Live data from Hacker News

FCC fines robocaller record $120M

techcrunch.com

91–100 of 175 posts

Re: FCC fines robocaller record $120M

#91
i wonder how a proof of work scheme, a la hashcash, would work for call spam. it was originally designed to reduce email spam: https://en.wikipedia.org/wiki/Hashcash

it could be possible to have different PoW requirements for different callers. perhaps you could require a higher PoW for an unknown caller, and no requirement for someone you know.

Re: FCC fines robocaller record $120M

#94
post #3

The real problem is the lack of security and authentication on telephone networks, which enables number spoofing with virtually no chance of reprisal -- foreign callers (realistically out of the FCC's jurisdiction) use VoIP services to create calls that originate from an IP address from the telephone network's perspective, and the phone network makes no attempt to authenticate the metadata (like the phone number that…

The telephone system, in the US at least, could charge people extra for calling a number with the extra charge going to the person/company that was called (those famous 900 numbers, now gone, that kids would call and rack up $10000 phone bills.) It seems to me that it would be pretty easy to set up a system where, if a person is not in my contact list, they get charged some amount of money to call me. Setting it at 5 or 10 cents would be enough to kill almost all of these spam calls and not deter a real person from calling you.

Re: FCC fines robocaller record $120M

#95

> a technology designed to prevent robocalls altogether, recommended in a report more than a year ago and currently set to be implemented in Canada in 2019, has no such date here in the States. What’s the technology? Edit: https://transnexus.com/solutions/stir-and-shaken/stir-and-sh... ”STIR and SHAKEN use digital certificates, based on common public key cryptography techniques, to ensure the calling number of a tele…

Some of the scammers have run shady phone companies like CallerID4U [0] specifically meant as "bulletproof hosting for robocallers". I could see them branching out into the CA business. CallerID4U seems to have gone (has been put?) out of business, at least. My Asterisk box hasn't received calls from their prefixes (which I blacklisted) since 2015, and their website's main page returns a 403 Forbidden. [1] It took a…

Agreed. We (Nomorobo) stopped seeing calls from them around the same time.

They were also known as 33 wireless and a few related companies. Here's an old discussion about them [0]

Not sure what happened but their telephone number blocks were all reassigned to other companies

[0] https://800notes.com/forum/ta-705926565a74ba5/callerid4u-inc...

Re: FCC fines robocaller record $120M

#96
post #61

Earlier quoted context omitted.

What I don’t understand is why no major mobile carrier is offering a solution to this. It’s a pretty competitive market and this could be a big selling point. When the isp wars were going strong, before broadband put everyone under the thumb of monopolists and also before gmail, spam filtering was a serious competative advantage. Why can’t phone companies take an RBL like approach? If your VoIP service garners too ma…

Blocking calls from certain VoIP services is almost certainly going to be a violation of common-carrier rules (which still apply to phone service no matter what happens with broadband). At a technical level, spam filtering relies heavily on analyzing email text. Doing similar analysis on voice calls is way harder. Also, there's UI issues. You can redirect suspected spam emails to a folder the user can inspect for fal…

Later on spam filtering relied on analyzing email text, but before that was available there was the blunt instrument of blackholing ISPs that refused to police their users.

That approach could work here.

Re: FCC fines robocaller record $120M

#97
post #50
post #35

Earlier quoted context omitted.

There are legitimate reasons for spoofing to work given how fucked up the PSTN is. Mobile roaming is one for example - when you roam on another carrier and place a call, that carrier directly originates the call and “spoofs” your caller ID to make it look like the call originated from you. Some companies may use different carriers for either load balancing or least-cost routing and so both of these carriers are requi…

I think the correct approach is economic, not technical. Make a rule that, if you get a spoofed call, then your telco owes you $100, not subject to any arbitration clause or other contractual waiver. Give a way out to avoid actually killing the telcos: annual penalties are limited to a few percent of annual gross revenues. The telcos will find a technical solution real fast.

Or just let telephone users set a price, for someone not in there contact list, to call them. Set it at 5 cents by default. Problem solved for the most part. People that don't know you can still call you (like the person who you left your curtains at for repair) but most robo call campaigns won't be worth it. If you really hate spam, set your price to $10.

Re: FCC fines robocaller record $120M

#98
post #47
post #44

Earlier quoted context omitted.

T-Mo has two larger and one smaller national competitors. Do they want the $0.50 they get from robo callers more than the $70 they get from luring a user away from Verizon or AT&T?

Even if they wanted the 70$, at the moment there’s nothing they can do about robocalls without cooperation from the entire industry. A robocall doesn’t look any more shady than a normal call from a receiving carrier’s perspective; whatever solution they come up with will have tons of false positives.

While you cannot say for certain that a particular call is coming from a robot, being a major network you can make a very good guess. E.g. when the same origin hits every number with a caller ID in that number's exchange just block that origin from your network. If there is a legitimate reason for this - they will contact you immediately and sort it out. Bonus point - spammers will hit the competitors networks with more bandwidth and force even more people to consider switching.

The current situation is the one, which requires cooperation of the whole industry, actually. It's a prisoner's dilemma in the sense that the first one to implement anti-spam will gain a temporary advantage but eventually everyone will have to implement it and keep up with the spammers who will be finding new ways to circumvent these measures. As it stands now - nobody gains advantage and nobody has to spend money on anti-spam and lose revenue from spam at the same time. As little as it is, taking your $70 and $0.05 from spammers is a lot better than taking your $70 and zero from spammers.

Re: FCC fines robocaller record $120M

#99
post #56

Earlier quoted context omitted.

How would you prove the call was spoofed? Record all calls? Prove it with statistics? No telco will pay. This is a technical problem.

You have a call received on your monthly bill from a number and the owner of that number does not have the call on their bill.

How? Even in the same city, cellular and land lines aren't always serviced by the same company. In most places I'm pretty sure it's illegal for phone companies to be swapping call data. Or are you suggesting I call back all the numbers that call me to compare bills with the owner on the other end? This plan is not going to work out.

Re: FCC fines robocaller record $120M

#100

So, if you take any notice of anything on this web site, you will see that even after the page has loaded, it keeps on making loads of network connections to all sorts of servers. For ever. This is now a browser-hostile web site.

Running NoScript in default deny JS mode results in the page loading, with no further requests occurring while you read the page (because none of the javascript that is making the requests is allowed to run).
Post reply on HN