Live data from Hacker News

FCC bars providers for non-compliance with robocall protections

docs.fcc.gov

211–220 of 281 posts

Re: FCC bars providers for non-compliance with robocall protections

#211
post #179

Earlier quoted context omitted.

This is a corollary to Chesterton’s fence. unsignedint’s public good. If you can’t explain the benefit then you can’t tear it down. The PSTN guarantees that all telco operators interoperate. Without it you get what happened with instant messaging. AKA walled gardens. You take for granted the ability to call an iPhone with an Android. The FCC is responsible for maintaining trust, which they have done here. They can in…

I think Chesterton’s fence is a fair analogy—but it only works if the “fence” still serves a protective function. With the PSTN, the fence is riddled with holes, and the people meant to maintain it can’t keep up with the erosion. Interoperability was indeed its greatest strength, but today that same universality is what lets malicious actors reach everyone at trivial cost. Comparing PSTN to instant messaging walled g…

I don’t find “good chunk” compelling. I think you need to do a more rigorous analysis of the costs and benefits. FCC is fully capable of creating the incentive structure to maintain a spam-free PSTN. This is a political problem.

IP addresses and phone numbers are indistinguishable in the context of spam. If you successfully argue that the PSTN cannot be operated at a net benefit to society because of spam volume the same argument must also be a valid call to shut down the Internet.

Re: FCC bars providers for non-compliance with robocall protections

#212

Earlier quoted context omitted.

I think Chesterton’s fence is a fair analogy—but it only works if the “fence” still serves a protective function. With the PSTN, the fence is riddled with holes, and the people meant to maintain it can’t keep up with the erosion. Interoperability was indeed its greatest strength, but today that same universality is what lets malicious actors reach everyone at trivial cost. Comparing PSTN to instant messaging walled g…

> Comparing PSTN to instant messaging walled gardens is interesting, but I’d argue the real parallel is email: a federated, open standard that also suffers from spam and abuse, yet still manages to limp along thanks to heavy filtering and layered trust systems. I think you're absolutely right to draw that parallel. But, today's email landscape isn't much of a federated open standard. It's a web of trust and distrust,…

Yes, absolutely — I’m not suggesting email is anywhere near perfect or free of abuse. But at least collectively, the layers of filtering, reputation systems, and standards make it usable for most people most of the time.

The key difference for me is that the PSTN moves at a snail’s pace, maybe because of regulatory entanglements, maybe because of interoperability constraints. The result is that problems which have been rampant for decades — spoofing, spam, robocalls — remain trivial to exploit. Email has plenty of its own problems here, but at least you get more signals to work with (headers, DKIM/SPF/DMARC, filtering, etc.) than just a string of 10–12 digits with no real context.

That’s why I’m less inclined to “cherish” a system whose shortcomings shift so much burden onto the end user’s well-being, all in the name of interoperability. If interoperability means putting up with abuse at this scale, then that interoperability isn’t worth much — and that’s where my frustration comes from.

Re: FCC bars providers for non-compliance with robocall protections

#213
post #38

I'll definitely believe it when I don't see those calls, but I could not be more in favor of turning the phone network into a much more "trusted" type of system -- similar to how SSL certs used to be prior to the Let's Encrypt era, where it requires some form of validation of something besides 'existence': Conceptually, someone US-based should have to cryptographically sign, with their license to continue participati…

Categorizing “whistleblower needs to talk to journalists” as a cliche really undermines your argument here. This isn’t an insurmountable problem. We have regulatory frameworks. FCC has proven they have teeth. It’s a political problem we can solve without losing any of the benefits of the PSTN.

Re: FCC bars providers for non-compliance with robocall protections

#214
post #211

Earlier quoted context omitted.

I think Chesterton’s fence is a fair analogy—but it only works if the “fence” still serves a protective function. With the PSTN, the fence is riddled with holes, and the people meant to maintain it can’t keep up with the erosion. Interoperability was indeed its greatest strength, but today that same universality is what lets malicious actors reach everyone at trivial cost. Comparing PSTN to instant messaging walled g…

I don’t find “good chunk” compelling. I think you need to do a more rigorous analysis of the costs and benefits. FCC is fully capable of creating the incentive structure to maintain a spam-free PSTN. This is a political problem. IP addresses and phone numbers are indistinguishable in the context of spam. If you successfully argue that the PSTN cannot be operated at a net benefit to society because of spam volume the…

I only said “good chunk” because there are already more than a few reports pointing to a shift in behavioral patterns around calls. (Feel free to Google, Bing, or DuckDuckGo it when you have a chance.) The point is less about an exact percentage and more about the fact that user behavior has already adapted in ways that erode PSTN’s practical value.

And if the FCC were fully capable of solving this problem, I don’t think we’d still be here after decades of the same issues. That longevity itself is part of my argument: it’s not that people haven’t tried, it’s that the structural limitations resist a clean fix.

Also, IP addresses aren’t a great analogy. They’re not a sole indicator of origination — we have layers of metadata, routing, and reputation systems around them. I’d accept that comparison more readily if phone numbers were spoof-proof. But they aren’t, and that’s yet another area where the FCC hasn’t managed to close the gap.

Re: FCC bars providers for non-compliance with robocall protections

#215

Earlier quoted context omitted.

My theory is age. I get very few calls. Neither does my wife. My mother in law is called multiple times a day. I assume there’s some basic demographic data available out there and they’re targeting retirees because they know (statistically speaking) they’re an easy hit.

I think an important factor is also how long you had the same number. I switch numbers every couple of years because I get a new contract and moving the number to the new company is such a hassle. Over time you share your number with more and more companies and people who sell it or get breached. My parents had their number for ~30 years. I never get spam calls or texts. They get one once a week or so (this is in Ger…

I’ve had the same cell phone number for 25 years across 5 carriers and get maybe 1 spam call a week.

Re: FCC bars providers for non-compliance with robocall protections

#216
post #138

Earlier quoted context omitted.

As others have alluded, there are unknown third parties who must call you (and you would want their call). For example, the hospital: something has happened with a loved one. We can probably solve this problem with certification. Show me your medical license (or hospital scale equivalent) and you get to make unsolicited calls. Then we allow people to select certified unsolicited calls by category: medical, financial,…

Even in this case, I'd rather get a text message. A mere call doesn't provide any context and is not informative. Maybe your loved one showed up in their ER or maybe it's a billing issue. The text message should explain the nature of the call and which number to call in reply.

How is that practically any different than a voice mail with an automatic transcription that you can see real time and after the call?

Re: FCC bars providers for non-compliance with robocall protections

#217

Earlier quoted context omitted.

> Comparing PSTN to instant messaging walled gardens is interesting, but I’d argue the real parallel is email: a federated, open standard that also suffers from spam and abuse, yet still manages to limp along thanks to heavy filtering and layered trust systems. I think you're absolutely right to draw that parallel. But, today's email landscape isn't much of a federated open standard. It's a web of trust and distrust,…

Yes, absolutely — I’m not suggesting email is anywhere near perfect or free of abuse. But at least collectively, the layers of filtering, reputation systems, and standards make it usable for most people most of the time. The key difference for me is that the PSTN moves at a snail’s pace, maybe because of regulatory entanglements, maybe because of interoperability constraints. The result is that problems which have be…

> at least you get more signals to work with (headers, DKIM/SPF/DMARC, filtering, etc.) than just a string of 10–12 digits with no real context.

For most people it is a distinction without a difference because they know about as much what to do with a DMARC policy as they do an SS7 frame.

DKIM/SPF/DMARC as bandaids just as much as STIR/SHAKEN are, they just need to get a kick in the ass to implement them -- on both fronts. I get tons of official and sensitive email still from domains that fail DMARC.

Re: FCC bars providers for non-compliance with robocall protections

#218

Earlier quoted context omitted.

Yes, absolutely — I’m not suggesting email is anywhere near perfect or free of abuse. But at least collectively, the layers of filtering, reputation systems, and standards make it usable for most people most of the time. The key difference for me is that the PSTN moves at a snail’s pace, maybe because of regulatory entanglements, maybe because of interoperability constraints. The result is that problems which have be…

> at least you get more signals to work with (headers, DKIM/SPF/DMARC, filtering, etc.) than just a string of 10–12 digits with no real context. For most people it is a distinction without a difference because they know about as much what to do with a DMARC policy as they do an SS7 frame. DKIM/SPF/DMARC as bandaids just as much as STIR/SHAKEN are, they just need to get a kick in the ass to implement them -- on both f…

Sure, but my point still stands — you have more tools to work with in email. For what it’s worth, I can usually contextualize a message from the subject line and the sender’s address without needing to dive deep into headers. (Phishing is definitely a real problem, but it’s not unique to email in this discussion.)

Now compare that to the PSTN: what does 555-123-4567 really tell you? Not much. It’s just a string of digits with no inherent context. And unlike email, I can’t even choose to outright refuse delivery of a call at the network level.

Re: FCC bars providers for non-compliance with robocall protections

#219

I get relentless text and phone spam calls - both robotic and with humans - from just a few voice over Internet platforms. Bandwidth.com, Neutral Tandem, and ALL the brands associated with Sinch ( https://en.wikipedia.org/wiki/Sinch_AB ) like Inteliquent. Many of these companies got cease and desist orders in the past from the FTC. It didn’t help anything. We need to see them fined, shut down, and executives jailed.

How would one discover which VOIP providers are the source of calls?

https://freecarrierlookup.com/

There are other sites like this. And then you can use the carrier info, go to that platform‘s website, and submit an abuse complaint through their form. But all they will do is possibly block that one spammer from contacting your phone number while continuing to allow the spammer to operate. And of course they have other spammers as customers.

Better option is to skip their abuse form and send complaints to your state’s AG, to the FTC website, and FCC website. They’ll ask for a lot of info but I think it helps them identify the problematic companies.

You can also forward spam texts to 7726 (“SPAM”) in the US, and your carrier will use that info to take action.

Re: FCC bars providers for non-compliance with robocall protections

#220

At this point I'm firmly of the opinion that "leak this 10 digit code and anyone on the planet can call me relentlessly" is just a broken model. Maybe that worked better when the calls carried a significant cost, but clearly the scammers are able to do this sort of thing at scale. In practice of course, my phone is 100% permanently in "do not disturb" mode and does not ring at all unless I've added you to my contact…

Imagine if the concept of a phone call did not exist. We still have these computers in our pockets, but without the history of the telephone system. Then, one day, an app developer thought: Wouldn't it be cool if there was an app that would interrupt what the user was doing, play a sound, vibrate the device, and put up a full-screen dialog, that this all could be activated remotely by any other device by simply typin…

> Then, one day, an app developer thought: Wouldn't it be cool if there was an app that would interrupt what the user was doing, play a sound, vibrate the device, and put up a full-screen dialog, that this all could be activated remotely by any other device by simply typing in a short numeric code

When you're actively using your smartphone, phone calls show up as notifications, not full-screen dialogs (which trips up my non-technical relatives, since they don't know how to answer a call through the notification). Given that, it's not that different from what we had on computers with instant message applications like ICQ. In a world without the concept of phone calls, they would be a natural evolution from these instant messengers (and, as I'm sure you remember, ICQ used a short numeric code as the user identity).

Post reply on HN