Live data from Hacker News

Anti-fraud tools can't keep pace with robocall scammers

broadbandbreakfast.com

11–20 of 149 posts

Re: Anti-fraud tools can't keep pace with robocall scammers

#11
The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the call in question entered his own network from. The last cooperative network in the chain gets stuck with the fee, forcing them to either reclaim the money from the malicious customer, the next network in the chain (in court) or pony up the money themselves.

Result: All routes to non-cooperating networks get dropped within days to weeks and scam-calling stops being a lucrative business basically instantly.

Re: Anti-fraud tools can't keep pace with robocall scammers

#12

The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the cal…

A lot of scams unfortunately operate right on the line of legality like the car warranty morons

Re: Anti-fraud tools can't keep pace with robocall scammers

#13

The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the cal…

I think we have to do something this extreme. We have to give the system a total makeover. Somehow we also have to keep it from being fully centralized and have the big brother problem on the other side. Unfortunately these two goals are difficult to get through at the same time, with the system that we have.

Re: Anti-fraud tools can't keep pace with robocall scammers

#14
post #10

One of the biggest concerns I have with phone scams is that the people most vulnerable are the elderly, and they don’t have the knowledge on how to block these calls (if a technical solution is the only option). And further to that, the elderly are also the ones who cannot block unknown numbers, because doctors’ offices seem to have random numbers they call you from (they may have a pool of numbers but it’s not reaso…

AARP's magazine and bulletin[1] are pretty much filled with scam-awareness articles every issue. It's an absolutely major concern.

________________________________

Notes:

1. Incidentally, the first and second largest-circulation magazines in the US now: https://www.magazineline.com/blog/most-popular-magazines-in-...>.

Re: Anti-fraud tools can't keep pace with robocall scammers

#15
post #6

T-Mobile’s Scam Shield works really well for me. But you have to get the premium tier.

Funny, the same telecoms that whine about how hard this traffic is to stop... are also selling a "premium" service to customers- who then manually tag unwanted calls so that the telecom can sell that data back to other customers...

I don’t seem to be charged for Scam Shield on my account. I’ve had one unknown number call and not leave a message over the last month, which is a far cry from the 20–40 spam calls per day some people report.

Re: Anti-fraud tools can't keep pace with robocall scammers

#16
post #13

The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the cal…

I think we have to do something this extreme. We have to give the system a total makeover. Somehow we also have to keep it from being fully centralized and have the big brother problem on the other side. Unfortunately these two goals are difficult to get through at the same time, with the system that we have.

Cue the crypto bros touting their decentralized spam-detection blockchain

Re: Anti-fraud tools can't keep pace with robocall scammers

#17

T-Mobile’s Scam Shield works really well for me. But you have to get the premium tier.

There are a number of options. My view is that carrier-based filtering (rather than on-device filters) are where effort must be focused. Much as we learned with email: if you're routing traffic for many people, mass-contact attempts and patterns become quickly visible. Individuals see only a minuscule fraction of traffic, networks see overall patterns.

The other element is that carriers can act at the network level, noting how much abusive traffic arrives from given peers, and taking direct action against those peers. That could involve rejecting traffic outright, subjecting it to stronger challenges, and/or diverting it to investigative / law-enforcement bodies (I'd suggest both national and state entities) for both tracking and enforcement. Power-law relations mean that at any given time, a small number of networks will account for the overwhelming majority of spam, though which networks will likely change over time.

The key problem with this is getting the carriers to act, which ... will probably involve a few carrots and sticks. I'll address those in another comment, except to mention bonding: https://oag.ca.gov/consumers/general/telreg>.[1]

Individual action will not solve this problem, but there are steps you can take.

Most major US carriers now offer some form of robocall blocking. "Scam Shield" from T-Mobile, "ActiveArmor" from AT&T, "Call Filter" from Verizon.

MVNOs (mobile virtual network operators) may or may not offer scam / robocall blocking themselves (though IMO they should, and should be required to). Some will identify spam calls, but those are still passed through to your handset.

Beyond this, there are on-device apps which can be used, some are carrier-based (e.g., "Call Filter Plus", from Verizon, similar tools exist for Verizon and AT&T), some are third-party. These of necessity share your voice/text activity with third parties, which is its own concern and consideration.

Full Android, iOS, and several full-featured Android alternatives (GrapheneOS, /e/OS, LineageOS, etc.) offer unknown caller rejection. Numbers not in your contact list are directed to voicemail. At present, few spam calls will leave voicemail, though some do, and as AI expands in capabilities, applications, and adoption this will all but certainly increase. I'd strongly encourage use of this.

Feature phones / dumbphones ... have far less capability. Most cannot even reject unknown numbers, which ... seems a ripe target for legislation and/or regulation. Phone frameworks such as AOSP / KaiOS seem to afford little capability for even creating a call-blocking app. This and other dumb devices (e.g., traditional landlines) are a strong argument for carrier/network level mitigations.

The company everyone loves to hate, Comcast/Xfinity, actually has one of the most sophisticated voice/text spam blocking systems, and one I'd like to see mandated to all carriers: https://www.xfinity.com/support/articles/spam-blocker-overvi...>

It's risk based.

It classifies calls into three categories: high, medium, and low risk.

It adjudicates calls based on risk.

High-risk calls are terminated entirely.

Medium-risk calls are directed to voicemail.

Low-risk calls are subjected to an audio CAPTCHA (enter a two digit value to ring through), otherwise are directed to voicemail.

(It's not clear whether or not a whitelisted number will escape any treatment, perhaps subject to conditions such as originating from the appropriate/approved network for that call.)

I haven't used that system, but in advising people still moving off landlines, or looking at VOIP solutions, it's making Comcast an attractive option.

(I don't know what other VOIP providers, say, Twillo or Asterisk, offer, but suspect at least some have similar if not more-capable systems.)

________________________________

Notes:

1. California requires a $100,000 bond by all telemarketers in the state. The state has a small fraction of the incidence of robocalls of the worst US states. Several others have some bond. My view is that bonding should apply at the carrier level and be surrenderable to both contacted individuals and downstream peering networks, to provide both a strong financial penalty to abusers, and an incentive to downstream networks to pursue abusive calls.

Re: Anti-fraud tools can't keep pace with robocall scammers

#18
post #10

One of the biggest concerns I have with phone scams is that the people most vulnerable are the elderly, and they don’t have the knowledge on how to block these calls (if a technical solution is the only option). And further to that, the elderly are also the ones who cannot block unknown numbers, because doctors’ offices seem to have random numbers they call you from (they may have a pool of numbers but it’s not reaso…

> because doctors’ offices seem to have random numbers they call you from

This is a huge issue with scam/security awareness education. Too many legitimate orgs use the exact behaviors we tell people to avoid. Same thing with email, can't tell someone to never click links in emails when services keep relying on magic links, third-party notification domains, etc. SPF, DKIM, and DMARC do nothing because scammers will just typosquat.

In the phone number example, most of those numbers too are unlisted outbound numbers, you couldn't even google them to verify.

Half the battle is getting legitimate organizations to stop acting like scammers in the first place so that shady behavior becomes an obvious red flag again.

Re: Anti-fraud tools can't keep pace with robocall scammers

#19
post #6

T-Mobile’s Scam Shield works really well for me. But you have to get the premium tier.

Funny, the same telecoms that whine about how hard this traffic is to stop... are also selling a "premium" service to customers- who then manually tag unwanted calls so that the telecom can sell that data back to other customers...

Unsurprisingly: telcos sell outbound dialing capabilities to business customers.

For spam mitigations to work, the cost of selling that business must exceed its revenue.

Some, and I won't mention AT&T by name, are very curiously opposed to any regulations touching this.

Re: Anti-fraud tools can't keep pace with robocall scammers

#20
post #7
post #2

I genuinely don't understand why this is so hard to tackle. Phone numbers are a scare resource and the telecommunications networks heavily regulated with numerous central points of control. This bullshit is scaling because the companies which gate and sell that access have no obligations, legal or otherwise, to deny scammers access to their resources.

I was under the impression that SHAKEN / STIR was supposed to do that by authenticating the phone numbers displayed against the telco that made the call. But as the other comment says, your telco earns money from scam calls and they don't want that to stop.

Identification is insufficient without accountability.

SHAKEN/STIR identifies whether or not a given number is originating from a specific network, but without knowing whether that's an approved network, rejecting unapproved-origin calls, or tracking how much unapproved traffic a given network is emitting and penalising it for this, the information isn't actionable.

"Measure it harder" doesn't solve problems. The information must direct meaningful action.

Post reply on HN