Live data from Hacker News

Your PBX has been hacked

cringely.com

51–60 of 63 posts

Re: Your PBX has been hacked

#51
post #47
post #38

Earlier quoted context omitted.

As a Google Voice user, the downside would be sad but totally worth it if it meant I could have GV accurately screen my calls. I could still get full caller ID information for GV calls received through VoIP, and when receiving calls through POTS I could at least know that the call is from somebody I'm willing to take calls from. The other use case applies pretty much only to people I don't want to hear from in the fi…

It sounds like the list of people you're willing to receive calls from is pretty small. Have you ever actually received a phone call which spoofed the caller ID of someone you know? I haven't - all the spoofed calls I receive are from numbers I usually wouldn't answer anyways since I don't recognize them. Also, note that Google Voice no doubt uses many termination providers (considering they're giving the service awa…

Why can't we have a system whereby Google is required to prove to each of their termination providers that they legitimately own and control my GV number, and thus all of those providers can assure my outgoing GV calls have valid caller ID data? I don't see where it should matter whether calls into my number take a potentially different route from calls from my number.

Re: Your PBX has been hacked

#52
post #49
post #11

Earlier quoted context omitted.

I don't think you've seen the systems they use in developing countries. Phone networks are almost a century behind the internet. It's not something that's easy to fix, nor are there too many situations where you would need to rely on the CID to identify the caller.

You're still using the circular logic of insisting that caller ID can't be trusted because it shouldn't be trusted because it can't be trusted. I and most people who want to not get robocalls want a caller ID system that is trustworthy, and the first-world telcos we're doing business with are totally capable of providing a service that is at least partly trustworthy. I'm not interested in receiving calls from third-w…

You're not talking about Caller IDs here though, you're talking about some completely new technology that'd require a complete rework of current telephony systems.

If you're worried about someone spoofing the source of their call you should probably consider using SIP over TCP, although it is unlikely that rest of the world is going to follow suit any time soon.

And no, first-world telcos wouldn't be capable of providing what you want without massive overhauls either... Nor would they want to since there's a plenty of business critical applications that depend on this behavior.

Re: Your PBX has been hacked

#53
post #52
post #49

Earlier quoted context omitted.

You're still using the circular logic of insisting that caller ID can't be trusted because it shouldn't be trusted because it can't be trusted. I and most people who want to not get robocalls want a caller ID system that is trustworthy, and the first-world telcos we're doing business with are totally capable of providing a service that is at least partly trustworthy. I'm not interested in receiving calls from third-w…

You're not talking about Caller IDs here though, you're talking about some completely new technology that'd require a complete rework of current telephony systems. If you're worried about someone spoofing the source of their call you should probably consider using SIP over TCP, although it is unlikely that rest of the world is going to follow suit any time soon. And no, first-world telcos wouldn't be capable of provi…

Caller ID is what describes what I want, and the current methods for delivering caller ID info to the recipient of a call would not need to change. The telcos may have to invent a new term for how they handle things behind the scenes, but it would be transparent to me except that I'd now have a way to stop the robocalls.

I highly doubt that it would be hard for telcos to implement such a system. I have no doubt that they don't want to, as evidenced by their decision not to in the face of strong demand. I can certainly understand that they might have lots of businesses interested in preventing such a change, but I'm not aware of how legitimate businesses would be harmed. All they need to do is ensure that when they call me they deliver caller ID information that corresponds to a real number that can be used to identify them to the FTC when I file my complaints.

Re: Your PBX has been hacked

#54

Phone numbers are going to (eventually) disappear. They are inefficient, hard to remember and not human-friendly (they are great for computer-based routing :P ). Easier thing we can do, is to map them down like we do it with IPs and domain names, but as usual, this is far from being a practical solution. Best think is to let conventional telephony die and VoIP take over its place.

> map them down like we do it with IPs and domain names We have been able to map phone numbers to SIP URIs for a long time with E.164 ENUM. Numbers are a hassle, but there's nothing preventing numbers from living alongside proper URIs today. > let conventional telephony die and VoIP take over its place. Many places are still circuit-switched at the last mile, whether over landline or cellular. We can't turn off the P…

Could you image what things would look like with rogue "DNS" servers that mapped bankofamerica.phone to a phisher controlled endpoint? You could no longer trust that calling the "number" on the back of your credit card would actually get you in touch with the actual bank.

Re: Your PBX has been hacked

#55

Earlier quoted context omitted.

> Digital voice services, which are basically VoIP You say that as if things like GR-303 and ISDN BRIs/PRIs don't exist. The only thing that isn't digital about modern, non-IP phone networks is the last mile when you order an analog loop. > properly differentiate between calls and data, so calls on these networks are going to be much more reliable than simply leasing a SIP trunk. In theory, sure. As I said though, in…

> You say that as if things like GR-303 and ISDN BRIs/PRIs don't exist. Granted, "digital voice" was imprecise terminology, but you get the gist... modern consumer phone services are VoIP. > fall behind their circuit switched counterparts in performance even on carrier grade routes. Most carrier backbones have been all-IP for years. Pretty sure end-to-end circuit switched calls are atypical nowadays, although I'm hap…

> Most carrier backbones have been all-IP for years. Pretty sure end-to-end circuit switched calls are atypical nowadays, although I'm happy to be proven wrong.

That certainly depends on what network and where. If you're talking about someone like Level 3, they definitely use IP transport for phone calls. But there's a number of networks that don't. Verizon, for example, has a toll network based on the DMS-250 and DEX-600 switch platforms. Both of these are designed from the ground up to handle circuit switched traffic. There are a few routes that're IP, but they're pretty easy to pick out since there's a combination of comfort noise, significant latency and packet loss (!) on them.

AT&T, similarly has a toll network running on 4ESS, 5ESS and DMS-250s. There are a few IP trunks on there, but they're typically only used for destinations like San Francisco to Chicago.

Sprint has an all DMS-250 network at their disposal as well, as well as TDS Metrocom and the McleodUSA network that Windstream bought. Anyway, you get the idea.

On the local end, to get transport to the phone network, you have to order DSX trunks; there is no IP trunking to be had. Not to mention, there's typically quite a large number of circuit switches in any given market. Typically enough to outnumber the number of softswitches.

Re: Your PBX has been hacked

#56

Earlier quoted context omitted.

CDRs are kept for quite a while, so it's possible/easy to track these calls down. There are a bunch of intermediaries (I ran one), and each time you need to get them to release customer information. The FCC doesn't care enough; no one investigates.

Okay we do the legwork and track him down. He's an Indian national using a stolen or prepaid credit card in Mumbai and using voip.ms or flowroute or whoever just needs a CC to get started. He has long left this service and gone to another by the time you "catch" him. He's made millions of calls since.

Well most places don't just allow a credit card to start sending high volume, due to the fraud risk. But agreed, there may not be too much ID, and prosecuting internationally is hard. So there's a few options:

1. Don't allow such users to use other caller IDs until they verify themselves (business, USF ID, etc.) or until they verify ownership of the number, or some other limitation. This is fairly reasonable and can be totally automated (some providers do so). Some Indian shop doesn't need to spoof all US numbers, so why allow them?

2. Require deposits against such behavior, and in case of uncontested complaint, keep the money.

3. Share information on offenders (FCC run, mandatory). This is like having a list of known bad agents. Yes, they can get new IDs, but that costs a bit (see point 1, no need to allow someone in India on a free email account, without a company, impersonate all US numbers).

4. Of the FCC really wanted to nuke the problem, they could make providers liable. End of story. Within a month, providers would get together and figure it out.

And this wouldn't need to hurt legitimate usage that much. Established operators are easy enough to figure out (or you can grandfather until there are complaints). End users trying to get going should have no problem, either.

Re: Your PBX has been hacked

#57

Earlier quoted context omitted.

> map them down like we do it with IPs and domain names We have been able to map phone numbers to SIP URIs for a long time with E.164 ENUM. Numbers are a hassle, but there's nothing preventing numbers from living alongside proper URIs today. > let conventional telephony die and VoIP take over its place. Many places are still circuit-switched at the last mile, whether over landline or cellular. We can't turn off the P…

Could you image what things would look like with rogue "DNS" servers that mapped bankofamerica.phone to a phisher controlled endpoint? You could no longer trust that calling the "number" on the back of your credit card would actually get you in touch with the actual bank.

The same problems would happen if someone mapped "google.com" to a phisher controlled endpoint. TLS solves that, and by extension, so does SIPS. Then add in SRTP, etc.

Re: Your PBX has been hacked

#58

Earlier quoted context omitted.

> You say that as if things like GR-303 and ISDN BRIs/PRIs don't exist. Granted, "digital voice" was imprecise terminology, but you get the gist... modern consumer phone services are VoIP. > fall behind their circuit switched counterparts in performance even on carrier grade routes. Most carrier backbones have been all-IP for years. Pretty sure end-to-end circuit switched calls are atypical nowadays, although I'm hap…

> Most carrier backbones have been all-IP for years. Pretty sure end-to-end circuit switched calls are atypical nowadays, although I'm happy to be proven wrong. That certainly depends on what network and where. If you're talking about someone like Level 3, they definitely use IP transport for phone calls. But there's a number of networks that don't. Verizon, for example, has a toll network based on the DMS-250 and DE…

Very interesting, thanks for the information!

Re: Your PBX has been hacked

#59

>They are operating from overseas and can’t be traced. Not to ad-hominem, by this guy doesn't know what he's talking about. (I've seen his posts before.) The real problem is that no one cares to push any investigations. I've had many many cases of customers sending "illegal" calls through my network. It's not my customers, it's someone down the line. I'm not going to do anything without a warrant. And when an upstrea…

"Oh, you can't go back to knowing who is allowed to send what number. Things are too mixed up, and it'd break many services. Including many uses of 9-1-1. It's far more difficult than, for instance, preventing spoofed IP source addresses."

That's interesting. Why is that?

Re: Your PBX has been hacked

#60
post #18
post #3

I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.

The use case for caller id spoofing is when the callback number is different than the number you are calling from, most commonly to present a generic (possibly toll free) customer service number when an agent who might not even have a DID number makes an outbound call. Large operations might also have trunks from multiple carriers for redundancy, so simple ingress filtering is not necessarily viable.

Ingress filtering is totally viable. A telco should strip any caller ID information that is not coming from a trusted source. If a customer operating a call center wants to spoof caller ID they have to prove to their provider that they own the one number they're spoofing. Caller ID from shady telcos should be removed and customers given the option of not receiving such calls. None of those rules are at all difficult to implement.
Post reply on HN