Live data from Hacker News

FCC fines robocaller record $120M

techcrunch.com

21–30 of 175 posts

Re: FCC fines robocaller record $120M

#21
post #3

The real problem is the lack of security and authentication on telephone networks, which enables number spoofing with virtually no chance of reprisal -- foreign callers (realistically out of the FCC's jurisdiction) use VoIP services to create calls that originate from an IP address from the telephone network's perspective, and the phone network makes no attempt to authenticate the metadata (like the phone number that…

Doesn't ANI work? When I worked at a business with a phone system used for time tracking we relied wholly on ANI as caller id is what is spoofed. However I am not sure if the ANI information is a paid for service or is it being spoofed as well? Caller ID data was always malleable and never to be trusted

Re: FCC fines robocaller record $120M

#22

> a technology designed to prevent robocalls altogether, recommended in a report more than a year ago and currently set to be implemented in Canada in 2019, has no such date here in the States. What’s the technology? Edit: https://transnexus.com/solutions/stir-and-shaken/stir-and-sh... ”STIR and SHAKEN use digital certificates, based on common public key cryptography techniques, to ensure the calling number of a tele…

Some of the scammers have run shady phone companies like CallerID4U [0] specifically meant as "bulletproof hosting for robocallers". I could see them branching out into the CA business.

CallerID4U seems to have gone (has been put?) out of business, at least. My Asterisk box hasn't received calls from their prefixes (which I blacklisted) since 2015, and their website's main page returns a 403 Forbidden. [1] It took a bit of hunting with the Wayback Machine to find a good shot of their page. [2]

Spot-checking on telcodata.us, it looks like their prefixes/thousands groups have gone to others as well. 253-245-2xxx now belongs to CenturyLink, for instance, and 425-336-8xxx is unassigned.

Much like "unsubscribe" links in spammer emails, they even had a helpful "Click here to register a complaint and put your phone number on the DO NOT CALL (DNC) list" item on their web site.

[0] https://800notes.com/forum/ta-705926565a74ba5/callerid4u-inc...

[1] http://callerid4u.com/

[2] https://web.archive.org/web/20130310040410/http://callerid4u...

Re: FCC fines robocaller record $120M

#23

I got an angry call from a real person the other day yelling at me for calling them so many times. I tried to explain to them, it wasn't me, but they hung up after they said what they had to say. Has anyone else had similar happen? For some naive reason I just figured the spoofers were using blocks of unused numbers, not live ones.

They're using live ones, all right. Their latest tactic is to use random numbers in the same prefix as your phone, or use prefixes in nearby rate centers.

Re: FCC fines robocaller record $120M

#24
post #3

The real problem is the lack of security and authentication on telephone networks, which enables number spoofing with virtually no chance of reprisal -- foreign callers (realistically out of the FCC's jurisdiction) use VoIP services to create calls that originate from an IP address from the telephone network's perspective, and the phone network makes no attempt to authenticate the metadata (like the phone number that…

[deleted]

Re: FCC fines robocaller record $120M

#25
post #18
post #15

Earlier quoted context omitted.

>"It makes telcos money." How?

Telcos charge for connecting phone calls and routing voice packets. Even robocallers have to pay those fees.

Not only that, but they also charge for Caller ID name lookups.

Re: FCC fines robocaller record $120M

#26
So, if you take any notice of anything on this web site, you will see that even after the page has loaded, it keeps on making loads of network connections to all sorts of servers. For ever. This is now a browser-hostile web site.

Re: FCC fines robocaller record $120M

#29
post #17

The FCC has dragged their scapegoat into the public square to torture in a big show for the brutalized masses. But how effective has the FCC been at actually curtailing the problem of robocalls? This FCC won't do anything meaningful because they've been bought off by the telecoms, and the telecoms make money hand over fist on robocalls: http://www.latimes.com/business/lazarus/la-fi-lazarus-fcc-ro... "The problem," he…

Do you have a source that’s not an offhand quote suggesting that carriers make any significant revenue from robo calls? Also, most robo calls are made through VoIP services. Aren’t they the one with the most financial incentive to keep robocalls going, and the ones that could most easily detect them? By the time the robocall gets to a carrier’s network, its already been mixed with tons of legitimate traffic from VoIP users.

Re: FCC fines robocaller record $120M

#30
Can we please get phone OEMs to enable a feature to only allow calls from people in our contact list? Baked in. No apps that scrape your phone book to do it. If you're not on my contact list, go to voicemail and I'll decide if you're legit. And have an option like DND where if you call in rapid succession then I'll pick up.
Post reply on HN