Hacker News new | ask | show | jobs
by toast0 1903 days ago
As the sibling comment says, spoofing sender ID or caller ID is relatively easy. You can't trust it, outside of some very narrow cases (although, shaken/stir may change that).

Some carriers do make available lists of recycled numbers, and some telephone information companies aggregate these lists, when I was looking, coverage was sparse though, and questions about reliability and privacy were too big relative to the limited coverage. Sharing of confidential information was an issue too: carriers wanted to provide events only for numbers of interest to a 3rd party service, so the carrier didn't divulge the number of customers leaving their service; the 3rd party service didn't want to provide numbers of interest because it would divulge user count. I may be biased (I was working for a service), but the recycled number list feels less privacy invasive than providing numbers of intetest. The numbering space is small, so you can't meaningfully obscure the numbers, etc. Determining which carrier is responsible for a number is also tricky, of course.

1 comments

If they prompoted to receive a code during sign-up it would make the system immune to a person accidentally entering the wrong number. Only malicious entry would remain, which I suspect the company would ultimately not be liable for. So I believe it would actually be a better solution if the goal is to prevent robotexting people who didn't consent to it.
So I think you're proposing, enter your number, get a code, send a text to a special number with that code, get a text reply and enter that. Then the service has done their best job of validating the number before they validated it.

Of course, getting a working incoming number for all countries worldwide that doesn't cost users an arm and a leg to message is not exactly easy.