Live data from Hacker News

US Anti-Robocall Litigation Task Force

thecentersquare.com

191–200 of 223 posts

Re: US Anti-Robocall Litigation Task Force

#191
post #83

Earlier quoted context omitted.

I never, ever get legitimate calls from overseas. Just turn those calls off for my phone. Well, perhaps callbacks from helpdesks located in other countries, in which case give me time-boxed control over foreign calls, and perhaps a passcode that I can communicate along with my callback number. There are billions of dollars at stake, of course. This is a solvable problem, and the FCC doesn't even need to get involved.…

The problem is someone from overseas can claim to be from a US number. The number you see on your phone can be anything the caller wants it to be. A fair number of robocalls are from overseas but looks to you like they come from your country.

That's precisely what the carriers need to solve.

They're not interested.

Re: US Anti-Robocall Litigation Task Force

#192
post #3

Earlier quoted context omitted.

Websites have been given a practical choice between annoying popups and blocking Europe. It makes my life better when they block Europe, and I wish more did. I also wish Europe got rid of the GDPR.

Wouldn't you rather websites just stop invading your privacy? The EU is not to blame for the shitty business practices of these websites.

GDPR has compliance costs even if you are doing nothing that violates privacy. As long as you've got data that can be associated with a user you might have GDPR obligations, including handling inquiries from users about what data you have about them, requests from users to delete their data, and similar.

Just being able to receive such requests has costs, because GDPR requires that you have a contact in the Union that users can contact for such things.

So say you've got an online forum in California and some EU people join and participate. Whether or not that is enough to make you subject to GDPR depends on Article 3(2). There's lots of subjectiveness in Article 3(2) so it is not at all clear where the boundaries are.

If it does, then whether or not you have to have an in-Union representative is covered under Article 27. You do not need one if your processing of covered data is all of the following: (1) occasional, (2) does not fall under some special categories of data, (3) is unlikely to result in a "risk to the rights and freedoms of natural persons".

That's pretty fuzzy. What is occasional processing?

If you aren't sure that GDPR does not apply, or aren't sure that if it does your processing is occasional enough to fly under Article 27's radar, you need an Article 27 representative.

Eventually there will be rulings from EU data regulators that will make the boundaries of Article 3(2) clearer, so that you may be able to stay in "does not apply" without blocking. Or maybe rulings will clarify Article 27 so you will be able to confidently determine that your processing is occasional enough to not need a rep.

There's actually a lot of unclarity in GDPR. Take the data subject's right to have you delete their data. How do you actually implement that? Writing some scripts to delete from your database is probably not too hard.

But what about backups? Do you need to go through all your backup sets and delete their data from those? What about printed records (yes, GDPR covers printed data)? Offsite long term archives?

For a site like a forum, what about data that was in messages they posted that were quoted in messages from other users?

Until all these kind of things are cleared up by EU data regulator rulings it can make a lot of sense for a site that is aimed mainly at a non-EU audience to block EU users.

Re: US Anti-Robocall Litigation Task Force

#193
post #47

Earlier quoted context omitted.

In Canada and while I do get some it’s fairly rare. Maybe 1 a month.

Anecdotes do not constitute data. My family in Canada gets tons of robocalls and spam calls, to the point that nobody answers unrecognized numbers unless they're expecting a call...

Have they signed up for the national do not call list or renewed it? as it expires iirc. My friends in the same boat often never signed up like I did.

Re: US Anti-Robocall Litigation Task Force

#195
post #119

Earlier quoted context omitted.

Yes, there are lots of solutions if there is a genuine attempt to solve the problem and not just dance around it. Political calls and texts should absolutely be blockable by users if they so choose. Cost-based calling may not be practical, IMO. I look at the amount of junk mail I get from the USPS and I am not sure a "sender pays" approach would result in a meaningful reduction with a cost structure that didn't also…

Just an FYI, FTC has a signup for junk mail just like they do for phone calls. I just do the prescreen one and the only junk I get now is for previous tenants. Unfortunately I don't know how to solve that one. https://consumer.ftc.gov/articles/how-stop-junk-mail

Ugh. That's an awful solution. In order to not be spammed and have your privacy invaded, you have to submit information about yourself to the bad actors in the first place. Plus you have to pay them for the privilege of not harassing you, and on top of it, they only stop for 10 years and then you have to do it all over again. It's fucking ridiculous. This is not a real solution.

Re: US Anti-Robocall Litigation Task Force

#196

Earlier quoted context omitted.

Just an FYI, FTC has a signup for junk mail just like they do for phone calls. I just do the prescreen one and the only junk I get now is for previous tenants. Unfortunately I don't know how to solve that one. https://consumer.ftc.gov/articles/how-stop-junk-mail

Ugh. That's an awful solution. In order to not be spammed and have your privacy invaded, you have to submit information about yourself to the bad actors in the first place. Plus you have to pay them for the privilege of not harassing you, and on top of it, they only stop for 10 years and then you have to do it all over again. It's fucking ridiculous. This is not a real solution.

It is awful, but they already are buying that information tbh. So I'm not sure there's an information gain through this. I don't do the paid service (which is $2... come on...) and my spam (phone and mail) is significantly reduced. It's not a perfect solution, but it is a real solution.

Re: US Anti-Robocall Litigation Task Force

#197

Earlier quoted context omitted.

My doctor (well, their hospital system) uses Epic/MyChart as their EMR. I also have the MyChart app on my phone. I get a push notification via the MyChart app when anything new posts to my chart - no phone call, text, or email required. And I don't want the push notifications, I could opt out of that too. Surely most doctors offices use a vanishingly small amount of EMR providers, and they could support similar very…

The people who use the hospital system the most are the ones who are the least likely to be able to use those functions effectively.

Never underestimate how out of touch and incapable of understanding other people HN nerds are.

Re: US Anti-Robocall Litigation Task Force

#198
post #97

Phone companies are trying to turn this problem into a revenue generation “opportunity”. Not only do they get paid for the calls that traverse their network, but now they also want you to sign up for their “premium” blocking services, at a monthly cost, to stop them. This screams for not only a crackdown on the bad carriers who initiate the calls, but also on the big telcos who are double-dipping.

What companies sell this additional premium service?

AT&T allows you to sign up for enhanced protection for $3.99/mo.

Re: US Anti-Robocall Litigation Task Force

#199
post #140
post #100

Earlier quoted context omitted.

I thought it was a legal requirement for phone network operators to leave phone numbers accessible to all Is it a legal requirement to allow spoofed caller ID from bad actors? Spoofed IP addresses used to be a much bigger problem on the Internet than they are today (many examples but see Smurf Attack). We collectively implemented security to reduce the threat. Phone companies could do the same for spoofed caller ID f…

> Spoofed IP addresses used to be a much bigger problem on the Internet than they are today (many examples but see Smurf Attack). Most of the large DDoS attacks are UDP reflection, the attacker spoofs the victims address and sends to chargen[1] servers or whatever. So spoofing is still alive and well. [1] yes really, the worst ones are people who install Microsoft's Services for Unix and enable the chargen server to…

How long have you been on the Internet? I ask because I started an ISP in 1996 and IP address spoofing used to be soooo much worse.

Today’s situation is the product of literally 2.5 decades of encouraging and/or shaming Internet-connected networks into properly configuring their routers to drop spoofed packets egressing from their network with a spoofed IP address not from their network.

Re: US Anti-Robocall Litigation Task Force

#200

An idea: Would it be possible to use phone number “extension” conventions to create a shared secret key that verifies that the caller is a trusted contact? Let’s say I’m at the DR’s office and I’d like them to call me with my test results. Before giving them my phone number, I pull out my phone, open the phone app, and tap the “new trusted contact extension” button. It then displays the text “ext 47901” and prompts m…

A similar idea that a friend of mine implemented is, when he gets called, the caller hears this message "Thanks for calling (name); press one to be connected immediately" This filters out pretty much all spam!

It probably filters out legit calls, too. I used to have an answering machine (in the late 90s or early 2000's) that allowed you to have voice mailboxes for different people. We had it set up so you could "Press 1 to leave a message for (me), Press 2 to leave a message for (my spouse)". It was smart enough that if the caller didn't press a number, it would still record a message and put it into a catch-all category. Literally every call, even from friends and relatives, went into the catch-all category. I tried calling our phone from a friend's house and testing it out to make sure I hadn't set it up incorrectly. It worked just fine, but nobody ever pressed any number. They just heard, "Hi, we're not at home..." then ignored everything else and waited until they heard a beep.
Post reply on HN