on to retire the last twisted pair within a very few years, if not months. Utilisation rates are well into the single-digits and falling, which makes continued support quite expensive. The problem for many holdouts is that alternatives fail to deliver reliability, or the equivalent of a site-centred service (as opposed to personal mobile devices). Residential VOIP is confusing from the subscriber's perspective, and the telcos aren't making choosing options much easier. SMS itself is highly problematic, as it's grossly insecure, unreliable, and very subject to surveillance and other abuse. Secure chat alternatives tend to be proprietary (e.g., RCS, effectively specific to Apple and Google, see: <https://en.wikipedia.org/wiki/Rich_Communication_Services https://en.wikipedia.org/wiki/Rich_Communication_Services>), or aren't supported on all devices (Signal would be excellent, but isn't supported on most Feature Phone / Dumbphone OSes, such as KaiOS/AOSP). And Signal too is ultimately a single provider.
- SoftTalker 2mo agoIs this a USA problem, or world-wide? If other countries don't have such a problem, why not?
- bluGill 2mo agoWorldwide. It doesn't affect everyone equally though so some in each county are not having a problem while others are swamped with garbage.
- nicbou 2mo agoI get spam calls in Germany, but it's maybe two dozen a year in random bursts.
- alightsoul 2mo agoBecause the US market is very lucrative. In other countries they aren't calls, they're WhatsApp messages just asking for money. Sometimes they somehow hack into people's WhatsApp accounts and then ask their friends for money.
- inigyou 2mo agoPervasive KYC.
- dredmorbius 2mo agoIt seems to be much worse in the US for now, though why is the subject of a great deal of speculation. There's not much publicly-available research on the topic. One better source I've found is "Robocalls: A Worldwide or US-only Problem? Analyzing Spam and Fraud in International Phone Calls" (30 Jun 2026) <https://arxiv.org/html/2606.31790 https://arxiv.org/html/2606.31790> On the magnitude in the US vs. elsewhere: Even though robocalls are an international problem, our findings indicate that US citizens are substantially more affected than the rest of the world. The median number of phone numbers in our US honeypot was 11 751, compared to 101 913 international phone numbers. Despite an almost tenfold difference in the number of available phone lines, the US honeypot numbers received 8 314 813 calls (95.1%) compared to 432 538 calls (4.9%) received by the international numbers. On average, a single phone number in our US honeypot received 707.5 calls during a nine-month period, about 2.62 calls per day. Non-US numbers received, on average 4.24 calls during the same period, about 0.016 calls per day. The paper does not break out calls per person by country, though it discusses general patterns. Hiya has an accessible report which highlights "seven key countries", with calls per month in parenthesis: The US (22), UK (5), Canada (6), Spain (13), France (18), Germany (3), and Brazil (29, highest in the world). Americas: Brazil (29), Mexico (26), Chile (23), and the US (22) lead. In Asia: HK (23), Indonesia (16), the Philippines (12), and India (8) lead. <https://work.hiya.com/hubfs/2025/Global%20Call%20Threat%20Report_2025Q2.pdf https://work.hiya.com/hubfs/2025/Global%20Call%20Threat%20Re...>
- alex1138 2mo agoI get messages (and often don't answer my phone; my ringer is off) in which it's obviously this automated thing but they immediately dock it down to "press 1 if..." 'Kay. So you call people and just clearly have a tone the second you hear a voice which could well be someone's answering machine (Of course most of it would be automated, I guess) Special place in hell for these people
- cindyllm 2mo ago[dead]
- Razengan 2mo agoWhy are phones still so fucking far behind in the dark ages?? Instant messaging solved all this shit 700 years ago! Let each number act as an "account" on the phone network/company, just like IM accounts, each with its list of contacts, and blocked numbers. Shove incoming calls into "Strangers" with low-annoyance notifications (ringtones) by default unless they're from a "verified" company etc. Oh and yeah as others said, a "Report Abuse" button.
- josh-wrale 2mo agoAllow list for phone numbers. All else goes to VM. Job done.
- ogou 2mo agoMy Google Voice number got 37 calls from the same region in the past 2 days. All day, about every 50 minutes, rotating different 404 based numbers. It happens about twice a year from this area code (404). I know exactly where it is from. I had to park in Atlanta once and it required me to create an account on an app for that parking lot to pay. Of course I used my Google number. That service must have transferred or sold my number. Now my account gets bombed by them on a regular basis.
- timoth3y 2mo agoThis is actually an easily solvable problem. In fact, most of the world has already solved it by not allowing caller-ID spoofing and by blocking bad actors similar to the way that ISPs block email coming from known bad IPs. The US has the STIR/SHAKEN authentication protocols, but the telcos seem to have no financial are regulatory pressure to clamp down on all the sketchy intermediate carriers the scammers use to bypass them. Rather then actually solve the problem, the US prefers to turn it into a business opportunity with the telcos selling subscriptions to blocking software and an entire ecosystem of moderately effective apps.
- inigyou 2mo agoThis must be why every country is locking down the phone network. KYC or you don't get connected. You get a spam call? Good, caller ID is authenticated so it's easy for the police to find out who called you.
- TimBurman 2mo agoI've been using the Android app SpamBlocker off F-Droid for several years to block unwanted calls and SMS. It blocks entire area codes, individual numbers, names and any pattern using regular expressions. It can silence, pickup and hangup or just send to VM. The developer has a github page and has provided many updates. https://f-droid.org/en/packages/spam.blocker/ https://f-droid.org/en/packages/spam.blocker/
- dredmorbius 2mo agoThis rehashes much of the experience fighting email spam in the late 1990s / early aughts. Initially the approach was a long list of rules, usually a whitelist and blacklist of known good and bad contacts, and then a large set of specific patterns and assigned weights. Procmail was an early standard here, later Spamassassin. The biggest revolution came with Bayesian classification. YCombinator's Paul Graham (@pg) developed one such system. The idea here was that a small set of mail was classified into two categories, spam (unwanted) and ham (wanted), and the classifier went looking for patterns within each corpus, automatically assigning weights. This took much of the guesswork and assumptions out of the process, but still relied on contextual clues within the mail itself, though both data (the message payload) and metadata (email headers) could be used. Following that were reputation-based systems, generally looking at domains or IP address space, where a sufficiently large-scale survey of mail patterns, initially based on honeypots, later largely conducted by large email providers themselves such as AOL, Yahoo, Hotmail, (this was the aughts, they still existed), and eventually Gmail and a few others. Senderbase/Ironport (later bought by Cisco) were another major contender here. These approaches strongly leveraged power-law relations, in which a small number of origins (IPs, CIDR blocks, ASNs) account for the vast majority of email spam. Generally: poor network hygiene practices, whether intentional or otherwise, show, and are actionable by peers / others. Google especially, through Gmail, had access to a phenomenal amount of activity, and could detect both datacenter-based bulk mailing activity and residential proxy campaigns. Effectively its Gmail service serves as a huge, distributed, collection observatory, and can respond to new spam campaigns incredibly quickly. I don't have specific insights, but suspect that response times are measured in minutes if not seconds. Google of course also has insight to the contents of emails, but network- and header-level adjudication is much faster, cheaper, and surprisingly effective. This is why I'm strongly advocating carrier-based, network-level phone-spam mitigations, and whatever regulatory changes are necessary to incentivise providers to adopt these. On-device apps are fine, so far as they go, but would best work in concert with network-level countermeasures.
- crawfordmarch 2mo ago[flagged]