Live data from Hacker News

FCC will require phone carriers to authenticate calls by June 2021 [pdf]

docs.fcc.gov

181–190 of 352 posts

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#181
post #177
post #166

I didn't see anything in there about penalties for carriers not enforcing this. Also willing to bet they beg for extensions claiming they're not ready - or too costly to implement.

Good point. I suspect carriers tolerate scammers because they're good for the bottom line.

If my mom's bill is any indication, the telco's getting ~$40 for each landline. Not sure what a voice T1 goes for these days.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#182
post #177
post #166

I didn't see anything in there about penalties for carriers not enforcing this. Also willing to bet they beg for extensions claiming they're not ready - or too costly to implement.

Good point. I suspect carriers tolerate scammers because they're good for the bottom line.

The same way USPS is funded by junk mail, a large volume of Telecoms' voice calls is likely robo-caller spam. Still I would have thought either Verizon or AT&T could come up with a competitive advantage of, you know, "the number that comes up on caller ID is authenticated to actually be the person paying for that phone number"

The spoofed caller ID to match your local area code has landed on people in my contact list, and it was extremely jarring to think "why is my best friend's mom calling me out of the blue" and get offered a discount cruise by a robot.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#183

Earlier quoted context omitted.

Some carriers may have the ability to limit calls to customers based on attestation level. Customer could configure they only want to receive i.e "A" attested calls. This means the carrier from where the call originated knows that the customer who made the call owns the number they dialed from.

Right, but I guess I'm asking, are plans for this in the works? Because currently I'm not aware of anything like this, nor of any plans to implement anything like this. None of the announcements suggest it might be happening either, so that's why I'm lost as to what the end-user experience would be.

I can only speak for one carrier, and the answer as of this moment is no. Pretty much everyone is struggling to meet the FCCs aggressive timelines and do interoperability testing with each other. After that is done, maybe. I'm sure the FCC has upcoming requirements based on this, but to my knowledge those aren't out yet. If the FCC doesn't make additional requirements, then it will depend on the carrier's decision. I'm under the assumption that they will introduce those additional requirements though.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#184
Good. But really, why did this take this long?

It should be relatively easy to identify the bad actors here and I don't mean the spammers, I mean the telcos that make this possible, deliberately so, by essentially "laundering" spam calls.

My response to picking up a number is to answer the call and say nothing. Auto-dial systems will route the call to a person when they get a "live" response. I don't know the criteria but I'm pretty sure it's them detecting noise on the call (which could be voicemail).

A human calling will wonder what is happening and fill the silence by saying something. A machine will not.

I hang up within 6 seconds of this in the hopes that it affects some metric somewhere of this being a low-quality or spam call. I don't know if it does. I think I read somewhere once that it did. I could be wrong.

If a real human is on the other end and does say nothing in this window, they'll generally just call right back. You get the exact same number again then this time I'll answer it.

It is nice to filter contacts vs non-contacts but there are too many things on non-contacts. Businesses you deal with, primarily.

In the email world where obviously spam is a huge problem zombie relays that allow this (which I believe is the primary source?) can get blacklisted. Why don't telcos who do this also get blacklisted? Or at least identified? This isn't AT&T or Verizon. It's the little telcos that connect to them.

But is this all too little too late? I think we've discovered over the last 20 years that we're all pretty much over open networks. It's all opt-in now with the likes of Whatsapp, FB Messenger and so forth.

Oh and while we're at it, can we get rid of this stupid exemption to robocalling restrictions for political campaigning? It's defended as "political free speech". To me, this is nonsensical. Free speech doesn't mean that I should be forced to listen to it.

EDIT: Found an example [1] of the bad actors I'm talking about.

[1]: https://www.theverge.com/2020/1/31/21117477/justice-departme...

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#185

Earlier quoted context omitted.

Right, but I guess I'm asking, are plans for this in the works? Because currently I'm not aware of anything like this, nor of any plans to implement anything like this. None of the announcements suggest it might be happening either, so that's why I'm lost as to what the end-user experience would be.

I can only speak for one carrier, and the answer as of this moment is no. Pretty much everyone is struggling to meet the FCCs aggressive timelines and do interoperability testing with each other. After that is done, maybe. I'm sure the FCC has upcoming requirements based on this, but to my knowledge those aren't out yet. If the FCC doesn't make additional requirements, then it will depend on the carrier's decision. I…

I see. Thanks!

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#186
post #147
post #127

Earlier quoted context omitted.

I just wish various Doctors and Dentists could jump on the text/email bandwagon. Those two groups are responsible for nearly all of my phone usage - with a slim minority (that is itself mostly spam) being calls from my bank.

They are subject to HIPAA comstraints.

There's something in HIPAA saying how the provider is to contact you? Over which channels? I'm sceptical. I get texts from my dentist and in-app notification from doctor.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#187
post #147

Earlier quoted context omitted.

They are subject to HIPAA comstraints.

There's something in HIPAA saying how the provider is to contact you? Over which channels? I'm sceptical. I get texts from my dentist and in-app notification from doctor.

You have to ensure a channel that doesn’t gratuitously leak. Email took a very long time to be accepted, especially after things like hotmail and especially gmail arrived.

This is why fax is still so common in medicine and law (in law there’s also a belief that a fax confirmation says it’s been delivered, if not read, while email is considered less reliable / more easily deniable.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#188

Can someone explain what this will translate into in terms of the end-user experience? For one thing, authentication will be next to useless (at least to me) if my phone is still going to ring. So does that mean it's not going to ring for a spoofed number? Also, if it results in tons of voicemail then that's still going to be quite annoying. (How) is the actual end-user experience going to be addressed?

The thing this will address is certain classes of scams that rely on spoofing a specific area code. The infamous “Windows support” calls, which generally spoof a Redmond, WA area code. The IRS/FBI/Immigration scam calls that spoof Washington DC area codes. These are scams which defraud people of huge sums of money every year, mostly the elderly and immigrants.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#189
post #154

Earlier quoted context omitted.

From my understanding, spoofed calls won’t get onto your carrier’a network under this model, let alone ring your phone. All this assumes that sorting out spoofing resolves the problem, which isn’t guaranteed.

I thought they still go through to the carrier? Just under a different attestation level: https://www.bandwidth.com/glossary/stir-shaken/

Thanks, that link is a much better overview. It seems the calls will still reach the destination network, and the phone then, but with potential for the operator to signal the likelihood of it being an unwanted or spoofed call.

I imagine we will see a tickbox in the operators apps and web settings portals to block or send such calls straight to voicemail (or similar), as they'd be able to be distinguished via the reduced attestation level.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#190

Earlier quoted context omitted.

this is not true. but if you need to carry around proof of passport there is a passport card you can get for North American travel only.

The passport card is no longer valid for international flights, only entry by land or sea.

It was never valid for international flights. It is, however, valid as ID for domestic flights (and I have used it as such).
Post reply on HN