Signalling system 7 has no authentication. That's the bottom line. Adding authentication is pretty obviously not trivial, not just because of protocol upgrade issues, but also because end-to-end authen. won't be easy to add at all, and hop-by-hop authen. w/ something like "egress filtering" won't work in the age of phone number portability. What might work is a TCP-like return routability test. I.e., have the network…
Ask HN: How can scam callers fake a mobile phone number?
141–150 of 156 posts
Re: Ask HN: How can scam callers fake a mobile phone number?
#142Earlier quoted context omitted.
Out of curiosity - what do you mean by "Can't really leave a message" ?
Not the OP, but if you are a doctor and need to ring a relative or a friend to inform them about a very sick patient, leaving a message without the opportunity for at least brief interaction isn't something particularly pleasant for either party. ( You either leave too nonspecific information that not being sure what to do, or too much that potentially is breaching patient confidentiality or is going to panic the rec…
Re: Ask HN: How can scam callers fake a mobile phone number?
#143Earlier quoted context omitted.
I remember many years ago getting a random phone call from someone who claimed they were a detective investigating a case. The detective sensed my skepticism right away over the phone and suggested that I look up the phone number for his police department, and to ask for badge number ZZZ when I call. I called back, everything was above board, they came and interviewed me (they wanted to see if I still had something i…
You can't drop a story like that on us and not tell us what "the item" was ;)
Re: Ask HN: How can scam callers fake a mobile phone number?
#144It is actually incredibly easy! If you are using a voip line, it is just a configurable field in the UI. You can do it with any voip phone app (e.g. [1]) and a voip provider (e.g. [2]). I have an old archived video showing it here [3]. It is not so interesting though, just me poking around in a voip provider's UI. To address the other question about phone providers verifying stuff. SHAKEN/STIR [4] protocols are suppo…
It's ridiculous that phone companies allow this. Anyone wanting to set caller ID via voip should be forced to provide some sort of verification that the number is theirs and the phone company should not route it if it fails verification. We only have 3 major cell carriers here is Switzerland, it should be trivial for the 3 to verify each other's numbers to see if those customers even exist. Unlike the US each cell pr…
Re: Ask HN: How can scam callers fake a mobile phone number?
#145Earlier quoted context omitted.
I remember many years ago getting a random phone call from someone who claimed they were a detective investigating a case. The detective sensed my skepticism right away over the phone and suggested that I look up the phone number for his police department, and to ask for badge number ZZZ when I call. I called back, everything was above board, they came and interviewed me (they wanted to see if I still had something i…
All this could be faked, this could have been an elaborate scam.
Re: Ask HN: How can scam callers fake a mobile phone number?
#146Earlier quoted context omitted.
on iOS, the "Silence Unknown Callers" feature has completely eliminated this for me.
Canadian physician here: yeah, this is hell for us trying to reach patients through the hospital system, which is "unknown" by default. Straight to voicemail and you can't really leave a message. Totally agree though, this problem is very time consuming, if only for the time it takes me to look at my phone and decide not to answer the call - a few seconds of my life each time. My worst day was a few days ago; 7 calls…
Re: Ask HN: How can scam callers fake a mobile phone number?
#147The nice thing was, you could pass your phone number out to everyone, but it would only ring for the people you gave the code to. And it was easy to manage, just give your number as "555-1212 ext.382" or whatever. And if the code got spread too widely, you could just change it and give anyone you wanted to hear from the new code.
I keep hoping someone will make an app like that for cellular phones, but most people seem to like saving their spam calls in their voicemail boxes to review them later.
Re: Ask HN: How can scam callers fake a mobile phone number?
#148Earlier quoted context omitted.
The problem is that carriers (especially smaller ones) have been dragging their feet on implementing it, and nobody can use it to actually block calls until essentially everybody supports it and is interoperating. Until then, phones will just show calls between STIR/SHAKEN carriers as having verified caller ID.
would it be possible to tell my carrier to simply block all call that are not (STIR/SHAKEN)? If all my friend are on carrier that support it, I am not interested in receiving call from people that are not on a carrier that support it.
Re: Ask HN: How can scam callers fake a mobile phone number?
#149Re: Ask HN: How can scam callers fake a mobile phone number?
#150Earlier quoted context omitted.
That's a ridiculous system design.
It’s remnants from a time where security wasn’t a concern. The original intent of the From: field in email was that it’s definitive, but now it’s just a legacy field that many systems ignore because it’s fakeable.