Live data from Hacker News

A Call to Action: Stop the FCC's KYC Regime

blog.lopp.net

141–150 of 248 posts

Re: A Call to Action: Stop the FCC's KYC Regime

#141
post #10

Earlier quoted context omitted.

Counterpoint: for my part I would like it to be the case that any phone line that can dial or message my phone can be traced back to a known human being who can be held accountable for abuse of that phone line in terms of generating spam, abuse or harassment. Seems that we can’t both get what we want. A potential solution is that you get your anonymous phone line but my phone provider simply refuses to let you call m…

It should show up as anonymous. And you should have a setting: allow anonymous calls y/n

.. precisely what I asked for?

Re: A Call to Action: Stop the FCC's KYC Regime

#142
post #53

In my opinion, the real fix to scam, spam, and robocalls is to pass along the REAL(TM) Caller ID information not just the caller ID but the actual billed Caller ID information and allow the recipient easy ways to drop the calls when those two don't match. I don't know exactly the technical details of Stir/Shaken but someone somewhere is paying / getting paid for each call and this information should be transparently…

I was nodding in agreement, but I realized there must be some catch here. If this was that simple it probably could've been implemented a while ago. My guess is that there's some requirement that if it's a working number, it must be able to dial emergency services and that's the loophole that's being exploited. So the FCC's answer is if all numbers must work, push the check directly on the subscriber.

In theory, yes. I would hope all the things that are "common sense" and "simple" would have already been implemented. However, as my professor of History from college loved to say "follow the money". If something could be simple and straightforward but is implemented in a convoluted way that is clearly suboptimal, someone somewhere makes more money as a result. It could be as transparent as Google Chrome implementing auto play with a "Media Engagement Index (MEI)", Apple being forced to implement USB-C on the iPhone kicking and screaming, or carriers and large call centers dragging their feet on doing STIR/SHAKEN correctly and passing along the billing information that I will remind you they already have because they like to get paid. So, while we hope common sense previals, at the end of the day, it only does so automatically when it makes business sense.

To your point about emergency services—while it's true that any unactivated phone must be allowed to dial 911, that rule only opens a one-way path to emergency dispatch. It doesn't give a device the ability to place outbound calls to everyday citizens. The real loophole isn't a public safety mandate; it's the wholesale VoIP market.

Re: A Call to Action: Stop the FCC's KYC Regime

#143

Earlier quoted context omitted.

Spoofing isn’t ended at all Almost every spam call has that I get, is spoofed. Someone here explained it, once. I think the spoofed calls use a legacy transport tech that can’t be forced to validate.

How do you verify it is spoofed? Have you asked your carrier to drop unverified calls from your service?

> How do you verify it is spoofed?

Not my job to "verify," in the technical sense.

When a call for an Indian crypto pump comes in as "SMITH, ROBERT", and a local exchange, I call that "spoofed."

Re: A Call to Action: Stop the FCC's KYC Regime

#144

Earlier quoted context omitted.

Counterpoint: for my part I would like it to be the case that any phone line that can dial or message my phone can be traced back to a known human being who can be held accountable for abuse of that phone line in terms of generating spam, abuse or harassment. Seems that we can’t both get what we want. A potential solution is that you get your anonymous phone line but my phone provider simply refuses to let you call m…

> Seems that we can’t both get what we want. Why can't you? They don't want to provide info for a credit check, you want human accountability. All that requires is for them to use a debit card for whatever service (prepaid or postpaid). Law enforcement can trace that if needed. No need for credit checks or really any other information directly in the hands of the telco.

This is an argument in favor of KYC requirements for telcos, just that it assumes they can outsource it to banks.

Re: A Call to Action: Stop the FCC's KYC Regime

#145
post #86

Earlier quoted context omitted.

Sure, but with phone numbers that can't be spoofed, telcos can terminate service, and filtering technologies can block calls. Spam gets expensive if you have to buy new service every five calls.

It does. But the spammers still do it. Because eventually they hit one person who gives them a thousand dollars or whatever and it pays off.

Preventing spoofing doesn't have to make spam cost-prohibitive for every spammer to greatly reduce the volume, and it does not interfere with ordinary people obtaining phone service anonymously.

Re: A Call to Action: Stop the FCC's KYC Regime

#146
post #135

We just need a new phone system where 'phone numbers' are designed to be disposable. Phone numbers were designed with the idea that they need to be easily memorizable in your head but I don't think that's really needed today. At any moment I should be able to discard my contact and redistribute it on my own. The idea that old numbers get recycled is completely ridiculous as well.

We need to get rid of phones straight up. No one should be able to interrupt someone else by randomly ringing them and demanding attention.

I mean I think that is ok as long as I explicitly allowed you to.

The problem is, with a phone number anyone can. Phone numbers need to operate more like a shared secret.

I was getting an oil change the other day and the guy asked me for my phone number...

I said why? Do you need to call me?

He said, no we just need it to put in the system and it won't let me proceed without one.

I said ok well here is a fake number since you don't need to contact me.

He was visibily frustrated with me, yet inputed the fake number and it allowed him to proceed.

My point with sharing this story is it seems like we have forgotten as a society what the purpose of the phone number is. Your supposed share it when you want to be able to communicate that's it.

It's turned into a required chokepoint to do anything.

Re: A Call to Action: Stop the FCC's KYC Regime

#147

Earlier quoted context omitted.

We need to get rid of phones straight up. No one should be able to interrupt someone else by randomly ringing them and demanding attention.

You can trivially accomplish this under the current system. There is no need for a change that imposes your preferences on everyone.

Do tell for a laymen like me.

Re: A Call to Action: Stop the FCC's KYC Regime

#148

Earlier quoted context omitted.

What ever happened to SHAKEN/STIR? I thought this was supposed to happen 5 years ago. Did they just chicken out on the prospect of actually shutting down telcos sending spam volume? I still get loads of spam phone calls, so clearly something went wrong (or slow enough to be indistinguishable from wrong).

I love a good tortured acronym: > SHAKEN system, short for Signature-based Handling of Asserted information using toKENs [...] > The name was inspired by Ian Fleming's character James Bond, who famously prefers his martinis "shaken, not stirred". STIR having existed already, the creators of SHAKEN "tortured the English language until [they] came up with an acronym." https://en.wikipedia.org/wiki/STIR/SHAKEN (Unrelate…

I like backronyms because it tells me someone with a soul was involved

Re: A Call to Action: Stop the FCC's KYC Regime

#149
post #53

In my opinion, the real fix to scam, spam, and robocalls is to pass along the REAL(TM) Caller ID information not just the caller ID but the actual billed Caller ID information and allow the recipient easy ways to drop the calls when those two don't match. I don't know exactly the technical details of Stir/Shaken but someone somewhere is paying / getting paid for each call and this information should be transparently…

I was nodding in agreement, but I realized there must be some catch here. If this was that simple it probably could've been implemented a while ago. My guess is that there's some requirement that if it's a working number, it must be able to dial emergency services and that's the loophole that's being exploited. So the FCC's answer is if all numbers must work, push the check directly on the subscriber.

They make too much money from the spammers. Who wants to cut out such a large revenue stream?

Re: A Call to Action: Stop the FCC's KYC Regime

#150

We really just need telcos to stop allowing caller id spoofing. Doesn’t even need your name, but with a real number we could actually report these scams. You can still allow people to hide it, but then by default every non-business phone should block calls with hidden numbers.

Medical offices hide their numbers for very good reasons: if you've got an abusive spouse, you often don't want the medical office in your call history. Which results in a lot of very important calls being ignored.
Post reply on HN