Live data from Hacker News

A Call to Action: Stop the FCC's KYC Regime

blog.lopp.net

81–90 of 248 posts

Re: A Call to Action: Stop the FCC's KYC Regime

#81
post #75

Earlier quoted context omitted.

This is already not allowed. If your carrier accepts a spoofed call they're already violating FCC recommendations.

Recommendations aren't requirements; you're allowed to violate them.

Of course

Re: A Call to Action: Stop the FCC's KYC Regime

#82
Honestly I'm at the point where I'm like lets just kill the POTS. It makes little sense to me that it's become a sort of user ID for many things, that we have better alternatives (WebRTC, FaceTime et al) that we should push. Like where it currently says "Telephone number" i should be able to put in a URL like "webrtc://" (which itself could be a dropdown box for "This device" on the phone itself...)

For example, why isn't it the default that when a telemarketer calls me it's not a video call? And why can't I preview their video stream prior to answering?

I get its "impossible" to make everyone change, but i do think we should push forwards...

Re: A Call to Action: Stop the FCC's KYC Regime

#83
post #3

Im USA based use prepaid service because I dont want to provide information for a credit check to obtain postpay service. Theres absolutely no reason for a US based telephony provider to retain the most sensitive PII on their customers. Every large provider has a history of breaches and selling customer data. The telephone companies are already tracking, storing, selling; so many data points on their customers. They…

Counterpoint: for my part I would like it to be the case that any phone line that can dial or message my phone can be traced back to a known human being who can be held accountable for abuse of that phone line in terms of generating spam, abuse or harassment. Seems that we can’t both get what we want. A potential solution is that you get your anonymous phone line but my phone provider simply refuses to let you call m…

> my phone provider simply refuses to let you call me with it.

I don't think it's necessary to go this far. The provider could indicate something like "CANNOT VERIFY NUMBER". I imagine most people would block such calls.

Re: A Call to Action: Stop the FCC's KYC Regime

#84
post #36
post #11

Earlier quoted context omitted.

It did in every other country that did it. What's different about this one? If you get a spam call in Europe from Europe, you call the police and the spammer gets located and punished.

Europe does not consistently have KYC for phone service, at least for mobile connections. Normal phone companies in Ireland don't ask for information when buying SIMs (physical ones, at least). Some eSIM providers in Europe don't ask for information at all, and accept cryptocurrency payments. (I'm also aware that some other European countries have very different requirements, up to actually needing copies of identifi…

As an additional anecdote, I've never heard of a number-porting/2FA attack using social engineering or other methods in Ireland - but we have our own unique issues now with Robocalls and phishing on WhatsApp and SMS.

Re: A Call to Action: Stop the FCC's KYC Regime

#85
post #71

Earlier quoted context omitted.

What ever happened to SHAKEN/STIR? I thought this was supposed to happen 5 years ago. Did they just chicken out on the prospect of actually shutting down telcos sending spam volume? I still get loads of spam phone calls, so clearly something went wrong (or slow enough to be indistinguishable from wrong).

The FCC issued a report on this very subject[1]. TLDR, there have been four exceptions to the SHAKEN/STIR requirements: - Providers that can't afford it implement it - Non-IP networks - Small voice service providers that originate calls via satellite using U.S. NANP - Providers that lack control over the network infrastructure necessary to implement Nothing is going to change as long as those holes exist. 1: https://…

The can't afford it exception is disappearing soon, as it isn't true for any business. Total setup costs for STIR/SHAKEN are under $2000 these days. Providers that lack control over the network infrastructure (i.e. they don't have the ability to control the stir/shaken headers so by definition they can't spoof numbers) will likely continue to be a thing as changing it would force pretty much every small business in the VOIP industry out of business and allow only large companies to be VOIP service providers.

Re: A Call to Action: Stop the FCC's KYC Regime

#86

Earlier quoted context omitted.

What ever happened to SHAKEN/STIR? I thought this was supposed to happen 5 years ago. Did they just chicken out on the prospect of actually shutting down telcos sending spam volume? I still get loads of spam phone calls, so clearly something went wrong (or slow enough to be indistinguishable from wrong).

Just because a call is a spam call doesn't mean it is spoofed. STIR/SHAKEN ends spoofing but anyone can ultimately buy a phone and make calls that are spammy.

Sure, but with phone numbers that can't be spoofed, telcos can terminate service, and filtering technologies can block calls. Spam gets expensive if you have to buy new service every five calls.

Re: A Call to Action: Stop the FCC's KYC Regime

#87

Earlier quoted context omitted.

What ever happened to SHAKEN/STIR? I thought this was supposed to happen 5 years ago. Did they just chicken out on the prospect of actually shutting down telcos sending spam volume? I still get loads of spam phone calls, so clearly something went wrong (or slow enough to be indistinguishable from wrong).

Just because a call is a spam call doesn't mean it is spoofed. STIR/SHAKEN ends spoofing but anyone can ultimately buy a phone and make calls that are spammy.

Nobody is making spam calls with cell phones. Spammers use VOIP services and old TDM systems.

Re: A Call to Action: Stop the FCC's KYC Regime

#88

"force phone providers to collect identity information from ordinary people before they can acquire or renew service with a phone carrier." don't see the harm in this? isn't this already the case for 99.9% of phoneline havers already?

Realistically, it is for 99.9% of people who have phones. The 0.1% have to go out of their way to buy, with cash or crypto, prepaid SIM top-ups on flip phones, and by doing so they stand out like a sore thumb.

Back in the days of rotary phones, not only did the phone providers have your name, they even listed it, your home address, and your phone number in the white pages of the phone book, and everyone in town had a copy of it. Before the rise of microcomputers which enabled data tracking and robocalls, which in turn gave rise to demand for privacy from spam, having that information out in public wasn't a problem except for edge cases like domestic abuse victims or people in a witness protection program. The 99.9%, though, are still getting tracked no matter what, and I sometimes wonder if we've sacrificed the convenience and confidence of the phone-book age for an illusion of privacy that relies on anxiety.

Re: A Call to Action: Stop the FCC's KYC Regime

#89

Earlier quoted context omitted.

Now that you mention it, I believe I have seen a couple of red flagged calls, but I still get ~3 calls a day from a very aggressive business loan spammer, it's always a new number and never flagged.

That's because they are bulk purchasing numbers from voip providers, cycling through probably hundreds per day.

Do they actually need to purchase numbers to do that, though?

I always imagined that there are certain shady providers ("grey-market Twilio" sort of idea) that just let you run single outbound call/text requests through a giant pool of numbers shared with other customers of the service. Perhaps specifically a bank of residential numbers plugged into banks of regular cell phones, like a residential IP proxy service provider.

Re: A Call to Action: Stop the FCC's KYC Regime

#90
Phone numbers are just a liability:

- It is kind of expensive,

- You are forced to provide it to many official institutions,

- It is the default or mandatory insecure 2FA for many institutions,

- It always get leaked somewhere and is one of the most common/reliable identifier.

We still have them around governments and telcos love it and old people and scammers are its last users.

Post reply on HN