Hacker News new | ask | show | jobs
by etchalon 1 day ago
I genuinely don't understand why this is so hard to tackle.

Phone numbers are a scare resource and the telecommunications networks heavily regulated with numerous central points of control.

This bullshit is scaling because the companies which gate and sell that access have no obligations, legal or otherwise, to deny scammers access to their resources.

3 comments

One word: incentives. You're absolutely right- and telecom networks get us on both sides. They collect fees from the scammers, then fees from customers to block the scammers. Can't get any better than that.
so penalties for telcos have to be higher than they earn from scam calls.

2-5% of scams succeed but penalty should be there accounting for 95-98% that did not succeed.

IANAL but I know failed attempt at robbery or murder is also prosecuted, failed attempts at scam are not, because people just hang up and move on. Then the reality is society doesn’t have enough resources to deal with "scam attempts" - well we have to focus on murder attempts an plain robbery

I don't think we want telcos to block scam calls themselves. We want them to be forced to give the subscriber's actual address to the police.
Why not?

And why would you impose a highly-intrusive personal-tracking system across billions of subscribers?

Because I don't want some stupid AI system to randomly decide I'm a spam caller.

And you know every other country has full KYC for phone connections, right?

What would be a sufficient appeals process or remedy action that might address your concern?

What activities are you engaged in which make you think you'd likely be considered a spammer? What specific harms do you see occurring? Might these be related to your present line of business / profession / employment?

They don't to block scam calls. They can easily limit who gets access to make them, making the resource itself precious enough no one would risk wasting it on a dial scam.
I was under the impression that SHAKEN / STIR was supposed to do that by authenticating the phone numbers displayed against the telco that made the call. But as the other comment says, your telco earns money from scam calls and they don't want that to stop.
Identification is insufficient without accountability.

SHAKEN/STIR identifies whether or not a given number is originating from a specific network, but without knowing whether that's an approved network, rejecting unapproved-origin calls, or tracking how much unapproved traffic a given network is emitting and penalising it for this, the information isn't actionable.

"Measure it harder" doesn't solve problems. The information must direct meaningful action.

SHAKEN/STIR has a loophole for calls passing through legacy trunks that don't support it. So now certain carriers made a business model off of routing your scam calls through those trunks so they won't have to be verified.
Which is why we turn originating / sourcing / routing calls into a risk. See:

<https://news.ycombinator.com/item?id=49130932>

There's a related issue apparently of small operators who can't afford (or haven't been bothered) to implement STIR/SHAKEN. Many of these are apparently small rural phone co-ops (its own interesting bit of telecoms history). There should be both support in providing them with such capabilities, and penalties for failing to do so, including liability for transiting spam calls to their own or other carriers' subscribers.

Well then phone companies will stop originating/routing/sourcing calls. Do you want that? Your idea has been implemented for banks already, and the result is that machine learning algorithms randomly block transactions and close people's accounts for no reason.
Telcos will stop originating high-risk calls.

Where there's legitimate business, and the risks are low (including the overwhelming majority of personal / residential lines, as well as most business / institutional lines), there's absolutely no problem.

The key is getting incentives right. Indexing bonding and payouts to the spam level, and having a target, is one way to approach this.

The problem with cheap comms, or cheap anything, is that it makes low-return, high-volume activities viable, including especially those which externalise costs and internalise benefits. Such as, say, fraud or spam generally.

What my proposal does is internalise those costs to spammer and telcos which facilitate them, by raising effort (most bulk calls are blocked) and shifting the financial incentives. From participating in the fight against spam for the past 30 years I've a pretty good notion that this will work. And unlike email, the phone system already has a costing and payment system built in.

With single spam operations generating hundreds of millions to billions of calls monthly and barely achieving profitability, I'm pretty sure we can knock things back a lot without inconveniencing legitimate players.

Banks have this rule and it's terrible. My proposed alternative: if someone spams you, get them arrested.
I think making noise is cheaper than reducing it.

And I think this is also a problem at the habit/behavior level for people. Most people don't want to know how to set proper boundaries with people and technology and articulate what they want. Once you do that at least you can articulate what you want to come in at you or not.

Without that you get stuck with a weird one-size-fits-all policy which definitely doesn't fit for me at least.