SHAKEN/STIR has a loophole for calls passing through legacy trunks that don't support it. So now certain carriers made a business model off of routing your scam calls through those trunks so they won't have to be verified.
There's a related issue apparently of small operators who can't afford (or haven't been bothered) to implement STIR/SHAKEN. Many of these are apparently small rural phone co-ops (its own interesting bit of telecoms history). There should be both support in providing them with such capabilities, and penalties for failing to do so, including liability for transiting spam calls to their own or other carriers' subscribers.
Well then phone companies will stop originating/routing/sourcing calls. Do you want that? Your idea has been implemented for banks already, and the result is that machine learning algorithms randomly block transactions and close people's accounts for no reason.
Where there's legitimate business, and the risks are low (including the overwhelming majority of personal / residential lines, as well as most business / institutional lines), there's absolutely no problem.
The key is getting incentives right. Indexing bonding and payouts to the spam level, and having a target, is one way to approach this.
The problem with cheap comms, or cheap anything, is that it makes low-return, high-volume activities viable, including especially those which externalise costs and internalise benefits. Such as, say, fraud or spam generally.
What my proposal does is internalise those costs to spammer and telcos which facilitate them, by raising effort (most bulk calls are blocked) and shifting the financial incentives. From participating in the fight against spam for the past 30 years I've a pretty good notion that this will work. And unlike email, the phone system already has a costing and payment system built in.
With single spam operations generating hundreds of millions to billions of calls monthly and barely achieving profitability, I'm pretty sure we can knock things back a lot without inconveniencing legitimate players.
Please walk through just how you'd accomplish this, at scale, in a system with many chain-of-authentication holes, spanning international jurisdictions.
Please walk through as well, what the privacy, surveillance, data-disclosure, third-party bad-actor, and authoritarian-government risks of such a system would be.
<https://news.ycombinator.com/item?id=49130932>
There's a related issue apparently of small operators who can't afford (or haven't been bothered) to implement STIR/SHAKEN. Many of these are apparently small rural phone co-ops (its own interesting bit of telecoms history). There should be both support in providing them with such capabilities, and penalties for failing to do so, including liability for transiting spam calls to their own or other carriers' subscribers.