Live data from Hacker News

FCC fines robocaller record $120M

techcrunch.com

1–10 of 175 posts

Re: FCC fines robocaller record $120M

#3
The real problem is the lack of security and authentication on telephone networks, which enables number spoofing with virtually no chance of reprisal -- foreign callers (realistically out of the FCC's jurisdiction) use VoIP services to create calls that originate from an IP address from the telephone network's perspective, and the phone network makes no attempt to authenticate the metadata (like the phone number that is calling) before forwarding it on.

The 'neighborhood scam' is one which I am frequently subject to, and there is virtually nothing I can do about it (except block all the numbers with the same prefix as my own, but even this only covers the cases where they restrict their spoofed numbers to that small range).

Domestic callers like the one described in this article seem like a very small part of the problem, since they can be tracked and prosecuted. Foreign callers never pay the penalty with our current system, and I suspect they are more numerous based on the accents of most robocall operators I've gotten on the line.

Re: FCC fines robocaller record $120M

#5
post #3

The real problem is the lack of security and authentication on telephone networks, which enables number spoofing with virtually no chance of reprisal -- foreign callers (realistically out of the FCC's jurisdiction) use VoIP services to create calls that originate from an IP address from the telephone network's perspective, and the phone network makes no attempt to authenticate the metadata (like the phone number that…

I've suggested in the past that every instance of provable spoofing where they did not control the claimed number should result in a fixed fine. $100 sounds about right.

Every phone network will then quickly begin passing on that cost to anyone they "peer" with and it will be a non-issue soon enough.

Is there a compelling reason to allow such spoofs?

Re: FCC fines robocaller record $120M

#6
> a technology designed to prevent robocalls altogether, recommended in a report more than a year ago and currently set to be implemented in Canada in 2019, has no such date here in the States.

What’s the technology?

Edit: https://transnexus.com/solutions/stir-and-shaken/stir-and-sh...

”STIR and SHAKEN use digital certificates, based on common public key cryptography techniques, to ensure the calling number of a telephone call is secure. Each telephone service provider obtains their digital certificate from a certificate authority who is a trusted authority. The certificate technology enables the called party to verify that the calling number is accurate and has not been spoofed.”

Re: FCC fines robocaller record $120M

#7
post #5
post #3

The real problem is the lack of security and authentication on telephone networks, which enables number spoofing with virtually no chance of reprisal -- foreign callers (realistically out of the FCC's jurisdiction) use VoIP services to create calls that originate from an IP address from the telephone network's perspective, and the phone network makes no attempt to authenticate the metadata (like the phone number that…

I've suggested in the past that every instance of provable spoofing where they did not control the claimed number should result in a fixed fine. $100 sounds about right. Every phone network will then quickly begin passing on that cost to anyone they "peer" with and it will be a non-issue soon enough. Is there a compelling reason to allow such spoofs?

> Is there a compelling reason to allow such spoofs?

It makes telcos money. That's reason enough, since there are no economic downsides to the network operators that enable these crimes. If companies like AT&T and Verizon were also being subject to this $120M fine, we might see them decide to make caller ID trustworthy so that it could be used to block robocalls.

Re: FCC fines robocaller record $120M

#8
post #5
post #3

The real problem is the lack of security and authentication on telephone networks, which enables number spoofing with virtually no chance of reprisal -- foreign callers (realistically out of the FCC's jurisdiction) use VoIP services to create calls that originate from an IP address from the telephone network's perspective, and the phone network makes no attempt to authenticate the metadata (like the phone number that…

I've suggested in the past that every instance of provable spoofing where they did not control the claimed number should result in a fixed fine. $100 sounds about right. Every phone network will then quickly begin passing on that cost to anyone they "peer" with and it will be a non-issue soon enough. Is there a compelling reason to allow such spoofs?

>Is there a compelling reason to allow such spoofs?

A few use cases to spoof the number:

* Appointment reminder systems - if I see the caller ID is from my doctor's office, I'm going to pick it up and hear the reminder. When the calls come from some other number, people think it's spam. People still expect reminder calls even if you/HN crowd would prefer an email/text.

* Outbound call centers on behalf of others companies (same reason as above)

* People who work from home but want to make business calls from a personal phone

If no one could spoof, it probably result in a huge uptick of people claiming spam calls since they would be getting tons of calls from numbers they didn't know.

There really needs to be an SPF, DKIM, DMARC for VOIP. I don't think a no spoofing policy would go over well for businesses or consumers.

Re: FCC fines robocaller record $120M

#9
post #8
post #5

Earlier quoted context omitted.

I've suggested in the past that every instance of provable spoofing where they did not control the claimed number should result in a fixed fine. $100 sounds about right. Every phone network will then quickly begin passing on that cost to anyone they "peer" with and it will be a non-issue soon enough. Is there a compelling reason to allow such spoofs?

>Is there a compelling reason to allow such spoofs? A few use cases to spoof the number: * Appointment reminder systems - if I see the caller ID is from my doctor's office, I'm going to pick it up and hear the reminder. When the calls come from some other number, people think it's spam. People still expect reminder calls even if you/HN crowd would prefer an email/text. * Outbound call centers on behalf of others comp…

In all of those scenarios, one could prove they controlled or had authorization for the spoofed number, hence it would not be eligible for my proposed fine.

I'm not suggesting no spoofing, I'm suggesting a fine on the carrier for unauthorized spoofing, which will force them to actually verify that there is authorization.

Re: FCC fines robocaller record $120M

#10
post #8
post #5

Earlier quoted context omitted.

I've suggested in the past that every instance of provable spoofing where they did not control the claimed number should result in a fixed fine. $100 sounds about right. Every phone network will then quickly begin passing on that cost to anyone they "peer" with and it will be a non-issue soon enough. Is there a compelling reason to allow such spoofs?

>Is there a compelling reason to allow such spoofs? A few use cases to spoof the number: * Appointment reminder systems - if I see the caller ID is from my doctor's office, I'm going to pick it up and hear the reminder. When the calls come from some other number, people think it's spam. People still expect reminder calls even if you/HN crowd would prefer an email/text. * Outbound call centers on behalf of others comp…

The question wasn't about why spoofing exists at all. It was about spoofing where they did not control the claimed number.

If you want to place a call with spoofed caller ID info, your provider should require you to prove that the spoofed information is legitimate, not fraudulent. Otherwise, the telco should be obligated to strip the suspect caller ID information from the call so that the recipient can properly identify the call as fishy.

There's no need for any complicated cryptographic solution. Telcos should just be required to know their customer, much like banks, before allowing them to do certain things.

Post reply on HN