Earlier quoted context omitted.
How do you reach that conclusion based on what I've written?
Because it happened to everything else where this idea was tried.
And no specific instances or mechanisms detailed, to boot.
Thanks.
141–149 of 149 posts
Earlier quoted context omitted.
Sure, if someone gave me a false phone number to call them on, I could be declared a spammer. If I had to call more than 3 people a day ordinarily, I could be declared a spammer. I'm basing these on what already happens in the banking sector as a direct result of the regulation you want.
What would be a sufficient appeals process or remedy action that might address your concern? What activities are you engaged in which make you think you'd likely be considered a spammer? What specific harms do you see occurring? Might these be related to your present line of business / profession / employment?
Earlier quoted context omitted.
Jim is a good guy and ATIS tried real hard with STIR/SHAKEN, but technology cannot overcome the commercial incentives that carriers have to let this nonsense continue. I've written about this before too [0]. [0] https://news.ycombinator.com/item?id=48920432#48928781
I'd seen your earlier comment at the time. Your follow-up, here ( https://news.ycombinator.com/item?id=48938169 >), was particularly insightful, and has influenced my thinking. Essentially: authentication / validation should happen out of band with phone number itself, for the reasons you've given. I do suspect that for routing authentication, header-level signifiers should be reasonably useful, but for strong identi…
AT&T took some bad press around that time, and in July 2016, the FCC, facing political pressure, and now sensing that the PR gods were now on their side, leaned on the major carriers to set up a 'task force' to get things moving. I remember sitting in the little room at the FCC while various telco industry grandees bloviated. We all agreed that ATIS and IETF should define technical standards since they'd already made a start (Jim M did ATIS, for example) and so everyone agreed that STIR/SHAKEN was going to be The Path.
The original STIR/SHAKEN assumptions were that the attestation would be carried throughout the network in a SIP header and that every SIP processing element would deal with it. Reality soon intruded in the form of ancient telco equipment that didn't have the headroom to process another bunch of bytes in every call setup message. Another idea was to have signing and verification done by SIP application servers, but that didn't pan out for the same reasons. (Forgive me, I'm going to toot my own horn here for a second:) I invented a scheme with my colleagues where the signing or verification was an HTTPS operation triggered by the SIP device at the network perimeter (a 'session border controller' in telco-speak) which made the problem more tractable. AT&T took my PowerPoint and submitted a stunningly close copy as their own to the FCC. I still have the slides somewhere. I was salty at the time but ah well, what can you do: my employer still made money off the product with other customers.
Earlier quoted context omitted.
I'd seen your earlier comment at the time. Your follow-up, here ( https://news.ycombinator.com/item?id=48938169 >), was particularly insightful, and has influenced my thinking. Essentially: authentication / validation should happen out of band with phone number itself, for the reasons you've given. I do suspect that for routing authentication, header-level signifiers should be reasonably useful, but for strong identi…
Yes, I think that is it. Thank you for finding it! AT&T took some bad press around that time, and in July 2016, the FCC, facing political pressure, and now sensing that the PR gods were now on their side, leaned on the major carriers to set up a 'task force' to get things moving. I remember sitting in the little room at the FCC while various telco industry grandees bloviated. We all agreed that ATIS and IETF should d…
I've heard the "but we can't filter traffic at the network level" line from AT&T much more recently than that date. If there's any corporate learning that's occurred, it's not filtered through the ranks.
It seems as if sorting out the STIR/SHAKEN situation with smaller telcos is going to have to happen. How that happens is something I don't have much clarity on, though I suspect some degree of national regulation and assistance will be required in the US. Your work could be an element of that?
I've been ... unhappy ... with telecoms options for well over a decade now, and predicting the #DeathOfTelephony (one of my Fediverse topics/tags) for much of that time. It's coming about more slowly than I'd expected/hoped, but I'm seeing lots of strain. Enterprise/organisational frustration has been increasingly apparent over the past five years or so. Millennials and onward (as well as many Gen Xers) actively avoid voice calls. It's simply getting hard to connect to people. Then there's the privacy / surveillance / propaganda / manipulation elements.
I think what I'd like is a SIP trunk to the house, and manage remote calls over WiFi (possibly with a SIP phone, I've got an old GSM 2G I'm thinking of doing some hardware-hacking on, or I could buy something ready-made). Carry a standard mobile for emergencies, but avoid it if at all possible, and route most comms through the VOIP system with a bunch of bespoke rules.
If I were running a business there'd be other considerations. I'm ... glad I'm not, for the moment.
The extent to which something vaguely resembling that might be more widely used ... I'm not sure. I'm thinking through elements I'd like to incorporate, might post that later (probably to the Fediverse or elsewhere for now).
The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the cal…
The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the cal…
Sounds like a great way to strongly incentivize a new form of fraud--fraud-reporting fraud! Imagine how much fraudsters could gain by reporting thousands or tens of thousands of "fraud" calls that they themselves both originate and report from existing SIM farm infrastructure. Any deployment weakness or hole in blocking malicious traffic in the global telecommunications network all of the sudden becomes akin to a wea…
After that that scam would result in the scammer paying the (e.g.) $10 upfront, the (up to; e.g.) 10% for every hop between networks and likely and transaction, processing and legal fees for the civil case (if he's not cooperating).
And he'll likely end up with criminal charges on top of that.
Also it's not like the scammer gets sued by some powerless private citizen authorities are likely to ignore. His opponent will be a telecom provider in his own jurisdiction.
The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the cal…
"Cold calling" can either come from governmental organizations (IE, call from the police), or someone or some organization in your network can grant access to call, text, email, ect on their behalf.
The result is that SPAM has a chain of traceability, so you can then block people and organizations in your network who make unwanted calls.
Furthermore, regulation is needed so that your cable company can't pull dumb nonsense like saying "telemarking is required to use our service": This is where the SPAM button that you propose really comes in handy, because it holds accountable the fools who think that selling their customers' contact information is a good idea.