Live data from Hacker News

FCC will require phone carriers to authenticate calls by June 2021 [pdf]

docs.fcc.gov

331–340 of 352 posts

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#331
post #184

Good. But really, why did this take this long? It should be relatively easy to identify the bad actors here and I don't mean the spammers, I mean the telcos that make this possible, deliberately so, by essentially "laundering" spam calls. My response to picking up a number is to answer the call and say nothing. Auto-dial systems will route the call to a person when they get a "live" response. I don't know the criteri…

Telephone numbers are a synchronous interactive channel. If someone calls you to have a chat, they pay for your attention with their own. They can say something to you, and you can in turn say something back to them.

Robocalls shove someone else's voice into your ear, without offering you an ear in return. They signal a synchronous communication, and then reneg on that promise with a spammed asynchronous message.

"Political speech" is the same as every other kind of speech. There should be no exemptions for policy just because someone running for office is involved. They have the same duty of courtesy as everyone else, and we have the same right to block our ears from their spam messages as businesses and scams.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#332
post #314
post #232

Earlier quoted context omitted.

We shouldn't interfere in the free market. Those robocalls are just good old American ingenuity.

Such a disingenuous argument. The government quite frankly ties the free-market with weird regulations that essentially prevent competition. And then we get snarky comments such as this that say "oh wow, look how badly the free-market failed". For an example of free market trying to solve this, albeit not in a great way, have a look at TrueCaller and similar software.

The regulations are not "weird". Before telcos were required to route all calls without discrimination, they didn't. And as soon as telcos are no longer required to route their competitors' calls, they stop. A recent example is the new area code for VOIP calls introduced in Germany in 2009. Major telcos just didn't route them, citing "technical reasons" despite being able to route local area numbers with the same mechanism without problem.

Competition is only a solution for problems where the telcos' interest and the consumers' interest align. And that's very rare.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#334

Earlier quoted context omitted.

Missing an emergency call like that from a family member or close friend is one of my fears. I do hope these regulations come with teeth.

Most of those services use a different network, or their devices are flagged as emergency numbers and get some priority. Why doesn't the call from a paramedic or other emergency number go through as a high-priority call and indicate as such? When I call 911 my cell goes all nuts telling me about how it's got priority service and the UI changes to an emergency-colored UI with some additional information, so when they…

Good point - that would be awesome.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#335

Earlier quoted context omitted.

The US has had a do-not-call registry for 17 years. It still doesn't deter spammers who are not subject to US law. Back in the early 2000's I remember doing the same thing you're describing: startling spammers by telling them that I was on the list. But today, the people calling don't care because they aren't inside of the US.

This is what anti-spoofing is for - it's trivial to deny calls from India or Russia or whatever if you're not doing any business there, the problem is that currently they're spoofing a local number. If you're being called from a local number, then this should mean (and outside of USA actually means) that there's somebody who's subject to local law and fully responsible for ensuring that the spam laws are met. If you'…

[deleted]

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#336

Earlier quoted context omitted.

The US has had a do-not-call registry for 17 years. It still doesn't deter spammers who are not subject to US law. Back in the early 2000's I remember doing the same thing you're describing: startling spammers by telling them that I was on the list. But today, the people calling don't care because they aren't inside of the US.

This is what anti-spoofing is for - it's trivial to deny calls from India or Russia or whatever if you're not doing any business there, the problem is that currently they're spoofing a local number. If you're being called from a local number, then this should mean (and outside of USA actually means) that there's somebody who's subject to local law and fully responsible for ensuring that the spam laws are met. If you'…

CID spoofing is an entirely different thing from getting a local VoIP number. A lot of spammers just get local VoIP number, that's not spoofing, that's just a real local number.

CID spoofing is when you tell the network to display a different caller ID value than the actual originator. This never had any sort of authentication in the US (until the announcement in the OP)

Most of the spam calls in the US aren't CID spoofed, but some egregious scams are. This is usually used for things like scammers displaying "SOCIAL SECURITY" on the caller ID.

The US just generally doesn't make carriers liable for the crimes of their users. We don't need to change that, and I don't think it's a good idea either because of the unintended affects that could have on accessibility. We just need to require controls that authenticate proper use of the network. The announcement in the OP is one step towards doing that.

But preventing CID spoofing alone is not going to stop spam calls from local numbers, because VoIP.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#337
post #273
post #232

Earlier quoted context omitted.

We shouldn't interfere in the free market. Those robocalls are just good old American ingenuity.

Indeed. I'm from the Netherlands and never, ever in my life received a robocall, and also do not know anyone else who received one.

I'm from the Netherlands (born and raised) and have received several robocalls, until I registered my phone number on the bel-me-niet.nl web site.

Since then, I only get such calls from companies that got my details in exchange for some freebie. I tell them I'm not interested, and would they please stop calling me, and they do.

The only calls I got recently were in English with a heavy Indian accent, "Ilse Smid" or another stereotypically Dutch name, claiming to be from Microsoft Windows, and that my computer had alerted them that it had a virus... These scam calls all came from nonexistent Dutch phone numbers.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#338

Earlier quoted context omitted.

> Auto-dial systems will route the call to a person when they get a "live" response. I don't know the criteria but I'm pretty sure it's them detecting noise on the call (which could be voicemail). I work with phone systems. It's usually determined by how long they hear a continuous sound at the start of a call. If it's relatively short (and it can be adjusted by settings), it assumes it's a live voice (like someone s…

The case you are citing is not the one I would be most concerned about -- it is the spoofed numbers that should have been top priority. I get calls for different numbers (almost like they have been selected randomly) every single day selling cruises. If you call the missed call back, you realize the person picking up didnt make the call.

Be careful calling the numbers back. There's another scam where they use the equivalent of a 900 number to do billing to anyone who calls. The scammers use country codes with 3 digits to try and trick you into thinking it's a US number and hope that you attempt to return the call.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#339

Earlier quoted context omitted.

The thing this will address is certain classes of scams that rely on spoofing a specific area code. The infamous “Windows support” calls, which generally spoof a Redmond, WA area code. The IRS/FBI/Immigration scam calls that spoof Washington DC area codes. These are scams which defraud people of huge sums of money every year, mostly the elderly and immigrants.

Do people generally know area codes other than their own area?

At least on my iPhone, for numbers that aren’t in my contacts, it shows the location under the number. I’m assuming based on area code. So it will say Redmond, WA right on the screen.

Re: FCC will require phone carriers to authenticate calls by June 2021 [pdf]

#340
post #184

Good. But really, why did this take this long? It should be relatively easy to identify the bad actors here and I don't mean the spammers, I mean the telcos that make this possible, deliberately so, by essentially "laundering" spam calls. My response to picking up a number is to answer the call and say nothing. Auto-dial systems will route the call to a person when they get a "live" response. I don't know the criteri…

While I haven't taken the time to research further, I figured I'd try to brick the algorithm by speaking absolute gibberish. I also tell everyone else I know. Since machine learning is still "dumb", I figured that enough people babbling incoherently would require the spammers to hand-scrub the data or make more training rules, both requiring more work.

No idea if it worked, but it was the least I could do to halt progress in the wrong direction.

Post reply on HN