Earlier quoted context omitted.
Live in Europe, last time I got a spam call 4-5 years ago it was my ISP asking of I wanted to add tv to my internet. Told them not to call me again and they didn't.
I live in Europe and I get scam calls and sales calls. Yes, legit companies spam call less in Europe due to regulation but scammers committing crimes don’t care about privacy laws etc it’s their least problems
Anti-fraud tools can't keep pace with robocall scammers
91–100 of 149 posts
Re: Anti-fraud tools can't keep pace with robocall scammers
#92Is this a USA problem, or world-wide? If other countries don't have such a problem, why not?
Re: Anti-fraud tools can't keep pace with robocall scammers
#93Earlier quoted context omitted.
Infeasible. Fraud or spam is usually pretty hard to confirm from one recording without additional context. Many scammers have plausible deniability or are just checking whether the number is active. Moreover, this solution would involve secret non-consensual recording; what if it's not a scam?
Plus, who is ‘confirming’ the spam? The same entity (or group: carriers) that is keeping the $10 and paying the $100 out? That just means the result will always be ‘not spam.’
Scenario:
- Spamford places an unsolicited call to subscriber Alice initiating from MalTelCo, transiting carrier hops BunnTel1 and BunnTel2, to Alice's telco carrier, EndTelCo.
- Carriers MalTelCo, BunnTel1, BunnTel2,[1] and EndTelCo have all placed surety bonds, held by BondCo, to practice telephony operations within the jurisdiction (regional/national). The carriers are the Principals, BondCo is the Surety, and receiving subscribers (or telcos, see below) are the Obligees.[2]
- Unbonded carriers may have their traffic refused by peers. Peering to an unbonded carrier places the bond obligation on the receiving carrier.
- Alice flags the call as spam. A per-call surety of $100 is paid to Alice, and charged to EndTelCo against its BondCo contract. As an additional option the call may be flagged as fraud through the phone system, in which case it is automatically referred to LEO by EndTelCo. Obligation of surety is independent of any fraud finding and is based SOLELY on the unsolicited nature of the call.
- EndTelCo has the option of 1) eating the charge or 2) filing a claim against its peer, BunnTel2, the 2nd hop in the chain, which EndTelCo does.
- BunnTel1 similarly files a claim on BunnTel2.
- BunnTel2 files a claim on MalTelCo.
- MalTelCo now eats the claim (it's paid out by BondCo). MalTelCo may seek further compensation from Spamford, but that's Out Of Scope of the bonding / surety schema, and would be covered by MalTelCo's own terms of use.
- BondCo assesses risks and adjusts its surety rates correspondingly based on observed behaviours (and financial risks) of EndTelCo, BunnTel1, BunnTel2, and MalTelCo. If risks are excessive and no surety can be issued, MalTelCo is unbonded, and hence, decertified. Peers may now refuse traffic without penalty.
Note that no one carrier needs to know anything more about a call's routing than its own network boundary. If EndTelCo has no idea that BunnTel2 and MalTelCo were involved, it doesn't matter, because BunnTel1 is on the hook for passing on the call. Spoofing or falsifying records doesn't save you.
There are some questions over how this might be implemented, though generally:
- If Spamford and Alice are both subscribers to EndTelCo, then EndTelCo eats the surety, which is paid to Alice. There's no upstream. Moral: Telcos, don't spam your own customers.
- One thought is that the surety is split among telcos and the subscriber. Rather than just facing a potential cost, transiting and reciving-end-point carriers could see revenue by tracking and prosecuting unsolicited calls. This could include calls received by monitoring numbers set up strictly to assess unsolicited call activity directed to the network. This would mean that calls transiting multiple carriers would be subject to compounded surety claims ... and ... I think I'm OK with that.
- There would all but certainly be classes of calls which would be exempted from claims. Those should be very limited, preferably to government and specifically qualified emergency services only. No political exemptions, no non-profit / NGO exemptions.
- How often claims are settled and risks re-assessed is open for discussion. Daily might be too often, weekly or monthly seems most likely. Longer than that gives too much free-run for malevolent actors to operate.
________________________________
Notes:
1. "BunnTel", because bunnies hop.
2. For an overview of surety bonds, see https://www.suretybondsdirect.com/educate/what-is-surety-bon...>.
Re: Anti-fraud tools can't keep pace with robocall scammers
#94I genuinely don't understand why this is so hard to tackle. Phone numbers are a scare resource and the telecommunications networks heavily regulated with numerous central points of control. This bullshit is scaling because the companies which gate and sell that access have no obligations, legal or otherwise, to deny scammers access to their resources.
I was under the impression that SHAKEN / STIR was supposed to do that by authenticating the phone numbers displayed against the telco that made the call. But as the other comment says, your telco earns money from scam calls and they don't want that to stop.
Re: Anti-fraud tools can't keep pace with robocall scammers
#95Earlier quoted context omitted.
One word: incentives. You're absolutely right- and telecom networks get us on both sides. They collect fees from the scammers, then fees from customers to block the scammers. Can't get any better than that.
so penalties for telcos have to be higher than they earn from scam calls. 2-5% of scams succeed but penalty should be there accounting for 95-98% that did not succeed. IANAL but I know failed attempt at robbery or murder is also prosecuted, failed attempts at scam are not, because people just hang up and move on. Then the reality is society doesn’t have enough resources to deal with "scam attempts" - well we have to…
Re: Anti-fraud tools can't keep pace with robocall scammers
#96One of the biggest concerns I have with phone scams is that the people most vulnerable are the elderly, and they don’t have the knowledge on how to block these calls (if a technical solution is the only option). And further to that, the elderly are also the ones who cannot block unknown numbers, because doctors’ offices seem to have random numbers they call you from (they may have a pool of numbers but it’s not reaso…
> because doctors’ offices seem to have random numbers they call you from This is a huge issue with scam/security awareness education. Too many legitimate orgs use the exact behaviors we tell people to avoid. Same thing with email, can't tell someone to never click links in emails when services keep relying on magic links, third-party notification domains, etc. SPF, DKIM, and DMARC do nothing because scammers will ju…
Re: Anti-fraud tools can't keep pace with robocall scammers
#97The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the cal…
Re: Anti-fraud tools can't keep pace with robocall scammers
#98Earlier quoted context omitted.
> My only solution that I could think of is to have a dedicated phone line just for friends/family/work, and a second line for banking/shopping/utilities/everything else. This fails the moment one of your "clean line" contacts downloads a sketchy app that sells all their contacts, and sells an updated list as your appear in their recent calls list - meaning it's not a one-time thing, it's for a few weeks after every…
It works if you only allow incoming calls from your contacts (e.g. whitelisted numbers) on friends/family/work line. If that number leaks, who cares? The random numbers will be blocked anyway. Probably would want to set it up so the 'public' line is silenced - just periodically check the VM box for anything important.
Re: Anti-fraud tools can't keep pace with robocall scammers
#99Earlier quoted context omitted.
> because doctors’ offices seem to have random numbers they call you from This is a huge issue with scam/security awareness education. Too many legitimate orgs use the exact behaviors we tell people to avoid. Same thing with email, can't tell someone to never click links in emails when services keep relying on magic links, third-party notification domains, etc. SPF, DKIM, and DMARC do nothing because scammers will ju…
I work in this industry, and a big issue is that a major customer of the cheapest, shadiest telcos is the US federal government. Because they're "being responsible with your tax money." So cracking down on them will affect government calls and quickly generate too much pushback. "I don't care how scammy Bill's Discount No-Questions-Asked VoIP LLC is, the army uses them!"
Which telcos?
Re: Anti-fraud tools can't keep pace with robocall scammers
#100Earlier quoted context omitted.
I get the comfort that "normal person" would send an SMS "it was me Greg, call me back" if you don't pick up and most of my family is on whatsapp anyway. Scammers or spammers will never send an SMS with clarification that they wanted to call you.
But a normal person could be calling from a doctor's office, a hospital, or your child's school - and not an actual cellphone, and they may not want to text you (or not be allowed to text you) from their personal cellphone, either. As a parent, the "block all numbers!" approach has always seemed incredibly naive to me.
Other organisations, institutions, and businesses too. HN discussion tends to focus on the consumer side of this, it's what most commenters have most familiarity with themselves, but you'd better believe that pretty much the entire phone customer base is fed up to there on this. Which puts the entire network at risk of defection, a risk that telcos have been talking publicly about for over a decade now:
[S]ince mid-2015, a consortium of engineers from phone carriers and others in the telecom industry have worked on a way to [stop call-spoofing], worried that spam phone calls could eventually endanger the whole system. “We’re getting to the point where nobody trusts the phone network,” says Jim McEachern, principal technologist at the Alliance for Telecommunications Industry Solutions (ATIS.) “When they stop trusting the phone network, they stop using it.”
https://nymag.com/intelligencer/2018/05/how-to-stop-spam-rob...>
I've mentioned this on HN a few times: https://news.ycombinator.com/item?id=21494300> https://news.ycombinator.com/item?id=21542926> https://news.ycombinator.com/item?id=28756827> https://news.ycombinator.com/item?id=29003329> https://news.ycombinator.com/item?id=31939562>.
Broadband Breakfast just addressed the issue as well in this Fediverse toot, calling out not just schools (subject of the legislation) but other affected entities: https://mastodon.social/@BroadbandBreakfast/1169990755811584...>.