Hacker News new | ask | show | jobs
by evilantnie 783 days ago
STIR/SHAKEN doesn't prevent spoofing. It can verify in certain cases when a call is not spoofed but it's fairly limited and almost entirely mobile-to-mobile phone calls. It requires IP based network connectivity end-to-end, which just isn't possible in the US. If a call gets routed through a rural network and switches back to TDM, it will drop all STIR/SHAKEN data. It will still take years for US infrastructure to be entirely IP-based. Robocallers sign their calls with STIR/SHAKEN just fine, the originators do this for them, so it's not going to be a strong deterrent in my opinion.

Devices support attestation level A display (green or grey check marks in your call logs designate this). If you haven't seen that check mark, then you probably haven't seen many A-level attested calls to your device. As far as device manufacturers go, they only care about A-level attestation, which makes sense as it has full traceback capability.