Live data from Hacker News

Report Phone Spam – Shut down robocallers and text spammers

reportphonespam.org

321–330 of 339 posts

Re: Report Phone Spam – Shut down robocallers and text spammers

#321

Earlier quoted context omitted.

What systems rely on spoofed called ID-s? I would assume carriers don't like this too much, but so much legacy crap is built on this that they are just rolling with it and just accepting the bad rep for spam.

AFAIK, just about any time you get a call from a business - the specific desk phone that you were called from has a number, but they prefer to ID as the receptionist or the menu system so you'll get that when you call back.

Is that really caller ID spoofing though? Presumably the desk phone does not have an individual external line and it all goes trought a central phone exchange. If that exchange is responsible for both the public phone number and the internal phones then it using the public number for outgoing calls is not really the same as a third party claiming to be calling from a number that they don't own.

Re: Report Phone Spam – Shut down robocallers and text spammers

#322

Earlier quoted context omitted.

Nah. We're talking about spam texts and phone calls. That stuff isn't legal. Yeah what everyone else does is creepy af, and _should be illegal_, but that's not the facts on the ground today.

Imho the normalisation of agressive advertising and inhuman communication with customers is what make spamming profitable.. they are not that different from legit orgs.

100%

These guys are just doing what the ad guys are doing but it’s for fraud.

The fraud is only half of it.

Re: Report Phone Spam – Shut down robocallers and text spammers

#323

Earlier quoted context omitted.

Depends on how their PBX is set up, but often those lines—even if they have separate incoming numbers—will all have the same outgoing number.

Which is ironically done by spoofing the number, which is why it's so easy for scammers to spoof numbers.

I remember how shocked I was when I first learned how insecure caller-ID is. I was setting up a VOIP PBX for the small business I was taking over from my father after he passed away unexpectedly. I hadn't been able to get into his (telco-hosted) voicemail, until I happened to call the number from the new VOIP line. Since I had the caller-ID set to the same number, the voicemail system not only bypassed the greeting, but it automatically logged me in (it was set to bypass the PIN when calling from the same line).

I tell people that caller-ID should be trusted as much as the return address on an envelope. Perhaps I can soon update my guidance now that STIR/SHAKEN is (apparently) near full rollout.

Re: Report Phone Spam – Shut down robocallers and text spammers

#324

I wish we could euthanize this garbage, antiquated phone system. It shouldn't be expected/required that every adult has a phone number when the system is so irredeemably broken and dangerous. If the web didn't have HTTPS, it would be illegal to conduct sensitive business over it. Yet we're stuck with this entrenched telephone system, the best we can do is STIR/SHAKEN, and that's not real security.

The sad part is that it only got really really broken when it got digitised, i.e. IP telephony. Preventing number spoofing was trivial and a solved problem back when the phone system was still "antiquated". These design flaws were added surprisingly recently.

Re: Report Phone Spam – Shut down robocallers and text spammers

#325
post #218

I remember in the mid/late 2000s/2010s using Spamcop.net prodigiously to report every spam email I got because there were just so many. Spamcop automated the reporting process by looking up the mailhost that the spam was sent from and sent a report to the ISP hosting it along with any URL included to the site hosting it, as well as sites like Phishtank, the APWG, the FTC & etc. Spamcop also ran their own RBL for the…

I still do the Spamcop thing diligently. Heck if I know whether it does any good, but it's not a big effort and if it helps in a few cases, why not. A surprising amount of the spam and phishing mails I get come through major providers: Gmail, Amazon, Outlook, Sendgrid, etc. – I'd hope they actually do something (getting blacklisted can still be a very costly thing, I heard).

I also report all phishing sites I find to hosts, domain registrars, and Google+Microsoft blacklists. A similar service to Spamcop for that purpose is Phish Report. There, it's a bit easier to measure success. A surprising number of hosts are very quick to kill reported sites.

As for the blacklists… when I report ridiculously obvious phishing sites such as PayPal logins hosted on "verify-paypa1.business", usually the site is blocked on Edge around 15 minutes after I report it to Microsoft, but is often still reachable without warning on Chrome two or three weeks after I reported it to Google…

Re: Report Phone Spam – Shut down robocallers and text spammers

#326

Earlier quoted context omitted.

At the end of the recorded speech is a human. Let the speech play, then don't talk to the human. Let them listen to ... silence. They'll soon stop calling.

If you're bored, you can also choose to waste their time by pretending to be a gullible human, but not sending any money.

I tend to try and give them the impression that I'm gullible enough to maybe fall for it, then say I quickly need to do an urgent thing like move the washing to the dryer, put them on hold, and later check how long they stayed on the line, all hopeful that they may have found a victim. The record so far is almost a quarter hour.

It's definitely the best target to optimise – the more time they waste on you, the less time they have to work on some poor soul who's actually vulnerable.

Re: Report Phone Spam – Shut down robocallers and text spammers

#327

Wouldn't it be nice if you could give out a revokable token in place of a phone number to various businesses. If you ever received spam through a token just revoke it and move on. Puts the power back into the hands of the recipient rather than having to rely on some centralized service or your carrier.

Unfortunately, many spam callers don't even use number lists, but just iterate through. phoneNumber++ ad infinitum. With parallelised robocallers that only involve a human when a connection is established, it's cheap and effective.

Re: Report Phone Spam – Shut down robocallers and text spammers

#328
post #294

Earlier quoted context omitted.

Ok, but who's the culprit for "unknown caller"? If we don't have info, how do we go after them ourselves?

That's the art & science of it... you need to social engineer the info out of them. Most of the time, even if you do get a caller ID, it's spoofed, so it doesn't matter what "number" they call you from. You need to identify a business with an address and phone number, and definitively tie the activity back to that business. Yes, it takes time and skill, but then again, between the TCPA and state statutes you could po…

So if I try really, really hard, I can get the law to do what it's supposed to do without any effort on my part? How is that in any way a positive?

Re: Report Phone Spam – Shut down robocallers and text spammers

#329

This whole system needs to be automated. It should be as easy as clicking a "Report" button on my phone or in my SMS application.

I actually emailed the FCC[1] last month and asked about/offered to try to make this available to more consumers. A realistic MVP would be an FCC-operated wrapper for Twilio's Line Type Intelligence API, so that any consumer could find the carrier responsible for any US phone number. That's not perfect, but it's a great start. One step better would be that plus a unified contact form - basically, the process I descri…

Update that Mr. Egal responded and forwarded my message to the team responsible for robocall enforcement. It would be a great start if the FCC changed their reporting flow to also notify the originating carrier.

Re: Report Phone Spam – Shut down robocallers and text spammers

#330

Earlier quoted context omitted.

What an utter technological failure. How and why is this even (still) possible?

Why are ads a thing on cable? On the web? It's literally the same problem, and since this site's audience is likely more familiar with the latter, it should be clear it's not a technological failure, but a social/legal one.

Ads are not illegal. Spam is regulated by laws like the TCPA for sms and CAN-SPAM for email.
Post reply on HN