Skip to content

Comment on Understanding STIR/SHAKEN – New Anti-Robocalling Protocol

Comments

Always want to fill out the old https://craphound.com/spamsolutions.txt form with these ideas. Like the open world / closed world AI problem.

It might seem odd to north americans, but I never received a single robo call my entire life.

I received one spam call in the last 10 years, and the guy exused himself when I told him what he is doing is illegal.

This feels a bit like “weapon laws won’t solve anything” and “social healthcare can’t ever work”. So either Europe is living in an weird strand of alternate reality, or maybe some problems _are_ solvable if you really want to.

It's a regulation problem, not a technical one. In Germany --and probably in other EU countries--, the telco must make sure that a caller is authorized to use a certain number as origin. STIR just shifts that responsibility to some other entity.

If a call originates from an untrusted network, you remove the number or indicate that it is user-provided and probably fake. It would help if phones would properly display the difference (P-Asserted-Id present or not).

Isn't it also the case that in Germany the caller pays for the wireless airtime when calling a cellphone, not the recipient?

In the US, voice time is rarely metered for domestic calls. Even discount providers offer unlimited domestic calling. The only case where you see metered calls is for pre-paid SIMs, which aren't very popular here, because you can get unlimited talk & text for $25/month.

Isn't that the case everywhere? The caller pays for the call, the recipient doesn't? Where are you? My grandma has a prepaid SIM that I call and she never pays anything, just a small amount every few months to keep the number alive.

The US had a situation where the following happened

1. They issued all their phone numbers according to a geographic system, the North American Numbering Plan. Most cities would have one prefix, some larger ones gradually needed two or more, but basically you can tell from a number if the call is local.

2. Calls to local numbers were cheap or free, because routing a call on a circuit a few miles costs essentially nothing. Just spread the cost over all subscribers, it's fine.

3. Mobile telephones exist. NANP is full. How do we number these new phones? Let's give them local numbers wherever you're buying the phone.

4. Oh, but calls for a mobile cost more. Do we make everybody pay extra for the small fraction with mobiles? No. Can we charge callers for calling a mobile? They'd have no way to know they're getting charged because the numbers are local! OK, so let's charge _mobile owners_ when they receive a call.

5. Then everybody buys a mobile phone.

The end state is always the same, everybody eats the cost of maintaining a network and calls are basically free. But the way they got there was different from most countries.

I remember when staying with relatives when I was younger and calling long distance home for a minute to tell my mom to call my back on her cell so the family could talk for cheaper. I'd wait around until it was late enough in the evening that nighttime rates for her cell were cheaper than the long distance rate.

Thanks so much for the explanation. I had no idea :)

Is there a downside to doing this?

Not one I would be aware of. The problems the German network has, has more to do with coverage, monopolisation and the state selling frequency bands for far too much money on dubious auctions.

But this has not much to do with the phenomenon that spam is pretty much nonexistent compared to the US

Europe has stricter regulations. When I worked in a company 8 years ago that were sending sms to customers with text like - your order is ready, please come pick up, etc. And we used company name instead of number as sms allowed that, only 8 letters but was enough for us, but around that time we suddenly weren't able to do that anymore and company we used to send sms through said that some laws were passed and we must use one of the numbers registered to us and that's it.

I think that explains why it is much harder to do robocalls in some parts of europe at least.

That was never a law - you were probably just caught up with an interpretation by the service provider.

You opened this up to a larger discussion - but you are essentially correct. These problems aren't really problems if you decide to act. However, at least in the U.S., acting seems to cost money.

Well in the US the people responsible for the brazen robocalling can simply hire lobbyists to convince congress it is bad to limit robocalls. So our entire system is a bit broken at the moment when we have a terrible congress and a president who appoints questionable leaders (see the guy who he put in charge of the FCC ending Net Neutrality)

In Italy my family used to get daily (multiple per day even) robocalls just a couple of years ago. So Europe is not a single reality, as always.

Now that I think of it, it mostly stopped. Could it be GDPR?

It's been 20 years and it doesn't stop being funny. I'm afraid I'm a 12 year old boy in the body of a 40 year old :(

That thing effectively meant that you couldn't propose an actual solution to the SPAM problem that was fair for everybody, open source, etc. Instead Gmail went ahead and made one that is secret and hugely benefit them, people went to gmail because it actually worked, and yet some it is still linked to and considered a good thing.

I get plenty of spam in my Gmail inbox. Their filtering isn’t magic or perfect.

Worse, Gmail’s spam filter generates tons of false positives, and these are often the messages I want most: password resets, legit balance alerts from my bank.

It's still spot-on today, except perhaps s/Microsoft/Google/g (fully-encrypted Gmail comes to mind).

I was just thinking about that.

Your article advocates a (X) technical solution to robocalling.

Your idea will not work. Here is why it won't work.

(X) Requires too much cooperation from telephone service providers

Specifically, your plan fails to account for

(X) Extreme profitability of robocalling

Furthermore, this is what I think about you:

(X) Sorry dude, but I don't think it would work.

1) The FCC is threatening all kinds of hell for service providers that don't implement shaken/stir. AFAIK all the major US carriers are already committed to implement it.

2) Robocalling is probably not net profitable for the carriers. Much of it originates from abroad and much of it is associated with other kinds of fraud. Never mind the secondary impacts due to users deciding not to get phone lines if they are just going to receive spam.

But then again, email spam has been solved for the most part

That list is kinda defeatist and misses the fact that no solution needs to work 100% of the time

We have paid for that in features though. You can’t really use your home connection as a mail server anymore, for instance.

But then again, email spam has been solved for the most part

Only if you use one of the big email providers or if you pay to route it via some antispam system. If you don't and play around with e.g. Postfix and spamassassin then you'll notice more than enough spam.

If you use Postfix and CRM114 (http://crm114.sourceforge.net/) you can achieve equivalent or better spam filtering than the "big email providers".

I get maybe 1 spam every six months that leaks through. I simply add it to the crm114 filter as "this should be spam" and then no spam again for another six months or so.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.