Live data from Hacker News

Ask HN: How can scam callers fake a mobile phone number?

news.ycombinator.com

151–156 of 156 posts

Re: Ask HN: How can scam callers fake a mobile phone number?

#151
post #150

Earlier quoted context omitted.

It’s remnants from a time where security wasn’t a concern. The original intent of the From: field in email was that it’s definitive, but now it’s just a legacy field that many systems ignore because it’s fakeable.

Is it because earlier there was no display of numbers (ex in rotary phones)?

Possibly, but I'd wager more that it was due to Bell owning the entire network, so they knew that any "from" numbers were correct. If I'm reading Wikipedia right, SS7, which is still supported today, was created all the way back in 1975![0] Bell wasn't broken up until 1982.[1]

[0]: https://en.wikipedia.org/wiki/Signalling_System_No._7

[1]: https://en.wikipedia.org/wiki/Breakup_of_the_Bell_System

Re: Ask HN: How can scam callers fake a mobile phone number?

#152
post #113

Earlier quoted context omitted.

Or they'll leave a message. The real answer to the problem is to deprecate the legacy telephone system. It will never be as secure or user-configurable as just about any modern implementation of voice/video over IP.

>deprecate the legacy telephone system The legacy telephone system is being deprecated. All three US mobile operators now have VoLTE (ENUM) interconnection with each other. STIR/SHAKEN call verification is happening between the mobile operators and large consumer VoIP operators like Comcast and Charter. VoIP is far cheaper to operate than POTS and most all operators are using it now and shuttering their legacy networ…

Thanks for the educational response! I've been long wondering why it seems as if carriers are implicit in the widespread scam.

Re: Ask HN: How can scam callers fake a mobile phone number?

#153

Earlier quoted context omitted.

Also possible if they gave malware on the computer, and it modifies search results in the browser. That’s always seemed like a serious vector although I haven’t heard much in the way of in the wild exploits.

Computer malware + phone scam sounds like a remarkably targeted, technically broad, and labor intensive attack.

It is, which means it targets higher net worth individuals. I just listened to a darknet diaries episode where they talk about how much these attacks cost to execute - some are $10-100k per target.

Re: Ask HN: How can scam callers fake a mobile phone number?

#154

Signalling system 7 has no authentication. That's the bottom line. Adding authentication is pretty obviously not trivial, not just because of protocol upgrade issues, but also because end-to-end authen. won't be easy to add at all, and hop-by-hop authen. w/ something like "egress filtering" won't work in the age of phone number portability. What might work is a TCP-like return routability test. I.e., have the network…

Here in China they aggressively egress filter since ~15 years ago (source: had an E1 on fiber way back then). You can set caller ID to any number you are assigned and nothing else.

Yes, this would work. It would have to be implemented in a lot of telcos. It would take time to get it all deployed, but there's no better time for this than today.

Re: Ask HN: How can scam callers fake a mobile phone number?

#155
post #118

Earlier quoted context omitted.

It's not as easy... For example, it is possible and legal to use your own number to call from a VoIP provider, so the recipient can call you back on your actual phone. On the other hand, it should be possible to detect at least a percentage of spoofed caller IDs and block them (e.g. non-existing numbers).

The VoIP provider could forward the call to your phone as a middleman, or there could be 3 numbers(1. Who to bill 2. Calling number 3. Reply-to number) and only #3 is user-configurable.

The idea of using a VoIP provider would be to _avoid_ using one's phone, e.g. to get better rates... And the reply-to number, it's unfortunately not the way telcos work... and changing all the infrastructure for this would be very very expensive.

Re: Ask HN: How can scam callers fake a mobile phone number?

#156
post #16

Hoping this is something that doesn't need to be said here, but just in case: This is why you should NEVER provide personal information over the phone if you didn't initiate the call. It doesn't matter if your caller ID says it's your doctor's office or your bank or whatever. Hang up and call them back at the number you normally use to reach them, from their website or the back of your credit/debit card for example.…

This. A while ago, my wife got a call from a collections agency on my phone. They asked for her name, I asked "which one?" She said "I can only talk to ____." I said, "I understand but which one would are you looking for the older or younger?" "I can't share that information." "Then I can't put you in touch with who you're looking for if you can't tell me who you're looking for." "I can only speak with ____." I said…

I once sold a house while in a different state, and the real estate agent was positively baffled that I wanted to know how the person who was supposed to collect my banking information and identifying information would identify himself to me.

They really just expected me to meet some guy in a polo shirt at a coffee shop and let him take a snapshot of my passport and all my bank account info.

Frankly scammers have it too easy when the real thing works like this!

Post reply on HN