Live data from Hacker News

Anti-fraud tools can't keep pace with robocall scammers

broadbandbreakfast.com

101–110 of 149 posts

Re: Anti-fraud tools can't keep pace with robocall scammers

#101

The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the cal…

Infeasible. Fraud or spam is usually pretty hard to confirm from one recording without additional context. Many scammers have plausible deniability or are just checking whether the number is active. Moreover, this solution would involve secret non-consensual recording; what if it's not a scam?

> Moreover, this solution would involve secret non-consensual recording

In Canada at least, only one party has to consent to the recording

If you record your own phone calls that's not remotely illegal. Nor is it in my opinion unethical

Re: Anti-fraud tools can't keep pace with robocall scammers

#102

Earlier quoted context omitted.

I too set it up so all unknown calls go to VM. I figure if legit they will leave a message. If two calls and no message I block the unknown number.

Roughly 100% of my spam calls come from spoofed numbers and don't repeat, so I never bother blocking anything.

There's a technical hack available here as well.

Some carriers offer blocking all unknown calls from specified area codes. On Verizon that is "Neighborhood Filter", part of their "Call Filter" toolkit:

https://www.verizon.com/support/knowledge-base-238154/>

https://www.pcmag.com/news/verizons-neighborhood-filter-bloc...>

The way it's meant to be used is that the subscriber would block their own area code, and perhaps co-located overlays or neighbouring area codes. The limit for now is ten area codes.

Known or explicitly approved numbers are passed through.

The additional hack is that it's possible to request a number in any arbitrary area code, and spam and robocall rates vary tremendously across area codes. They're generally worst across the Deep South / Southeast (TX, OK, AR, AL, MS, TN, GA, SC, NC), and lowest in Alaska, Utah, Massachussetts, Washington, and North Dakota.

See:

"The Robocall Epidemic: Which states are hit hardest by spam calls?" (10 March 2026) https://www.whistleout.com/CellPhones/Guides/robocall-epidem...>

"The Robocall Geography Tax: Why Your ZIP Code Determines Your Spam Reality" (23 October 2025) https://www.karmacall.com/blog/southeast-spam-call-geography...>

I'd submitted the latter a few days ago: https://news.ycombinator.com/item?id=49082473>.

Pick a low-spam, low-population state, request a number from one of its area codes (if not its one area code ;-), and then block all but known numbers from that area code.

Re: Anti-fraud tools can't keep pace with robocall scammers

#103

Earlier quoted context omitted.

Infeasible. Fraud or spam is usually pretty hard to confirm from one recording without additional context. Many scammers have plausible deniability or are just checking whether the number is active. Moreover, this solution would involve secret non-consensual recording; what if it's not a scam?

> Moreover, this solution would involve secret non-consensual recording In Canada at least, only one party has to consent to the recording If you record your own phone calls that's not remotely illegal. Nor is it in my opinion unethical

Almost, as someone who used to work with telecom systems in Canada, while it is true that felony wiretapping requires 1 party to consent to not be illegal, it is not the only law. PIPEDA applies to only commercial endeavors, and requires two party consent.

This is why a company must inform you of the recording, but you do not have to inform them.

Re: Anti-fraud tools can't keep pace with robocall scammers

#104
post #3

I no longer can answer my phone. I get at least 20-40 spam/scam calls per day, and many are legitimate companies calling for loans and refinancing offers, which started after I got a home loan. I cannot seem to stop them from calling, and even though my phone number is listed in National Do Not Call Registry for many years, it hasn't worked at all. The only relief is that on my iPhone, I was able to block all calls n…

What I did was implement a SIP number that asks for a random digit to be pressed before allowing the call through. It also connects to my CardDAV server, and any numbers in my address book don't get the prompt. This works for 95% of bogus calls. The only thing this stops is people not on my address book calling from hands-free. But this has never come up in conversation so I think I'm OK!

Re: Anti-fraud tools can't keep pace with robocall scammers

#105
post #49
post #10

One of the biggest concerns I have with phone scams is that the people most vulnerable are the elderly, and they don’t have the knowledge on how to block these calls (if a technical solution is the only option). And further to that, the elderly are also the ones who cannot block unknown numbers, because doctors’ offices seem to have random numbers they call you from (they may have a pool of numbers but it’s not reaso…

And if you think spam calls on your cell phone are bad... oh boy, land lines get about 10x the calls. My theory is that because it's mostly older people who have land lines on top of the fact that spam laws are tighter for cell phones. There aren't enough land line users to complain, so not a big enough voice to make a public outcry. Cell phone users have no idea the problems that land lines have. I know this because…

In rural America, the major telcos choose not to help, and that is a big factor here. You can't do stir/shaken crypto attestation of calls over TDM, but the big guys refuse to sell SIP trunks to rural operators.

see [1] for more on why stir/shaken hasnt helped as much as it ought to.

[1] https://news.ycombinator.com/item?id=48920432#48928781

Re: Anti-fraud tools can't keep pace with robocall scammers

#106

Earlier quoted context omitted.

But a normal person could be calling from a doctor's office, a hospital, or your child's school - and not an actual cellphone, and they may not want to text you (or not be allowed to text you) from their personal cellphone, either. As a parent, the "block all numbers!" approach has always seemed incredibly naive to me.

Doctors' offices, hospitals, and schools are well aware of this problem because they're dealing with both the outgoing and incoming elements of it. Many hospitals no longer permit direct calls to inpatient rooms because of the spam and fraud rates . Outbound communications are similarly frustrated, and are driving use of online and app-based contact methods (with ... their own issues). Other organisations, institutio…

Jim is a good guy and ATIS tried real hard with STIR/SHAKEN, but technology cannot overcome the commercial incentives that carriers have to let this nonsense continue. I've written about this before too [0].

[0] https://news.ycombinator.com/item?id=48920432#48928781

Re: Anti-fraud tools can't keep pace with robocall scammers

#107

Earlier quoted context omitted.

> Moreover, this solution would involve secret non-consensual recording In Canada at least, only one party has to consent to the recording If you record your own phone calls that's not remotely illegal. Nor is it in my opinion unethical

Almost, as someone who used to work with telecom systems in Canada, while it is true that felony wiretapping requires 1 party to consent to not be illegal, it is not the only law. PIPEDA applies to only commercial endeavors, and requires two party consent. This is why a company must inform you of the recording, but you do not have to inform them.

I didn't know that, thanks for clarifying

Still, as an individual wanting to record scam callers, you're in the clear to record calls that you are a part of

Re: Anti-fraud tools can't keep pace with robocall scammers

#108

Earlier quoted context omitted.

Doctors' offices, hospitals, and schools are well aware of this problem because they're dealing with both the outgoing and incoming elements of it. Many hospitals no longer permit direct calls to inpatient rooms because of the spam and fraud rates . Outbound communications are similarly frustrated, and are driving use of online and app-based contact methods (with ... their own issues). Other organisations, institutio…

Jim is a good guy and ATIS tried real hard with STIR/SHAKEN, but technology cannot overcome the commercial incentives that carriers have to let this nonsense continue. I've written about this before too [0]. [0] https://news.ycombinator.com/item?id=48920432#48928781

I'd seen your earlier comment at the time.

Your follow-up, here (https://news.ycombinator.com/item?id=48938169>), was particularly insightful, and has influenced my thinking. Essentially: authentication / validation should happen out of band with phone number itself, for the reasons you've given.

I do suspect that for routing authentication, header-level signifiers should be reasonably useful, but for strong identity or authority attestation, they're not. That's ... a deeper problem, but also one which can be solved independently.

Oh, and I'd love to see that Dallas Morning News AT&T CEO interview story, if you could find it.

Would this be it?

"Watchdog Memo to AT&T's CEO: Didn't mean to get you in trouble", by Dave Lieber (July 8, 2016) https://www.dallasnews.com/news/watchdog/2016/07/08/watchdog...>

Re: Anti-fraud tools can't keep pace with robocall scammers

#109
post #88

Earlier quoted context omitted.

That's pretty much the proposal I've made for some years.[1] California has introduced bonding to telemarketing firms specifically. I feel that should apply at the carrier level, where networks carry a guaranteed bond, pay regular premiums on it, and are dinged for unwanted calls, with the proceeds being split among the called party and any third-party network(s) traversed by the calls. Downstream networks could seek…

Do you really want the network to be so locked down you can't get access to it?

How do you reach that conclusion based on what I've written?

Re: Anti-fraud tools can't keep pace with robocall scammers

#110
post #89

Earlier quoted context omitted.

I'd make one significant change to the proposal in the comment. The delivery penalty applies to any unsolicited email , as determined by the recipient. If also tagged as scam , those are further forwarded to law enforcement (state, national) for investigation. Many US states are one-party regarding recording. Even in two-party states (CA, OR, WA, MT, IL, PA, MA, CT, NH, MD, DE, FL), disclosed recording and continuing…

I sign up for a newsletter from Google, then I report it as unsolicited. Boom, I just made Google pay me $10.

That's a familiar complaint from the world of email, where it's usually applied to mailing lists.

If I were to steelman the concern, I'd look at a few related scenarios, say, where a subscriber is running a poorly-secured VOIP system and spammers hijack that to make calls. I'll ... get to that.

First: the scenario here is phone systems, not email, so the traffic would be voice calls, possibly texts. That said, I'll consider your question as if it was calls and not newsletters.

I've given a more detailed breakdown of how I see a bonding system working here, you might want to read it before continuing with this comment: https://news.ycombinator.com/item?id=49129679>.

Second: It's not subscribers who are on the hook for spam calls, but carriers. So Google isn't paying you, your carrier is paying you (via a Surety agent), with the option of recouping that penalty from an upstream carrier, if any. If you and Google are on the same carrier, and the call didn't transit any other networks, it's just you and your own telephony service provider (carrier).

A carrier might have its own TOU/TOS with its subscribers, and subscribers originating calls could and likely would attempt to recover abuse costs if they were incurred. That subscriber (say, Google) might also have its own TOU/TOS addressing the case of mis-reporting of authorised contacts. Those actions would be outside the bonding system itself. A party repeatedly abusing the system could be liable for other actions, including fraud or malicious damages.

Note that one of the interesting elements of bonding is that call origination becomes a risky activity for telcos. Presently, telcos are eager to enter such business, put few restrictions or obligations on their customers, and to prefer outbound traffic to inbound traffic. Under a bonding programme, this changes dramatically. Large-volume outbound traffic is a liability, where it does occur, it needs to be closely monitored and managed. Our poorly-secured VOIP system mentioned earlier would probably be subject to configuration/operation validation, pen testing, close monitoring for activity, and alerts/throttling if unexpected usage patterns emerge. All of this is now in the carrier's interest.

Third: The bonding scheme would be periodically settled among carriers. I've hand-waved how often this would occur, though somewhere between daily and monthly, with a shorter term more likely (malicious actors often shoot-and-scoot, we want to avoid that). So low-level skirmish actions such as you describe would tend to result in a net wash between carriers: claims on one would be balanced by claims on others.

Fourth: Just how Google came to communicate, what it's communicating, and the degree to which it's coercing, say, receipt of sales/marketing messages vs. strictly advisory messages tied to a service ... would probably have to be considered in a larger context, but would still be outside the bonding system itself.

Fifth: There's a model for how surety bonds and claims work in the State of California's syste. For a breakdown of that see: https://www.jwsuretybonds.com/states/california/telemarketin...>.

A few other points:

- New relationships might be permitted through a contact request. This itself could be mediated by a known third party. Private individuals for personal contacts, commercial or governmental trusted parties in other cases. Effectively it's the social-introduction problem from before the age of mass communications brought forward. Such systems will have some friction (necessary to defeat spammers), but not so much friction that the system as a whole doesn't work.

- Bonding does not require strong KYC for small accounts. That is, the person wanting to buy a mobile phone and service anonymously could, but their device and service would be monitored for abuse. I expect a tiered system to emerge, with individuals, small, mid-sized, and large accounts, with increased controls and obligations proceeding with scale and/or capability.

- Generally, it's not individual accounts which are responsible for large volumes of outbound calls, absent an issue such as a proxy hijacking. Large outbound volumes will tend to be associated with known call- or data-centres, and can be managed as such.

- The goal is preservation of a general-availability, universally-accessible phone system. That works only if it is not systematically abused, which is presently the case. If trust in public-switched telephone networks, permitting direct-dial access to any other number, anywhere in the world, is lost, what we'll see is desertion to other options which serve specific individuals' and organisations' interest. We are already beginning to see this, though no one clear winner has emerged. Unfortunately, most of the alternatives are proprietary, though some federated networks might prove to be viable alternatives.

Post reply on HN