5 ms·
The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telec
by DeepSeaTortoise 2mo ago
The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the call in question entered his own network from. The last cooperative network in the chain gets stuck with the fee, forcing them to either reclaim the money from the malicious customer, the next network in the chain (in court) or pony up the money themselves.
Result: All routes to non-cooperating networks get dropped within days to weeks and scam-calling stops being a lucrative business basically instantly.
- verall 2mo agoA lot of scams unfortunately operate right on the line of legality like the car warranty morons
- cj 2mo agoSure, but that's okay because you don't need 100% of spam calls to be recognized as spam for the incentive to do its job. The system still sounds like it could still work even if a large percent of calls weren't flagged.
- orbital-decay 2mo agoThis works both ways, if the detection rate is low then nobody would press a "lose $10" button.
- bckr 2mo agoI think we have to do something this extreme. We have to give the system a total makeover. Somehow we also have to keep it from being fully centralized and have the big brother problem on the other side. Unfortunately these two goals are difficult to get through at the same time, with the system that we have.
- ssalka 2mo agoCue the crypto bros touting their decentralized spam-detection blockchain
- giancarlostoro 2mo agoIf major states like California and New York pass it, and spam basically dies in those states, it wouldn't surprise me if it spreads across the country.
- pixl97 2mo agoAssuming the nature of the spam and how it makes money.
- LorenPechtel 2mo agoThey are impossible. You can't make a system that can force bad actors off the system that can't also be used to force politically undesirable actors off the system.
- dredmorbius 2mo agoThat's pretty much the proposal I've made for some years.[1] California has introduced bonding to telemarketing firms specifically. I feel that should apply at the carrier level, where networks carry a guaranteed bond, pay regular premiums on it, and are dinged for unwanted calls, with the proceeds being split among the called party and any third-party network(s) traversed by the calls. Downstream networks could seek compensation from ANY upstream network carrying the traffic regardless of whether or not they originated it. This would both create a penalty for providing, or transiting, unsolicited calls, AND create an incentive for carriers / network providers themselves to pursue unsolicited traffic from their peers. <https://oag.ca.gov/consumers/general/telreg https://oag.ca.gov/consumers/general/telreg> ________________________________ Notes: 1. See for example <https://toot.cat/@dredmorbius/111099306069523624 https://toot.cat/@dredmorbius/111099306069523624>
- inigyou 2mo agoDo you really want the network to be so locked down you can't get access to it?
- dredmorbius 2mo agoHow do you reach that conclusion based on what I've written?
- inigyou 2mo agoBecause it happened to everything else where this idea was tried.
- dredmorbius 2mo agoIn other words: nothing to do with what I'd written. And no specific instances or mechanisms detailed, to boot. Thanks.
- inigyou 2mo ago
- pessimizer 2mo agoI spent a little time unsuccessfully looking for a reference, but in some ancient Greek and early Roman governments, newly elected officials who were in charge of money were required to personally indemnify (become responsible for the professional liabilities of) their predecessor. If your predecessor committed fraud, you were 100% personally responsible for it. You would then gather the evidence and sue your predecessor for your losses.
- giancarlostoro 2mo agoHow does your predecessor today have those funds? The problem is politicians get to "play" with wealth beyond their own reaches (typically).
- Luc 2mo agoThat sounds like a great way to attract scammers and dissuade honest people, so if it's ever been tried it must have failed spectacularly (I also searched for variations of this idea but didn't turn up anything).
- bluGill 2mo agoIt probably worked for Romans because the taxes you were allowed to collect was so much more than you had to send back to Rome that you could get rich 'honestly'. That and you had options to prove the fraud that meant the other was unlikely to try.
- amazingamazing 2mo agoI don’t understand how this works. Suppose someone calls you about some political poll and you hit the button, would it count or not? What about a cold email (there was another such thread about cold emails being praised, i said fundamentally is spam but was downvoted lol).
- dmitrygr 2mo agoSimpler yet: require every call to come with a physical source address, huge (and enforced) jail times for faking it. Let the internet and the pissed callees crowdsource the rest
- hutattedonmyarm 2mo agoThis would be an enormous invasion of privacy. Other countries have a lot less issues with spam calls without these measures
- inigyou 2mo agoOther countries have this rule, actually. At least most of Europe records your passport and address.
- orbital-decay 2mo agoInfeasible. Fraud or spam is usually pretty hard to confirm from one recording without additional context. Many scammers have plausible deniability or are just checking whether the number is active. Moreover, this solution would involve secret non-consensual recording; what if it's not a scam?
- ryandrake 2mo agoPlus, who is ‘confirming’ the spam? The same entity (or group: carriers) that is keeping the $10 and paying the $100 out? That just means the result will always be ‘not spam.’
- dredmorbius 2mo agoThis is why fees should be structured such that all carriers are on the hook, but upstream carriers inherit the obligation, possibly with an increased liability per hop, implying that downstream carriers can utilise enforcement as a profit rather than cost centre. Scenario: - Spamford places an unsolicited call to subscriber Alice initiating from MalTelCo, transiting carrier hops BunnTel1 and BunnTel2, to Alice's telco carrier, EndTelCo. - Carriers MalTelCo, BunnTel1, BunnTel2,[1] and EndTelCo have all placed surety bonds, held by BondCo, to practice telephony operations within the jurisdiction (regional/national). The carriers are the Principals, BondCo is the Surety, and receiving subscribers (or telcos, see below) are the Obligees.[2] - Unbonded carriers may have their traffic refused by peers. Peering to an unbonded carrier places the bond obligation on the receiving carrier. - Alice flags the call as spam. A per-call surety of $100 is paid to Alice, and charged to EndTelCo against its BondCo contract. As an additional option the call may be flagged as fraud through the phone system, in which case it is automatically referred to LEO by EndTelCo. Obligation of surety is independent of any fraud finding and is based SOLELY on the unsolicited nature of the call. - EndTelCo has the option of 1) eating the charge or 2) filing a claim against its peer, BunnTel2, the 2nd hop in the chain, which EndTelCo does. - BunnTel1 similarly files a claim on BunnTel2. - BunnTel2 files a claim on MalTelCo. - MalTelCo now eats the claim (it's paid out by BondCo). MalTelCo may seek further compensation from Spamford, but that's Out Of Scope of the bonding / surety schema, and would be covered by MalTelCo's own terms of use. - BondCo assesses risks and adjusts its surety rates correspondingly based on observed behaviours (and financial risks) of EndTelCo, BunnTel1, BunnTel2, and MalTelCo. If risks are excessive and no surety can be issued, MalTelCo is unbonded, and hence, decertified. Peers may now refuse traffic without penalty. Note that no one carrier needs to know anything more about a call's routing than its own network boundary. If EndTelCo has no idea that BunnTel2 and MalTelCo were involved, it doesn't matter, because BunnTel1 is on the hook for passing on the call. Spoofing or falsifying records doesn't save you. There are some questions over how this might be implemented, though generally: - If Spamford and Alice are both subscribers to EndTelCo, then EndTelCo eats the surety, which is paid to Alice. There's no upstream. Moral: Telcos, don't spam your own customers. - One thought is that the surety is split among telcos and the subscriber. Rather than just facing a potential cost, transiting and reciving-end-point carriers could see revenue by tracking and prosecuting unsolicited calls. This could include calls received by monitoring numbers set up strictly to assess unsolicited call activity directed to the network. This would mean that calls transiting multiple carriers would be subject to compounded surety claims ... and ... I think I'm OK with that. - There would all but certainly be classes of calls which would be exempted from claims. Those should be very limited, preferably to government and specifically qualified emergency services only. No political exemptions, no non-profit / NGO exemptions. - How often claims are settled and risks re-assessed is open for discussion. Daily might be too often, weekly or monthly seems most likely. Longer than that gives too much free-run for malevolent actors to operate. ________________________________ Notes: 1. "BunnTel", because bunnies hop. 2. For an overview of surety bonds, see <https://www.suretybondsdirect.com/educate/what-is-surety-bond https://www.suretybondsdirect.com/educate/what-is-surety-bon...>.
- edoceo 2mo agoHow are they listening to a few minutes before the button? A "temporary" recording of the first 2 minutes of every call? I feel like there would be some privacy concerns.
- namibj 2mo agoIt'd suffice for them to sign the transmitted information (audio and required timing metadata for the packet stream) and make you do the temporary recording on your side, transmitting it back to the provider once you hit the button, to let them handle the backup/safekeeping aspects for you.
- LorenPechtel 2mo agoRecording into the recent past is quite common. You implement it by storing the data *to memory only* until the trigger event happens, then you write out what's currently in memory. It's a common feature in better dashcams--you get say the 30 seconds before the thump that triggered it. Likewise, many high speed cameras that record some short action. They're actually always running, but dumping the end of the data, they only "record" when the trigger happens.
- flatline 2mo agoUnscrupulous operators will just run up huge liabilities and close up shop by the time they can be identified and dragged into court, meanwhile having started another similar operation under a different name. That's basically already what's happening, and the speed differential between the technology and the law will be forever in their favor.
- pavel_lishin 2mo agoThe idea is that telecoms would be on the hook for these folks' behavior; they'd be incentivized to scrutinize them more thoroughly.
- dredmorbius 2mo agoWhich is why bonding is applied, as with other high-risk ventures. The bonding agent (the Surety) sets the bond rate based on the perceived risk of the venture. Unbonded ventures are not permitted to operate. In a telco context, unbonded carriers would not be peered to other carriers. Overview of how surety bonds work: <https://www.suretybondsdirect.com/educate/what-is-surety-bond https://www.suretybondsdirect.com/educate/what-is-surety-bon...>. California's present regulation: <https://oag.ca.gov/consumers/general/telreg https://oag.ca.gov/consumers/general/telreg>
- RobRivera 2mo agoOddly specific with the dollar ounts, but I like the general idea.
- bennettnate5 2mo agoSounds like a great way to strongly incentivize a new form of fraud--fraud-reporting fraud! Imagine how much fraudsters could gain by reporting thousands or tens of thousands of "fraud" calls that they themselves both originate and report from existing SIM farm infrastructure. Any deployment weakness or hole in blocking malicious traffic in the global telecommunications network all of the sudden becomes akin to a weak smart contract that is ripe for exploitation on the order of millions of dollars of fines until it is patched, all due to this depositing requirement.
- DeepSeaTortoise 2mo agoYou're assuming the telecom operator of the SIM farm doesn't know his customers. That'll change very quickly after the first few have to cover the fines themselves. After that that scam would result in the scammer paying the (e.g.) $10 upfront, the (up to; e.g.) 10% for every hop between networks and likely and transaction, processing and legal fees for the civil case (if he's not cooperating). And he'll likely end up with criminal charges on top of that. Also it's not like the scammer gets sued by some powerless private citizen authorities are likely to ignore. His opponent will be a telecom provider in his own jurisdiction.
- gwbas1c 2mo agoI think a much better solution is to get rid of phone numbers (and email addresses), and instead only allow incoming phone calls, texts, email, ect, from people and companies you know. "Cold calling" can either come from governmental organizations (IE, call from the police), or someone or some organization in your network can grant access to call, text, email, ect on their behalf. The result is that SPAM has a chain of traceability, so you can then block people and organizations in your network who make unwanted calls. Furthermore, regulation is needed so that your cable company can't pull dumb nonsense like saying "telemarking is required to use our service": This is where the SPAM button that you propose really comes in handy, because it holds accountable the fools who think that selling their customers' contact information is a good idea.