Live data from Hacker News

Washington’s new anti-robocall law won’t stop the calls

wsj.com

41–50 of 93 posts

Re: Washington’s new anti-robocall law won’t stop the calls

#41
post #15

The technology behind STIR/SHAKEN is relatively interesting, integrating certificate authorities into the SIP protocol: https://www.atis.org/sti-ga/resources/docs/shaken-faqs.pdf As the article mentions, there are some shortcomings. Caller ID spoofing is necessary for some services, as in the VOIP world calls are broken up into termination (dialout) and origination (dialin). If STIR/SHAKEN takes hold, the CID phone n…

I just implemented this at a telecom. To expand a bit, the three levels are A, B, and C. There is also of course empty (no attestation). Three levels of attestation are roughly:

A = I know the customer, they own this number.

B = I know the customer, can't confirm they own this number.

C = I'm sending this call out, but I know nothing of the customer or this number.

Carriers sometimes don't want to receive anything other than A, because its probably useless to them. By that I mean, if it's not A, they don't want to be sent the attestation level or identity header at all.

Re: Washington’s new anti-robocall law won’t stop the calls

#42
post #2

I've just stopped answering my phone altogether. If something is important enough the person calling should leave a voicemail.

I always answer the call and then joyfully "block/report spam" the number in the Android dialer. Being able to do something to fight back is satisfying enough that I don't ignore the call. I did just switch to T-Mobile and they pass "SCAM LIKELY" as the caller name so I may start declining those.

I have had (in the uk) a few recently - they stopped after the last one after I answered in my best BT Phone Voice "Met Police Duty Officer"

Re: Washington’s new anti-robocall law won’t stop the calls

#43

Earlier quoted context omitted.

I always answer the call and then joyfully "block/report spam" the number in the Android dialer. Being able to do something to fight back is satisfying enough that I don't ignore the call. I did just switch to T-Mobile and they pass "SCAM LIKELY" as the caller name so I may start declining those.

the block button doesn’t do anything since most of the phone numbers are spoofed (someone pretending to be someone else). Filtering out any number that shares my area code and first three digits and not in my phone book would go a long way to getting rid of spam.

I used a bulk number blocking app to do exactly that, and the amount of spam calls I receive has dropped dramatically. You can also have it make exceptions for numbers in your contacts list. The one I used on IOS is called Wideprotect, but I'm sure there are ways to do it on Android as well.

Re: Washington’s new anti-robocall law won’t stop the calls

#44

having a phone number will go the way of the landline same with email addresses -- this is some combination of your identity and a license to spam you spam protection is the main feature of gmail because email wasn't designed with fraud in mind -- an email system rebuilt from the ground up for 2019 would be safe for medical information, receipts, not be the giant password reset security hole that email currently is,…

My company recently switched to MSFT Teams, and the other day I was thinking how difficult it would be to get spam through teams. By design, only people part of our organization can communicate with each other. There (AFAIK) is no endpoint for my organizational teams account visible to other teams users outside my organization. For spam to occur, someone's account would need to be compromised (which would be found qu…

Yes, though internal spam is a thing too. Chat tools are the prime driver of it

Re: Washington’s new anti-robocall law won’t stop the calls

#45

Earlier quoted context omitted.

> For one, making calls costs money. It gets a lot cheaper at scale. > And then this spoofing: isn't the solution against that technological rather than legislation? "Spoofing" is just a name for using caller ID you shouldn't. There's no tech solution for it... unless we create a global federated registry that can be queried online, a new phone network which cares about it, and migrate every phone in the world to it.…

I never noticed this spoofing ability in Europe though. Can someone make a phone call and appear to have a different number (and is this about mobile or landline numbers)? If so, why isn't it being done at large scale in Europe to get around apps that block known call centers? Why would there be no tech solution around fake caller ID? The phone company knows who it's billing for this call, doesn't it?

Company A knows, but doesn't care, then sends the call to company B. Company B doesn't know / can't verify.

It seems like it's on the rise in the UK https://www.which.co.uk/news/2019/10/whos-really-calling-you...

As for the capability, in many ITSP companies you can sign a paper saying "I promise that all the calls I'm sending have a valid callerid" and get no restrictions.

Re: Washington’s new anti-robocall law won’t stop the calls

#46

Earlier quoted context omitted.

> For one, making calls costs money. It gets a lot cheaper at scale. > And then this spoofing: isn't the solution against that technological rather than legislation? "Spoofing" is just a name for using caller ID you shouldn't. There's no tech solution for it... unless we create a global federated registry that can be queried online, a new phone network which cares about it, and migrate every phone in the world to it.…

I never noticed this spoofing ability in Europe though. Can someone make a phone call and appear to have a different number (and is this about mobile or landline numbers)? If so, why isn't it being done at large scale in Europe to get around apps that block known call centers? Why would there be no tech solution around fake caller ID? The phone company knows who it's billing for this call, doesn't it?

> Can someone make a phone call and appear to have a different number?

I imagine so. It is quite easy to test. Here in Canada, if you verify your phone number with Google Hangouts [0], calls you make using Hangouts Dialer or through Gmail interface will show it originating from your phone number, even though it is originating from Google servers, not your phone. It seems Hangouts Dialer is available throughout EU. Have you tried using it?

[0] https://support.google.com/hangouts/answer/3116671

Re: Washington’s new anti-robocall law won’t stop the calls

#47
post #15

The technology behind STIR/SHAKEN is relatively interesting, integrating certificate authorities into the SIP protocol: https://www.atis.org/sti-ga/resources/docs/shaken-faqs.pdf As the article mentions, there are some shortcomings. Caller ID spoofing is necessary for some services, as in the VOIP world calls are broken up into termination (dialout) and origination (dialin). If STIR/SHAKEN takes hold, the CID phone n…

I just implemented this at a telecom. To expand a bit, the three levels are A, B, and C. There is also of course empty (no attestation). Three levels of attestation are roughly: A = I know the customer, they own this number. B = I know the customer, can't confirm they own this number. C = I'm sending this call out, but I know nothing of the customer or this number. Carriers sometimes don't want to receive anything ot…

Do you see any/some/most/all carriers implementing STIR/SHAKEN for termination soon?

Re: Washington’s new anti-robocall law won’t stop the calls

#48

Earlier quoted context omitted.

> For one, making calls costs money. It gets a lot cheaper at scale. > And then this spoofing: isn't the solution against that technological rather than legislation? "Spoofing" is just a name for using caller ID you shouldn't. There's no tech solution for it... unless we create a global federated registry that can be queried online, a new phone network which cares about it, and migrate every phone in the world to it.…

I never noticed this spoofing ability in Europe though. Can someone make a phone call and appear to have a different number (and is this about mobile or landline numbers)? If so, why isn't it being done at large scale in Europe to get around apps that block known call centers? Why would there be no tech solution around fake caller ID? The phone company knows who it's billing for this call, doesn't it?

iirc, the calling number is reported from the calling device, not the service provider.

I remember playing around with that on my rooted Android phone years ago (around Android 2.0-2.2) in germany.

It would probably be possible to discard this information from the client and overwrite it as the service provider, but they weren't doing that at least back then. It would also be costly (like a MitM proxy overwriting headers)

That was around 10yrs ago though. Might have changed by now.

Re: Washington’s new anti-robocall law won’t stop the calls

#49

This problem doesn't appear to exist at that scale (there exist some spammy call centers of course, and apps to block them...) in Europe. Not sure if that is legislation, technology or culture/economy related, and whether it's an active solution or it just passively works out. But what stops the US from doing whatever it Europe is doing to not have tons of robocalls? For one, making calls costs money. How can robocal…

Yep. This seems to be one of those American things like prescription drug ads on TV.

[deleted]

Re: Washington’s new anti-robocall law won’t stop the calls

#50
post #47

Earlier quoted context omitted.

I just implemented this at a telecom. To expand a bit, the three levels are A, B, and C. There is also of course empty (no attestation). Three levels of attestation are roughly: A = I know the customer, they own this number. B = I know the customer, can't confirm they own this number. C = I'm sending this call out, but I know nothing of the customer or this number. Carriers sometimes don't want to receive anything ot…

Do you see any/some/most/all carriers implementing STIR/SHAKEN for termination soon?

As someone who works with multiple carriers, I doubt anyone outside of the wireless carriers and Inteliquent will implement STIR/SHAKEN soon in the USA.

Inteliquent (aka Neutral Tandem, Onvoy, Exiant, Vitelity, plus 20 other sub-brands) is the only provider implementing this protocol outside the cellular industry, and most of the CLECs they work with are not capable of maintaining SIP with a TLS certificate, let alone their own PKI as STIR/SHAKEN would entail.

Post reply on HN