Hacker News new | ask | show | jobs
by otterpro 1 day ago
I no longer can answer my phone. I get at least 20-40 spam/scam calls per day, and many are legitimate companies calling for loans and refinancing offers, which started after I got a home loan. I cannot seem to stop them from calling, and even though my phone number is listed in National Do Not Call Registry for many years, it hasn't worked at all. The only relief is that on my iPhone, I was able to block all calls not found in my contacts (ie whitelist phone numbers only).

Now, my only worry is that I might get a call from someone who I need to talk to, but is blocked and I won't even know it. For example, what if I get an emergency call from police/fire/hospital and I won't even know it. I also tried using "Screen unknown caller" feature, but then, no one likes them and sometimes they think it is AI bot and they usually just hang up (which is great for spam caller but not for legitimate caller)

My only solution that I could think of is to have a dedicated phone line just for friends/family/work, and a second line for banking/shopping/utilities/everything else.

9 comments

> My only solution that I could think of is to have a dedicated phone line just for friends/family/work, and a second line for banking/shopping/utilities/everything else.

This fails the moment one of your "clean line" contacts downloads a sketchy app that sells all their contacts, and sells an updated list as your appear in their recent calls list - meaning it's not a one-time thing, it's for a few weeks after every time you call them.

It works if you only allow incoming calls from your contacts (e.g. whitelisted numbers) on friends/family/work line. If that number leaks, who cares? The random numbers will be blocked anyway. Probably would want to set it up so the 'public' line is silenced - just periodically check the VM box for anything important.
It seems possible, but maybe not affordable, for scammers to buy information about you and then spoof numbers of places that could/should theoretically call you. If you couple this with the potential victims on the other end being elderly you've greatly increased the risks of the attack being successful.
But then you're right back where you started: When you need a clean number for a hospital or similarly important service to call (Wife's work, daycare, school office), it goes to the distrusted, silent-by-default line, or, just as bad, it doesn't ring the clean, only-whitelsisted-numbers-ring line
> I also tried using "Screen unknown caller" feature, but then, no one likes them and sometimes they think it is AI bot and they usually just hang up (which is great for spam caller but not for legitimate caller)

When its someone legit I find that they actually go through the effort. I've had USPS explain who they were to my phone and I was able to answer them as a result.

I get the comfort that "normal person" would send an SMS "it was me Greg, call me back" if you don't pick up and most of my family is on whatsapp anyway.

Scammers or spammers will never send an SMS with clarification that they wanted to call you.

But a normal person could be calling from a doctor's office, a hospital, or your child's school - and not an actual cellphone, and they may not want to text you (or not be allowed to text you) from their personal cellphone, either.

As a parent, the "block all numbers!" approach has always seemed incredibly naive to me.

Those will usually leave a voice mail if it's important. Then you can call the place back and discuss it. If they don't bother to leave a voice mail, then it's not urgent / important.
Doctors' offices, hospitals, and schools are well aware of this problem because they're dealing with both the outgoing and incoming elements of it. Many hospitals no longer permit direct calls to inpatient rooms because of the spam and fraud rates. Outbound communications are similarly frustrated, and are driving use of online and app-based contact methods (with ... their own issues).

Other organisations, institutions, and businesses too. HN discussion tends to focus on the consumer side of this, it's what most commenters have most familiarity with themselves, but you'd better believe that pretty much the entire phone customer base is fed up to there on this. Which puts the entire network at risk of defection, a risk that telcos have been talking publicly about for over a decade now:

[S]ince mid-2015, a consortium of engineers from phone carriers and others in the telecom industry have worked on a way to [stop call-spoofing], worried that spam phone calls could eventually endanger the whole system. “We’re getting to the point where nobody trusts the phone network,” says Jim McEachern, principal technologist at the Alliance for Telecommunications Industry Solutions (ATIS.) “When they stop trusting the phone network, they stop using it.”

<https://nymag.com/intelligencer/2018/05/how-to-stop-spam-rob...>

I've mentioned this on HN a few times: <https://news.ycombinator.com/item?id=21494300> <https://news.ycombinator.com/item?id=21542926> <https://news.ycombinator.com/item?id=28756827> <https://news.ycombinator.com/item?id=29003329> <https://news.ycombinator.com/item?id=31939562>.

Broadband Breakfast just addressed the issue as well in this Fediverse toot, calling out not just schools (subject of the legislation) but other affected entities: <https://mastodon.social/@BroadbandBreakfast/1169990755811584...>.

Jim is a good guy and ATIS tried real hard with STIR/SHAKEN, but technology cannot overcome the commercial incentives that carriers have to let this nonsense continue. I've written about this before too [0].

[0] https://news.ycombinator.com/item?id=48920432#48928781

I'd seen your earlier comment at the time.

Your follow-up, here (<https://news.ycombinator.com/item?id=48938169>), was particularly insightful, and has influenced my thinking. Essentially: authentication / validation should happen out of band with phone number itself, for the reasons you've given.

I do suspect that for routing authentication, header-level signifiers should be reasonably useful, but for strong identity or authority attestation, they're not. That's ... a deeper problem, but also one which can be solved independently.

Oh, and I'd love to see that Dallas Morning News AT&T CEO interview story, if you could find it.

Would this be it?

"Watchdog Memo to AT&T's CEO: Didn't mean to get you in trouble", by Dave Lieber (July 8, 2016) <https://www.dallasnews.com/news/watchdog/2016/07/08/watchdog...>

Yes, I think that is it. Thank you for finding it!

AT&T took some bad press around that time, and in July 2016, the FCC, facing political pressure, and now sensing that the PR gods were now on their side, leaned on the major carriers to set up a 'task force' to get things moving. I remember sitting in the little room at the FCC while various telco industry grandees bloviated. We all agreed that ATIS and IETF should define technical standards since they'd already made a start (Jim M did ATIS, for example) and so everyone agreed that STIR/SHAKEN was going to be The Path.

The original STIR/SHAKEN assumptions were that the attestation would be carried throughout the network in a SIP header and that every SIP processing element would deal with it. Reality soon intruded in the form of ancient telco equipment that didn't have the headroom to process another bunch of bytes in every call setup message. Another idea was to have signing and verification done by SIP application servers, but that didn't pan out for the same reasons. (Forgive me, I'm going to toot my own horn here for a second:) I invented a scheme with my colleagues where the signing or verification was an HTTPS operation triggered by the SIP device at the network perimeter (a 'session border controller' in telco-speak) which made the problem more tractable. AT&T took my PowerPoint and submitted a stunningly close copy as their own to the FCC. I still have the slides somewhere. I was salty at the time but ah well, what can you do: my employer still made money off the product with other customers.

Yeah. A few months ago my wife and I had a miscommunication that ended up with her one place without her phone and me waiting for her in a different place. Completely unknown number, but since it didn't come up as suspected spam I answered it.
Same as GP. I silence unknown callers, and unknown text messages. They can leave a voicemail, and I might check it at some point. I check unknown texts a little more often, but they don't interrupt me with an alert which is the important thing.

No police/fire/hospital emergency outcome is going to hinge upon someone else answering a phone call or text messsage.

What I did was implement a SIP number that asks for a random digit to be pressed before allowing the call through. It also connects to my CardDAV server, and any numbers in my address book don't get the prompt. This works for 95% of bogus calls. The only thing this stops is people not on my address book calling from hands-free. But this has never come up in conversation so I think I'm OK!
The fix is a Google Voice number that you replace every few years. Keep your permanent number guarded for critical services only.
I too set it up so all unknown calls go to VM. I figure if legit they will leave a message. If two calls and no message I block the unknown number.
Roughly 100% of my spam calls come from spoofed numbers and don't repeat, so I never bother blocking anything.
There's a technical hack available here as well.

Some carriers offer blocking all unknown calls from specified area codes. On Verizon that is "Neighborhood Filter", part of their "Call Filter" toolkit:

<https://www.verizon.com/support/knowledge-base-238154/>

<https://www.pcmag.com/news/verizons-neighborhood-filter-bloc...>

The way it's meant to be used is that the subscriber would block their own area code, and perhaps co-located overlays or neighbouring area codes. The limit for now is ten area codes.

Known or explicitly approved numbers are passed through.

The additional hack is that it's possible to request a number in any arbitrary area code, and spam and robocall rates vary tremendously across area codes. They're generally worst across the Deep South / Southeast (TX, OK, AR, AL, MS, TN, GA, SC, NC), and lowest in Alaska, Utah, Massachussetts, Washington, and North Dakota.

See:

"The Robocall Epidemic: Which states are hit hardest by spam calls?" (10 March 2026) <https://www.whistleout.com/CellPhones/Guides/robocall-epidem...>

"The Robocall Geography Tax: Why Your ZIP Code Determines Your Spam Reality" (23 October 2025) <https://www.karmacall.com/blog/southeast-spam-call-geography...>

I'd submitted the latter a few days ago: <https://news.ycombinator.com/item?id=49082473>.

Pick a low-spam, low-population state, request a number from one of its area codes (if not its one area code ;-), and then block all but known numbers from that area code.

Ha, for a brief moment I thought VM=virtual machine and not voice mail and was scratching my head how you set that up and what the VM is doing with the call
Right but what keeps the second line clean? You’re going to get spam there too.
> The only relief is that on my iPhone, I was able to block all calls not found in my contacts (ie whitelist phone numbers only).

It is insane that Android still does not have this option. It has to be some kind of software patent horseshit preventing them from adding the feature.

Live in Europe, last time I got a spam call 4-5 years ago it was my ISP asking of I wanted to add tv to my internet. Told them not to call me again and they didn't.
I live in Europe and I get scam calls and sales calls. Yes, legit companies spam call less in Europe due to regulation but scammers committing crimes don’t care about privacy laws etc it’s their least problems
From European numbers? Someone had to scan their passport to get that number. The police can check.
Dont get those either, maybe just an outlier but GF don't get them either.
I get them maybe 3-4 times a year. So, not _never_ but not a big problem either
You are lucky. I been on a financial scam list for the last 18 years. They call maybe twice per year. Almost interesting to see over time what scams are trendy.
I live in Europe and I get spam calls from the US :(