Hacker News new | ask | show | jobs
by smallmancontrov 13 days ago
Speaking of which, what happened to SHAKEN/STIR? I thought the strong authentication requirements came down the pipe years ago and they were going to start turning off (or hiding by default) routes of low reputation. That was years ago, it was supposed to take years, but here we are years later and I still get loads of spam calls. What happened?
3 comments

I worked on STIR/SHAKEN for the two biggest US operators. The techies tried very hard to make it work, and, indeed, there was a brief time when it worked pretty well, but, the incentives from Corporate were and are fundamentally misaligned.

Type A attestation is, generally, solved. Carrier A attests that the number is one of theirs, and they know that the caller is one of theirs too and attached to their network.

However: this is a fraction of calls. Carriers also sell blocks of phone numbers without the corresponding access network. This is what allows you to pick, say, a Twilio number with a local area code. In these cases the best that can be hoped for is a lesser attestation.

But it gets worse, because the operator can also sell blocks of numbers to people with no direct connection to the US carriers and who need to spoof US numbers. That call from Capital One comes from the Philippines via two or three intermediate operators, none of whom can attest to much of anything. And into that gap ride the spammers.

Furthermore, in an Experian-like twist, some carriers also realized that businesses would pay to have their calls show up as "trusted" on the recipient's phone. So the standards were enhanced to deliver 'rich call data'. However, in order to be something worth paying for you also need a baseline of calls that do not have that premium look. A scam? You decide.

Finally, one other misaligned incentive. All of this needs VoIP. Not TDM (classic legacy telephony). However, the big US carriers make bank selling TDM circuits to the hundreds of small regional telcos, and refuse to sell them SIP trunks, because it's s such an easy money maker. So again, technology loses to incentives. These incentives, to make money from phone numbers, vastly outpace what

So we can't block shady spammers because business wants shady customer support call centers? Ugh. It figures, but ugh.

Thanks for the inside perspective.

I'm going to mangle the terms of art here, but the ur-problem is that labels of routing, like phone numbers and email addresses, get confused with labels of identity, and then with indicators of trustworthiness.

Everything is built to address that weakness - think DKIM, SPF, etc, plus STIR/SHAKEN, to say nothing of IP or ASN filtering, but they feel like bandaids on a very difficult problem. What you end up with are basically default-deny except for a personally curated trust set ("only accept calls from my contacts", "everything goes in spam unless I have previously corresponded with the sender"), etc.

One last robocall story. AT&T sat on their hands for years until consumer groups embarrassed the then-CEO enough to do something about it. There was a memorable interview in the Dallas Morning News where they called him on it instead of lobbing him softballs and I suspect that the embarrassment finally got through.

Details please on the AT&T CEO story
It's worth noting that TFA addresses this in the context of the scam: When the scam depends on the emotional reaction in response to a loved one's distress, it doesn't matter if the number the scam is coming from is unfamiliar. This means that the scam can use "technically correct" numbers that pass SHAKEN/STIR with no loss in conversion.

TFA also mentions that by routing calls through older non-IP networks you lose the accurate information, although it sounds like the FCC is slowly cracking down on this.

It is hard to get vendors to give up revenue no matter how illegal the source of revenue is.
So lots of judicially-unreachable call centers under judicially-unreachable telecoms need to lose reputation score and get spam-binned by default, just like email. I thought that was going to happen by now. Did the US telecoms just chicken out?
Why not fine vendors instead? They'll quickly change the tune..