Hacker News new | ask | show | jobs
by inigyou 1 day ago
I sign up for a newsletter from Google, then I report it as unsolicited. Boom, I just made Google pay me $10.
1 comments

That's a familiar complaint from the world of email, where it's usually applied to mailing lists.

If I were to steelman the concern, I'd look at a few related scenarios, say, where a subscriber is running a poorly-secured VOIP system and spammers hijack that to make calls. I'll ... get to that.

First: the scenario here is phone systems, not email, so the traffic would be voice calls, possibly texts. That said, I'll consider your question as if it was calls and not newsletters.

I've given a more detailed breakdown of how I see a bonding system working here, you might want to read it before continuing with this comment: <https://news.ycombinator.com/item?id=49129679>.

Second: It's not subscribers who are on the hook for spam calls, but carriers. So Google isn't paying you, your carrier is paying you (via a Surety agent), with the option of recouping that penalty from an upstream carrier, if any. If you and Google are on the same carrier, and the call didn't transit any other networks, it's just you and your own telephony service provider (carrier).

A carrier might have its own TOU/TOS with its subscribers, and subscribers originating calls could and likely would attempt to recover abuse costs if they were incurred. That subscriber (say, Google) might also have its own TOU/TOS addressing the case of mis-reporting of authorised contacts. Those actions would be outside the bonding system itself. A party repeatedly abusing the system could be liable for other actions, including fraud or malicious damages.

Note that one of the interesting elements of bonding is that call origination becomes a risky activity for telcos. Presently, telcos are eager to enter such business, put few restrictions or obligations on their customers, and to prefer outbound traffic to inbound traffic. Under a bonding programme, this changes dramatically. Large-volume outbound traffic is a liability, where it does occur, it needs to be closely monitored and managed. Our poorly-secured VOIP system mentioned earlier would probably be subject to configuration/operation validation, pen testing, close monitoring for activity, and alerts/throttling if unexpected usage patterns emerge. All of this is now in the carrier's interest.

Third: The bonding scheme would be periodically settled among carriers. I've hand-waved how often this would occur, though somewhere between daily and monthly, with a shorter term more likely (malicious actors often shoot-and-scoot, we want to avoid that). So low-level skirmish actions such as you describe would tend to result in a net wash between carriers: claims on one would be balanced by claims on others.

Fourth: Just how Google came to communicate, what it's communicating, and the degree to which it's coercing, say, receipt of sales/marketing messages vs. strictly advisory messages tied to a service ... would probably have to be considered in a larger context, but would still be outside the bonding system itself.

Fifth: There's a model for how surety bonds and claims work in the State of California's syste. For a breakdown of that see: <https://www.jwsuretybonds.com/states/california/telemarketin...>.

A few other points:

- New relationships might be permitted through a contact request. This itself could be mediated by a known third party. Private individuals for personal contacts, commercial or governmental trusted parties in other cases. Effectively it's the social-introduction problem from before the age of mass communications brought forward. Such systems will have some friction (necessary to defeat spammers), but not so much friction that the system as a whole doesn't work.

- Bonding does not require strong KYC for small accounts. That is, the person wanting to buy a mobile phone and service anonymously could, but their device and service would be monitored for abuse. I expect a tiered system to emerge, with individuals, small, mid-sized, and large accounts, with increased controls and obligations proceeding with scale and/or capability.

- Generally, it's not individual accounts which are responsible for large volumes of outbound calls, absent an issue such as a proxy hijacking. Large outbound volumes will tend to be associated with known call- or data-centres, and can be managed as such.

- The goal is preservation of a general-availability, universally-accessible phone system. That works only if it is not systematically abused, which is presently the case. If trust in public-switched telephone networks, permitting direct-dial access to any other number, anywhere in the world, is lost, what we'll see is desertion to other options which serve specific individuals' and organisations' interest. We are already beginning to see this, though no one clear winner has emerged. Unfortunately, most of the alternatives are proprietary, though some federated networks might prove to be viable alternatives.

So I just sign up for $60, collect a bunch of calls and then report them all a spam, earning me a guaranteed $1000 from the phone company?
Please see my second point above, particularly the 2nd 'graph.

If you're acting fraudulently and at scale, there will likely be consequences.

If this happens occasionally, it's a feature of the system, and your reports effectively become a super-opt-out.

And if perhaps the problem does become sufficiently widespread, I'd be interested in seeing how you'd address it given one constraint: operating within the bonding/surety system I've suggested. And that the State of California and others have already enacted in some form.