Live data from Hacker News

FCC fines robocaller record $120M

techcrunch.com

31–40 of 175 posts

Re: FCC fines robocaller record $120M

#31
post #29
post #17

The FCC has dragged their scapegoat into the public square to torture in a big show for the brutalized masses. But how effective has the FCC been at actually curtailing the problem of robocalls? This FCC won't do anything meaningful because they've been bought off by the telecoms, and the telecoms make money hand over fist on robocalls: http://www.latimes.com/business/lazarus/la-fi-lazarus-fcc-ro... "The problem," he…

Do you have a source that’s not an offhand quote suggesting that carriers make any significant revenue from robo calls? Also, most robo calls are made through VoIP services. Aren’t they the one with the most financial incentive to keep robocalls going, and the ones that could most easily detect them? By the time the robocall gets to a carrier’s network, its already been mixed with tons of legitimate traffic from VoIP…

I work in telecoms.

The billable minutes thing is absolutely true. You might not directly pay for them as a customer, but carriers pay each other for inbound calls, so whatever carrier that is originating the robocalls is paying the next carrier in the chain, and that one pays the next, and so on until it finally reaches your phone. We’re not talking much on a single call (the prices are often around 0,01$ or even less) but when you take all the robocalls originated in a single day that adds up to quite a bit.

Re: FCC fines robocaller record $120M

#33

Can we please get phone OEMs to enable a feature to only allow calls from people in our contact list? Baked in. No apps that scrape your phone book to do it. If you're not on my contact list, go to voicemail and I'll decide if you're legit. And have an option like DND where if you call in rapid succession then I'll pick up.

In iPhone enable do not disturb 24/7 and only allow calls from contact list. Only bad/good thing is that all notifications get disabled too.

Re: FCC fines robocaller record $120M

#34

Can we please get phone OEMs to enable a feature to only allow calls from people in our contact list? Baked in. No apps that scrape your phone book to do it. If you're not on my contact list, go to voicemail and I'll decide if you're legit. And have an option like DND where if you call in rapid succession then I'll pick up.

I'd prefer an open source software solution but, either way, they'd start leaving voicemails, which is still annoying to manage. However, a lot of them already leave a 3 second blank voicemail, so that would at least eliminate the ignore/reject call step and the rude interruption.

Re: FCC fines robocaller record $120M

#35
post #5
post #3

The real problem is the lack of security and authentication on telephone networks, which enables number spoofing with virtually no chance of reprisal -- foreign callers (realistically out of the FCC's jurisdiction) use VoIP services to create calls that originate from an IP address from the telephone network's perspective, and the phone network makes no attempt to authenticate the metadata (like the phone number that…

I've suggested in the past that every instance of provable spoofing where they did not control the claimed number should result in a fixed fine. $100 sounds about right. Every phone network will then quickly begin passing on that cost to anyone they "peer" with and it will be a non-issue soon enough. Is there a compelling reason to allow such spoofs?

There are legitimate reasons for spoofing to work given how fucked up the PSTN is.

Mobile roaming is one for example - when you roam on another carrier and place a call, that carrier directly originates the call and “spoofs” your caller ID to make it look like the call originated from you.

Some companies may use different carriers for either load balancing or least-cost routing and so both of these carriers are required to “spoof” the company’s caller ID.

This can definitely be fixed with a CA system and “delegation” where the main carrier who owns the number can issue certificates for any other carrier you’d like to use to temporarily allow them to use a particular caller ID, and each call request should be signed with that certificate and the signature should be verified by call intermediate carriers down the chain, and the call dropped if the signature is missing or invalid.

Re: FCC fines robocaller record $120M

#36
post #31
post #29

Earlier quoted context omitted.

Do you have a source that’s not an offhand quote suggesting that carriers make any significant revenue from robo calls? Also, most robo calls are made through VoIP services. Aren’t they the one with the most financial incentive to keep robocalls going, and the ones that could most easily detect them? By the time the robocall gets to a carrier’s network, its already been mixed with tons of legitimate traffic from VoIP…

I work in telecoms. The billable minutes thing is absolutely true. You might not directly pay for them as a customer, but carriers pay each other for inbound calls, so whatever carrier that is originating the robocalls is paying the next carrier in the chain, and that one pays the next, and so on until it finally reaches your phone. We’re not talking much on a single call (the prices are often around 0,01$ or even le…

The inter exchange fees are a way to divvy up the revenue collected at the call originator. At the end of the day, the total amount of revenues once all those payments are netted out is going to be limited by how much the robocaller companies are paying for phone service. Is there any evidence that is a lot of money that creates incentives for corruption, as OP implies?

Re: FCC fines robocaller record $120M

#37

I got an angry call from a real person the other day yelling at me for calling them so many times. I tried to explain to them, it wasn't me, but they hung up after they said what they had to say. Has anyone else had similar happen? For some naive reason I just figured the spoofers were using blocks of unused numbers, not live ones.

Yes, this happened to me a few years back. I was waiting on an important phone call, so I had to answer. Turns out some guy was swearing up and down that I called him the day before.

Re: FCC fines robocaller record $120M

#39
post #10
post #8

Earlier quoted context omitted.

>Is there a compelling reason to allow such spoofs? A few use cases to spoof the number: * Appointment reminder systems - if I see the caller ID is from my doctor's office, I'm going to pick it up and hear the reminder. When the calls come from some other number, people think it's spam. People still expect reminder calls even if you/HN crowd would prefer an email/text. * Outbound call centers on behalf of others comp…

The question wasn't about why spoofing exists at all. It was about spoofing where they did not control the claimed number . If you want to place a call with spoofed caller ID info, your provider should require you to prove that the spoofed information is legitimate, not fraudulent. Otherwise, the telco should be obligated to strip the suspect caller ID information from the call so that the recipient can properly iden…

A cryptographic solution is absolutely necessary. Most reputable telcos already restrict spoofing or require tons of paperwork to prove you own the number before allowing you to use it as caller ID (like Twilio for example).

The issue is that the PSTN is essentially a huge, worldwide message queue to which pretty much any telco can connect around the world, including shady ones - even if US law actually does fight spoofing, how do you prevent telcos from other countries from continuing the abuse?

Cryptography is needed - when a carrier leases you a number, they give you a certificate with which you can sign other carrier’s certificates if you want to let them use that number as caller ID. Every carrier on the call chain should verify call’s signatures against that and discard any calls with missing or invalid signatures. That will stop malicious spoofing while allowing its legitimate use, just like email where you can use SPF and DKIM to nominate any email provider to be able to send on your domain’s behalf.

Re: FCC fines robocaller record $120M

#40
post #31
post #29

Earlier quoted context omitted.

Do you have a source that’s not an offhand quote suggesting that carriers make any significant revenue from robo calls? Also, most robo calls are made through VoIP services. Aren’t they the one with the most financial incentive to keep robocalls going, and the ones that could most easily detect them? By the time the robocall gets to a carrier’s network, its already been mixed with tons of legitimate traffic from VoIP…

I work in telecoms. The billable minutes thing is absolutely true. You might not directly pay for them as a customer, but carriers pay each other for inbound calls, so whatever carrier that is originating the robocalls is paying the next carrier in the chain, and that one pays the next, and so on until it finally reaches your phone. We’re not talking much on a single call (the prices are often around 0,01$ or even le…

I believe that for some carriers the billable minutes thing is significant. But what I'm really skeptical of is rectang's assertion that the FCC has been bought off by the same carriers for whom this is significant revenue.

I certainly believe that the FCC is too influenced by large telcoms companies. As we see with the Michael Cohen thing, large companies believe they can buy influence. But those same companies that are receiving the calls are mainly paid by consumers. Is TMobile really willing to risk losing my ~$100/month to get whatever they do for calls I don't answer?

I'm sure there are carriers for whom the robocalls are a major slice of revenue. But are any of them nearly as big as the consumer-focused telecoms companies?

Post reply on HN