Live data from Hacker News

A Call to Action: Stop the FCC's KYC Regime

blog.lopp.net

71–80 of 248 posts

Re: A Call to Action: Stop the FCC's KYC Regime

#71

We really just need telcos to stop allowing caller id spoofing. Doesn’t even need your name, but with a real number we could actually report these scams. You can still allow people to hide it, but then by default every non-business phone should block calls with hidden numbers.

What ever happened to SHAKEN/STIR? I thought this was supposed to happen 5 years ago. Did they just chicken out on the prospect of actually shutting down telcos sending spam volume? I still get loads of spam phone calls, so clearly something went wrong (or slow enough to be indistinguishable from wrong).

The FCC issued a report on this very subject[1]. TLDR, there have been four exceptions to the SHAKEN/STIR requirements:

- Providers that can't afford it implement it - Non-IP networks - Small voice service providers that originate calls via satellite using U.S. NANP - Providers that lack control over the network infrastructure necessary to implement

Nothing is going to change as long as those holes exist.

1: https://docs.fcc.gov/public/attachments/DOC-416732A1.pdf

Re: A Call to Action: Stop the FCC's KYC Regime

#72

We really just need telcos to stop allowing caller id spoofing. Doesn’t even need your name, but with a real number we could actually report these scams. You can still allow people to hide it, but then by default every non-business phone should block calls with hidden numbers.

This is already not allowed.

If your carrier accepts a spoofed call they're already violating FCC recommendations.

Re: A Call to Action: Stop the FCC's KYC Regime

#73
post #31

It's even worse: Since cell phones broadcast your location at all times, this means telling hundreds of companies (and a number of governments) your location at basically all times. That's already an issue with most cell phones. Making this apply to prepaid phones is even worse.

"Downstream collection" would have a field day with this data.

Re: A Call to Action: Stop the FCC's KYC Regime

#75

We really just need telcos to stop allowing caller id spoofing. Doesn’t even need your name, but with a real number we could actually report these scams. You can still allow people to hide it, but then by default every non-business phone should block calls with hidden numbers.

This is already not allowed. If your carrier accepts a spoofed call they're already violating FCC recommendations.

Recommendations aren't requirements; you're allowed to violate them.

Re: A Call to Action: Stop the FCC's KYC Regime

#76
post #70

Earlier quoted context omitted.

Why would that hurt a consumption-based economy?

Telcos make money off of scammer activity.

Maybe in the same way that Office Depot makes money on the envelopes used in mail fraud

Re: A Call to Action: Stop the FCC's KYC Regime

#77

We really just need telcos to stop allowing caller id spoofing. Doesn’t even need your name, but with a real number we could actually report these scams. You can still allow people to hide it, but then by default every non-business phone should block calls with hidden numbers.

What ever happened to SHAKEN/STIR? I thought this was supposed to happen 5 years ago. Did they just chicken out on the prospect of actually shutting down telcos sending spam volume? I still get loads of spam phone calls, so clearly something went wrong (or slow enough to be indistinguishable from wrong).

Just because a call is a spam call doesn't mean it is spoofed. STIR/SHAKEN ends spoofing but anyone can ultimately buy a phone and make calls that are spammy.

Re: A Call to Action: Stop the FCC's KYC Regime

#78
post #56

For background on KYC in the banking context @patio11's podcasts and essays are worth consuming: Patrick: Yes, so "Know Your Customer" (KYC) and "Anti-Money Laundering" (AML) are mandatory elements of the international compliance regime that have been in place in the United States since the early 1980s. Over time, this regime spread globally, largely fueled by the U.S. leveraging the dollar as a tool of foreign polic…

Reading this line in Lopp's article: "FCC even asks whether providers should consult lists of terrorists, terrorist organizations, and “criminal persons” maintained by law enforcement entities," brings to mind McKenzie's work describing the outsourced role of NGO's in vetting banking customers.

https://www.bitsaboutmoney.com/archive/nonprofit-indicted-ba...

https://www.complexsystemspodcast.com/episodes/splc-financia...

https://www.complexsystemspodcast.com/episodes/defendant-cen...

Re: A Call to Action: Stop the FCC's KYC Regime

#79
post #14

> Note: By checking this box, I acknowledge that I am filing a document into an official FCC proceeding. All information submitted, including names and addresses, will be publicly available via the web. Is there really not a way to submit an express FCC comment that avoids all my personal info being publicly published to the web? Yeesh.

[deleted]

Re: A Call to Action: Stop the FCC's KYC Regime

#80

We really just need telcos to stop allowing caller id spoofing. Doesn’t even need your name, but with a real number we could actually report these scams. You can still allow people to hide it, but then by default every non-business phone should block calls with hidden numbers.

What ever happened to SHAKEN/STIR? I thought this was supposed to happen 5 years ago. Did they just chicken out on the prospect of actually shutting down telcos sending spam volume? I still get loads of spam phone calls, so clearly something went wrong (or slow enough to be indistinguishable from wrong).

STIR/SHAKEN up to this point has only been a self-certification that a telecom company has the right to use a number. What the FCC is trying to do is set up a legal obligation for the STIR/SHAKEN header to match a KYC verified identity.

If the FCC implements this, I expect a lot litigation because of the burden and legal liability this would place on telecom and VOIP companies. There are other less burdensome approaches to preventing spam that the FCC has not tried.

Post reply on HN