Live data from Hacker News

France to ban unsolicited telemarketing calls

lemonde.fr

511–520 of 525 posts

Re: France to ban unsolicited telemarketing calls

#511
post #244
post #220

The main problem and challenge with all these regulations is enforcement. How are they actually going to enforce them? The U.S. already has very strict rules against unsolicited calls, yet I still get around 20 spam calls a day saying things like "press 2 to be connected" or offering some "$64K loan." At the same time, I have not received a single unsolicited call from a reputable company. The same is true for text m…

> I have not received a single unsolicited call from a reputable company. Yet you receive 20 spam calls a day through a known company, namely your phone provider. The way to solve this is to forcibly draft the providers into this; for example: any time you receive a spam call, you can dial a special *# number after hanging up. This message will have the effect of crediting $5 on your next phone bill, and allows the p…

Yes, this.

The backtrack chain of accountability has to apply to each telco transiting a given call. We can argue about how much that penalty should be (I'd prefer a heftier one), and details over how to address abuse and whatnot.

I'd detailed a version of this a few days ago here: https://news.ycombinator.com/item?id=49129679>.

California has (recently?) introduced a bonding requirement of telemarketers. I'd like to see a far stiffer bonding obligation to telecoms providers, probably in the deca-to-mega millions amounts.

As that's bonding, the rate is based on risk (business assessment plus history), and would likely be a small fraction of the total amount for legitimate providers, but would be substantial for bad-actors, and the Surety (bond provider) would be strongly incentivised to limit their risk through bad behaviour on the part of the Principal (bonded entity).

Re: France to ban unsolicited telemarketing calls

#512

It’s crazy the amount of phone operator companies sell our data and numbers to those people. I really wish it would stop because scammers can also use it. So frustrating.

A major problem is that the phone number space is densely populated. That is, of all possible numbers, a large fraction are actually assigned.

This makes the act of randomly or sequentially dialing numbers tractable, as many of those attempts will reach an actual connection. This is known as wardialing https://en.wikipedia.org/wiki/Wardialing>.

In the United States (plus Canada and much of the Caribbean) , standard numbers are ten digits (three for area code, three for exchange, four for service number), which allows for 10 billion distinct numbers. Of these there are significant reserved blocks, but the total is still close to that. The total population is about 350 million, which means that there's roughly a 1:30 chance of a given dialed number connecting to an active account.

Actual utilisation and namespace exhaustion are harder to suss out, though numbers are currently constrained, with several area codes being fully exhausted by 2028, and the full system lasting to about 2061. See: https://en.wikipedia.org/wiki/Numbering_Resource_Utilization...>.

I see two ways around this.

1: Expand the namespace. By having vastly more potential identifiers than subscribers, wardialing succeeds far less often. The two principle problems with this idea are that a) once a given number is known it's vulnerable and b) the resulting numbers are far less memorizable.

2: Implement a caller-callee relationship. Effectively, a caller would have to authenticate to the callee when making a call, and only approved callers would be passed through. This is effectively the role an old-school receptionist would serve at a business, permitting only select calls through to a principal employee. Because of limitations with the existing phone network, the caller's number alone is a poor identifier. Some other challenge would be required.

One option I've considered, which should be implementable with a VOIP service, would be to have individual "extensions" assigned to specific callers. A caller would dial the primary number, then be asked to enter an "extension", which would be restricted to the caller's originating number (so that different callers each have a unique assigned extension). The extension space would also have to be relatively large (to avoid random/sequential search), probably 10-100x the number of approved contacts at a minimum.[1]

Previously-unknown callers might go through a preliminary vetting and be dropped to a voicemail box or (preferably) be requested to text their message, preferably in a brief, text-only format, say 40--80 characters or so, enough to identify the caller but not to drop a massive spam load.

________________________________

Notes:

1. If a typical person has 100-1,000 contacts, the "extension" space would be roughly 1,000 to 100,000 values, perhaps 3--5 digits.

Re: France to ban unsolicited telemarketing calls

#515

The problem is Phone numbers. No Band-Aids will fix them.

Explain, please.

They are long-term identifiers that are repeated across services so leaks are detrimental and it's easy to spam them.

Not even mentioning the terrible security of the cellular network (ss7) and terrible carrier security (sim swapping). It's caused probably hundreds of millions in crypto losses and billions in fraud.

Re: France to ban unsolicited telemarketing calls

#516
post #184

Earlier quoted context omitted.

I never understood what are the technical obstacles to building the phone network in such a way that caller numbers can not be spoofed or suppressed. Then, you could just build a system where receiving an unsolicited phone call from a commercial entity entitles you to a compensation in small claims court, to the tune of 50 EUR, unless the caller can prove that you explicitly authorised them.

The problem is that it's a network. The hard part of networking isn't the technology - it's the other people. And short of a government regulation or a monopoly, they'll never all agree. STIR/SHAKEN has an exception for calls passing through TDM trunks, which don't support it. This created a small industry for passing spam calls through TDM trunks. Such calls can trivially have their caller ID spoofed.

Do you have more information on this?

Why are those non-STIR/SHAKEN TDM trunks serving as transit trunks (non-terminating), rather than terminal-only trunks? Seems a pretty obvious hole to close.

Re: France to ban unsolicited telemarketing calls

#517

Earlier quoted context omitted.

That's so strange, both me, my wife and friends and family had similar issues years ago, before I put everyone into Lista Robinson, and it worked for all of us, easily 10+ people throughout the years. I wonder why it's so different between people. Does it depend on the region perhaps? We're all in Catalunya for what it's worth. Maybe double-check the details, I remember for one person it didn't work at first, and the…

The easy explanation is that the lists don't work and you and your friends are just lucky to not get spam calls. Yet. I also noticed a drop when the GDPR kicked in, but it doesn't solve the problem. It ironically just removes the "most benign" telemarketing from serious co's.

> The easy explanation

For you perhaps, for me the explanation is obviously they work, as we've had spam calls, got on the lists, and they stopped.

Re: France to ban unsolicited telemarketing calls

#518
post #11

Great idea! Telemarketers have ruined the phone network for me. I haven't answered an unknown call for the past 10 years, which sometimes means I miss important ones. 99.9% of all calls are an attempt to get money, and the 0.1% that's a dentist appointment, a friend that changed numbers or whatever become collateral damage. A ban is the right idea but I wonder how they can handle it, logistically. I think there needs…

The best technical solution I've seen is a spam review fee that turns into a reward and charged to the next closest originating peer. For example say you get a spam call. You notify your service provider and pay $10 to have them review the call recording to verify that its spam. An employee listens to the call and determines that it is, in fact, spam. You get a $100 reward for reporting spam and your service provider…

Not sure where you ran across that, but I'd made a similar suggestion a few days back on HN: https://news.ycombinator.com/item?id=49129679>.

I'm not aware of similar proposals (specifically: chaining liability through the route of call transmission).

Re: France to ban unsolicited telemarketing calls

#519

Earlier quoted context omitted.

Incorrect, it's the callee network

Sure but the caller network bills the telemarketer and they could be in cahoots.

Well yeah but that applies to local calls too and no telemarketer will sign up with a provider more expensive than they need.

Re: France to ban unsolicited telemarketing calls

#520

Earlier quoted context omitted.

The problem is that it's a network. The hard part of networking isn't the technology - it's the other people. And short of a government regulation or a monopoly, they'll never all agree. STIR/SHAKEN has an exception for calls passing through TDM trunks, which don't support it. This created a small industry for passing spam calls through TDM trunks. Such calls can trivially have their caller ID spoofed.

Do you have more information on this? Why are those non-STIR/SHAKEN TDM trunks serving as transit trunks (non-terminating), rather than terminal-only trunks? Seems a pretty obvious hole to close.

DEFCON talk "Journey to the center of the phone network"

Slides: https://media.defcon.org/DEF%20CON%2033/DEF%20CON%2033%20pre...

Video recording: somewhere

Post reply on HN