Live data from Hacker News

A Call to Action: Stop the FCC's KYC Regime

blog.lopp.net

31–40 of 248 posts

Re: A Call to Action: Stop the FCC's KYC Regime

#31
It's even worse: Since cell phones broadcast your location at all times, this means telling hundreds of companies (and a number of governments) your location at basically all times.

That's already an issue with most cell phones. Making this apply to prepaid phones is even worse.

Re: A Call to Action: Stop the FCC's KYC Regime

#32

"force phone providers to collect identity information from ordinary people before they can acquire or renew service with a phone carrier." don't see the harm in this? isn't this already the case for 99.9% of phoneline havers already?

Almost no one has physical phone lines anymore. It also used to be a given because they had to send a physical paper bill to someone, and hence needed an address.

Neither of these are true anymore.

Also, the tone is set from the top.

Do you think the current admin cares about actually tackling fraud and abuse?

Re: A Call to Action: Stop the FCC's KYC Regime

#33

Earlier quoted context omitted.

What ever happened to SHAKEN/STIR? I thought this was supposed to happen 5 years ago. Did they just chicken out on the prospect of actually shutting down telcos sending spam volume? I still get loads of spam phone calls, so clearly something went wrong (or slow enough to be indistinguishable from wrong).

I'm not certain, but I think on my phone incoming calls that fail SHAKEN/STIR show the caller id in red rather than black text. I'm on T-Mobile. It also shows "Number Verified" or something like that.

Now that you mention it, I believe I have seen a couple of red flagged calls, but I still get ~3 calls a day from a very aggressive business loan spammer, it's always a new number and never flagged.

Re: A Call to Action: Stop the FCC's KYC Regime

#34

"force phone providers to collect identity information from ordinary people before they can acquire or renew service with a phone carrier." don't see the harm in this? isn't this already the case for 99.9% of phoneline havers already?

You don’t see the harm in requiring telcos - famous for handing over data without warrants or court orders - being forced to have identifying data for every subscriber? I can think of a half dozen ways that can get abused. Remember that in the states policing is decentralized. There is always some department somewhere willing to abuse their power. Look at how flock has been used to stalk partners, or how geofencing w…

> famous for handing over data without warrants or court orders

More concretely, famous for supplying bulk data to the surveillance industry for a nominal fee. That is ostensibly the goals behind this development - all of these companies demanding phone numbers for "verification" and snake oil "2FA" want to reliably dox 100% of their users rather than just 80%.

Re: A Call to Action: Stop the FCC's KYC Regime

#35

"force phone providers to collect identity information from ordinary people before they can acquire or renew service with a phone carrier." don't see the harm in this? isn't this already the case for 99.9% of phoneline havers already?

The big ones already force you to give SSN for service. Then they lose it in a data breach.

Re: A Call to Action: Stop the FCC's KYC Regime

#36
post #11
post #5

Earlier quoted context omitted.

No.

It did in every other country that did it. What's different about this one? If you get a spam call in Europe from Europe, you call the police and the spammer gets located and punished.

Europe does not consistently have KYC for phone service, at least for mobile connections. Normal phone companies in Ireland don't ask for information when buying SIMs (physical ones, at least). Some eSIM providers in Europe don't ask for information at all, and accept cryptocurrency payments. (I'm also aware that some other European countries have very different requirements, up to actually needing copies of identification.)

More widely, however, there do seem to be differences that I don't know the details of. VOIP seems quite different (I use it for my old phones): DID numbers in the US seem extremely cheap and available instantly, with little information, while European ones seem to have an actual verification process and prices that would make large-scale spamming difficult.

Re: A Call to Action: Stop the FCC's KYC Regime

#37
post #35

"force phone providers to collect identity information from ordinary people before they can acquire or renew service with a phone carrier." don't see the harm in this? isn't this already the case for 99.9% of phoneline havers already?

The big ones already force you to give SSN for service. Then they lose it in a data breach.

The crazy thing is that a simple 9-digit number (that you must give away for many things) can ruin your life if it gets public.

The US seems so backwards at times.

Re: A Call to Action: Stop the FCC's KYC Regime

#38
post #16
post #9

Earlier quoted context omitted.

According to a defcon talk, spammers just make sure all their spam gets routed through legacy TDM systems which discard the shaken/stir header because they're too old to support it. The other side then re-adds a "we got this from somewhere that didn't support this header" header.

> legacy TDM systems Easy fix. It should be opt-in to accept a call that is routed through one of these. I know they allow it so some grandma in rural France that still uses a dial phone on a copper line that hasn't been touched since 1962 can call her son in New York, but for the rest of us who are not in that situation, we can just blacklist all those calls and lose nothing. This would even fix spam for the people…

> Easy fix. It should be opt-in to accept a call that is routed through one of these.

Easier (and correct) fix: Telecoms operators should not be permitted to provide transit to a call that's routed through one of these.

> I know they allow it so some grandma in rural France that still uses a dial phone on a copper line that hasn't been touched since 1962...

This doesn't make sense. Even my inexpensive Mikrotik switches can augment packets with the ID of the port that they originated from. I do not believe for even a second that Telecoms Grade switching equipment is unable to do the same. The fact that that grandma can send and receive calls tells you that both that that equipment exists and that it knows what port her phone is connected to.

Re: A Call to Action: Stop the FCC's KYC Regime

#39

We really just need telcos to stop allowing caller id spoofing. Doesn’t even need your name, but with a real number we could actually report these scams. You can still allow people to hide it, but then by default every non-business phone should block calls with hidden numbers.

Why do we even need to run on the 20th century system of numbers anyways? Why is there not a better call addressing system?

We don't, but the entire world currently does, and the amount of equipment deployed that depends on it is substantial.

I would be willing to bet money that any "better call addressing system" would be a design by committee where this just gets litigated there. And we'd end up with either a system that requires KYC per-call, or has compromises similar to what we're complaining about now.

Post reply on HN