I've got a FreePBX/Asterisk VoIP PBX and I've thought about running TeleCrapper2000 ( https://hackaday.com/2005/09/08/telecrapper-2000/ ), but a better solution is to just put Google Voice in front of it and turn on "Screen Calls". It does a very effective (although not 100%) job of eliminating most robo/sales calls.
FCC will require phone carriers to authenticate calls by June 2021 [pdf]
261–270 of 352 posts
Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]
#262Earlier quoted context omitted.
Ahem. "An independent U.S. government agency overseen by Congress, the commission is the United States' primary authority for communications law, regulation and technological innovation." Source: https://www.fcc.gov/about-fcc/what-we-do You can have arguments until forever about what they should or shouldn't do, but their raison d'être is to set policy according to these overarching objectives. Oh, and just to be cle…
Ahem, the authority comes from Title 2 passed in 1934. In 2005, the FCC decided that ISPs should be regulated by them. From 2005 - 2012, Congress failed to pass new bills granting the FCC this authority. It was denied by congress. In 2015, the FCC decided that they didn't congress to grant that authority. So yeah, the FCC website claiming they have an authority is not an impartial source. Two years later, the FCC rev…
It's inexplicable that the same party that claims the act establishing the FCC is more limited than the wording states while the federal arbitration act is continuously expanded to cover cases that neither the authors nor previous courts ever tolerated.
Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]
#263Earlier quoted context omitted.
Yea, you still probably don't know what that number is. This just prevents spoofing, not the calls themselves.
As long as there's no spoofing, shared client-side software-level blacklists (i.e. the same "adblocking" we do elsewhere) can handle the rest. It would solve 99% of the problem just to be able to block all the calls that either 1. originate directly in other countries, or 2. that originate from number-ranges leased to carriers known to exist solely for the purpose of leasing numbers to VoIP/softphone/"app calling" pr…
Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]
#264Good. But really, why did this take this long? It should be relatively easy to identify the bad actors here and I don't mean the spammers, I mean the telcos that make this possible, deliberately so, by essentially "laundering" spam calls. My response to picking up a number is to answer the call and say nothing. Auto-dial systems will route the call to a person when they get a "live" response. I don't know the criteri…
It took a while for the carriers to bring themselves into compliance with the technical requirements to make it work.
Basically, he walks through the history of the phone system and how it never really considered bad actors, and then what they are working on now and what it'll take to deploy it.
Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]
#265Earlier quoted context omitted.
I'm struggling with the decision of whether to automatically block anyone not in my contact list and leave a message in my voicemail explaining why. Don't want to be unfriendly, but it's only getting more ridiculous.
Recent versions of Android have an option to automatically screen callers who are not in your contact list. The caller gets a robot asking them why they're calling, and you can view the transcript of their response in real time and decide whether or not to answer.
Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]
#266Right now, I guess I'm "spoofing" my caller ID by using a VoIP service unrelated to my actual phone provider to make outbound calls. My phone provider has every incentive to sabotage this, since this alternative provider allows me to pay probably something like 1% of the rates I'd be paying to my regular provider.
The VoIP provider verifies that I own the number before letting me use it as caller ID, but towards the network it still relies on the ability to send arbitrary caller IDs. Will this remain possible/will providers controlling someone's phone number be required to somehow enable this?
How will this work for call centers that want to send a central well-publicized inbound number from multiple locations?
Edit: So I read up on the protocol The SIP provider will provide a claim, signed with their key, confirming that they checked my number.
This leaves the possibility of providers having bypassable checks (I think mine e.g. let you set an arbitrary caller ID if you edited a HTML dropdown client-side) and "how to identify which provider is trustworthy", but that seems a lot easier to solve than the original problem.
Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]
#267Earlier quoted context omitted.
After 15 years of cell phone spam, anything that shows up as a number on my personal phone, and not a contact, is reflexively ignored. I don't think I'll ever shake this habit: if it is important, they will leave a message.
If it’s important, they can text me. I ain’t listening to voice mail. Eww, what is this, the Middle Ages?
Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]
#268Why is this problem unique to the USA? I'm not saying I never get spam calls, but I certainly have to scroll back quite a bit in my phone call history to see the last one. Also, on the rare occasion I do get a spam call it's always from some random international country like South Sudan or Oman that I would never expect a phone call from. What makes this problem uniquely hard to solve for the USA as opposed to anywhe…
Until this HN post it never occurred to me that you could spoof phone calls. While landlines used to get lots of spam calls, perhaps I've had just two of these calls to my mobile in my life. Each time I typed the number into google and found reports of that number being spam. And maybe less than 20 spam sms's.
Does this mean that other countries (such as Australia) do not allow spoofing of numbers?
Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]
#269Earlier quoted context omitted.
Good point. I suspect carriers tolerate scammers because they're good for the bottom line.
The same way USPS is funded by junk mail, a large volume of Telecoms' voice calls is likely robo-caller spam. Still I would have thought either Verizon or AT&T could come up with a competitive advantage of, you know, "the number that comes up on caller ID is authenticated to actually be the person paying for that phone number" The spoofed caller ID to match your local area code has landed on people in my contact list…
Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]
#270Good. But really, why did this take this long? It should be relatively easy to identify the bad actors here and I don't mean the spammers, I mean the telcos that make this possible, deliberately so, by essentially "laundering" spam calls. My response to picking up a number is to answer the call and say nothing. Auto-dial systems will route the call to a person when they get a "live" response. I don't know the criteri…
> Auto-dial systems will route the call to a person when they get a "live" response. I don't know the criteria but I'm pretty sure it's them detecting noise on the call (which could be voicemail). I work with phone systems. It's usually determined by how long they hear a continuous sound at the start of a call. If it's relatively short (and it can be adjusted by settings), it assumes it's a live voice (like someone s…
Question you might know the answer to: I've noticed it's a pretty common practice to get appointment reminders with caller ID from the doctor's office. I like that feature. I'd imagine there are plenty of other legitimate use cases for caller ID spoofing as well. Do you have any idea how that's going to work with STIR/SHAKEN?
I'd guess it's going to be some kind of oauth for your phone number, where you own it and can grant spoofing access to other entities?
Google seems to be supporting it: https://ecfsapi.fcc.gov/file/1119583115056/2018-11-19%20Goog... (via https://www.fcc.gov/call-authentication)