Live data from Hacker News

Your PBX has been hacked

cringely.com

11–20 of 63 posts

Re: Your PBX has been hacked

#11
post #9
post #6

Earlier quoted context omitted.

It really isn't a big deal though, CID/ANI should never be trusted to identify the caller anyway.

That's only because we let that system be gamed. It doesn't have to be that way . Telcos always know who they're billing for a call; they have the capability to make caller ID reliable.

I don't think you've seen the systems they use in developing countries. Phone networks are almost a century behind the internet. It's not something that's easy to fix, nor are there too many situations where you would need to rely on the CID to identify the caller.

Re: Your PBX has been hacked

#12
When I get these calls I always debate trying to get their info so I can report it but it is just sooooo much easier to hang up.

For the bank I always hang up and call back. My money is worth the extra step.

Re: Your PBX has been hacked

#13

When I get these calls I always debate trying to get their info so I can report it but it is just sooooo much easier to hang up. For the bank I always hang up and call back. My money is worth the extra step.

The worry here is you hang up, call back, and the bank's telephone system is compromised and you get routed through to the malicious actor.

Re: Your PBX has been hacked

#14
post #3

I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.

There are significant downsides to technically prohibiting caller ID spoofing. First, you would no longer be able to preserve caller ID when forwarding calls. Consider how much less useful Google Voice would have been if you couldn't see the caller ID of calls forwarded to you. Second, in VoIP, outgoing calls (termination) and incoming calls (origination) are completely decoupled services. This is really nice because it enhances reliability (you can fail over to different termination provider) and reduces costs (you can route outgoing calls to the cheapest provider depending on the destination). A BCP38-style system would require you to purchase your termination from the same provider as your origination in order to have outgoing caller ID.

Re: Your PBX has been hacked

#15
post #8
post #7

Earlier quoted context omitted.

Not being able to identify the caller means I can't report it to the FTC for spamming me with "you've been approved for a $250k business loan!" and "this is cardmembers services for both Visa and Mastercard" scams.

Why should FTC be able to help you? Phones work internationally.

The FTC handles complaints for the US Do Not Call blocklist.

https://complaints.donotcall.gov/complaint/complaintcheck.as...

If someone wants to spend the money to dial me internationally just to try and pretend they're my credit card company, they're welcome to waste it.

Re: Your PBX has been hacked

#16
...and to press #4 to talk to their security department

Does something bad happen by pressing a number on dial pad or they just transfer to a human to talk to. Just curious because I heard from someone that pressing a button was good enough for the spammer who is calling you, but it does not makes sense how that can harm.

Re: Your PBX has been hacked

#17

Phone numbers are going to (eventually) disappear. They are inefficient, hard to remember and not human-friendly (they are great for computer-based routing :P ). Easier thing we can do, is to map them down like we do it with IPs and domain names, but as usual, this is far from being a practical solution. Best think is to let conventional telephony die and VoIP take over its place.

> map them down like we do it with IPs and domain names

We have been able to map phone numbers to SIP URIs for a long time with E.164 ENUM. Numbers are a hassle, but there's nothing preventing numbers from living alongside proper URIs today.

> let conventional telephony die and VoIP take over its place.

Many places are still circuit-switched at the last mile, whether over landline or cellular. We can't turn off the PSTN in favor of VoIP until everybody has switched over -- similar to the IPv6 changeover dilemma, although more tractable due to the ubiquity of Internet access and proper interworking -- no tunneling required.

What I'm waiting for though, is the ability to "bring your own" SIP URI so the carriers can handle our calls in the same way GMail can handle our email for personal/business domains. (Not to mention the capability to dial out to SIP addresses...)

Ideally, this would extend all the way down to "bring your own SIP proxy and registrar" where the carriers would just act as dumb pipes to carry your calls at the same QoS as theirs, but that's a far ways off.

Re: Your PBX has been hacked

#18
post #3

I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.

The use case for caller id spoofing is when the callback number is different than the number you are calling from, most commonly to present a generic (possibly toll free) customer service number when an agent who might not even have a DID number makes an outbound call. Large operations might also have trunks from multiple carriers for redundancy, so simple ingress filtering is not necessarily viable.

Re: Your PBX has been hacked

#19
post #8

Earlier quoted context omitted.

Why should FTC be able to help you? Phones work internationally.

The FTC handles complaints for the US Do Not Call blocklist. https://complaints.donotcall.gov/complaint/complaintcheck.as... If someone wants to spend the money to dial me internationally just to try and pretend they're my credit card company, they're welcome to waste it.

Bulk international dialing is pretty much just as expensive as local dialing. (Essentially free)

Re: Your PBX has been hacked

#20

Phone numbers are going to (eventually) disappear. They are inefficient, hard to remember and not human-friendly (they are great for computer-based routing :P ). Easier thing we can do, is to map them down like we do it with IPs and domain names, but as usual, this is far from being a practical solution. Best think is to let conventional telephony die and VoIP take over its place.

Right, because voip has a reputation for sounding great and being reliable.

(/s)

Post reply on HN