The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the call in question entered his own network from. The last cooperative network in the chain gets stuck with the fee, forcing them to either reclaim the money from the malicious customer, the next network in the chain (in court) or pony up the money themselves.
Result: All routes to non-cooperating networks get dropped within days to weeks and scam-calling stops being a lucrative business basically instantly.
That's pretty much the proposal I've made for some years.[1]
California has introduced bonding to telemarketing firms specifically. I feel that should apply at the carrier level, where networks carry a guaranteed bond, pay regular premiums on it, and are dinged for unwanted calls, with the proceeds being split among the called party and any third-party network(s) traversed by the calls. Downstream networks could seek compensation from ANY upstream network carrying the traffic regardless of whether or not they originated it.
This would both create a penalty for providing, or transiting, unsolicited calls, AND create an incentive for carriers / network providers themselves to pursue unsolicited traffic from their peers.
I think we have to do something this extreme. We have to give the system a total makeover. Somehow we also have to keep it from being fully centralized and have the big brother problem on the other side. Unfortunately these two goals are difficult to get through at the same time, with the system that we have.
If major states like California and New York pass it, and spam basically dies in those states, it wouldn't surprise me if it spreads across the country.
Infeasible. Fraud or spam is usually pretty hard to confirm from one recording without additional context. Many scammers have plausible deniability or are just checking whether the number is active. Moreover, this solution would involve secret non-consensual recording; what if it's not a scam?
Plus, who is ‘confirming’ the spam? The same entity (or group: carriers) that is keeping the $10 and paying the $100 out? That just means the result will always be ‘not spam.’
Sure, but that's okay because you don't need 100% of spam calls to be recognized as spam for the incentive to do its job. The system still sounds like it could still work even if a large percent of calls weren't flagged.
How are they listening to a few minutes before the button? A "temporary" recording of the first 2 minutes of every call? I feel like there would be some privacy concerns.
It'd suffice for them to sign the transmitted information (audio and required timing metadata for the packet stream) and make you do the temporary recording on your side, transmitting it back to the provider once you hit the button, to let them handle the backup/safekeeping aspects for you.
Simpler yet: require every call to come with a physical source address, huge (and enforced) jail times for faking it. Let the internet and the pissed callees crowdsource the rest
I spent a little time unsuccessfully looking for a reference, but in some ancient Greek and early Roman governments, newly elected officials who were in charge of money were required to personally indemnify (become responsible for the professional liabilities of) their predecessor.
If your predecessor committed fraud, you were 100% personally responsible for it. You would then gather the evidence and sue your predecessor for your losses.
That sounds like a great way to attract scammers and dissuade honest people, so if it's ever been tried it must have failed spectacularly (I also searched for variations of this idea but didn't turn up anything).
It probably worked for Romans because the taxes you were allowed to collect was so much more than you had to send back to Rome that you could get rich 'honestly'. That and you had options to prove the fraud that meant the other was unlikely to try.
I don’t understand how this works. Suppose someone calls you about some political poll and you hit the button, would it count or not? What about a cold email (there was another such thread about cold emails being praised, i said fundamentally is spam but was downvoted lol).
One of the biggest concerns I have with phone scams is that the people most vulnerable are the elderly, and they don’t have the knowledge on how to block these calls (if a technical solution is the only option).
And further to that, the elderly are also the ones who cannot block unknown numbers, because doctors’ offices seem to have random numbers they call you from (they may have a pool of numbers but it’s not reasonable to add all of them to contacts). Blocking all unknowns would block these important health related calls as well.
> because doctors’ offices seem to have random numbers they call you from
This is a huge issue with scam/security awareness education. Too many legitimate orgs use the exact behaviors we tell people to avoid. Same thing with email, can't tell someone to never click links in emails when services keep relying on magic links, third-party notification domains, etc. SPF, DKIM, and DMARC do nothing because scammers will just typosquat.
In the phone number example, most of those numbers too are unlisted outbound numbers, you couldn't even google them to verify.
Half the battle is getting legitimate organizations to stop acting like scammers in the first place so that shady behavior becomes an obvious red flag again.
It being a major concern doesn't mean there's any solution around said concerns. Give me 100 old peoples phone numbers and I bet I could convince 10 of them that I am AARP trying to make them safe and eventually get money out of them.
And if you think spam calls on your cell phone are bad... oh boy, land lines get about 10x the calls. My theory is that because it's mostly older people who have land lines on top of the fact that spam laws are tighter for cell phones. There aren't enough land line users to complain, so not a big enough voice to make a public outcry. Cell phone users have no idea the problems that land lines have.
I know this because I had to spend 6 months taking care of my dad while he was dying. We had so many medical people calling us and making appointments, and doing tests, etc etc. And on top of it about 10-15 spam calls a day and it's impossible to differentiate via caller ID. This was all while I was also working full time from home. It's a real hellscape, and these phone scammers are really having a negative effect on people's lives. It made my life miserable at one of the hardest times of my life, and I have nothing but contempt for these fuckers, and no empathy left for the people making the phone calls either. They're all scumbags and deserve time in prison.
I no longer can answer my phone. I get at least 20-40 spam/scam calls per day, and many are legitimate companies calling for loans and refinancing offers, which started after I got a home loan. I cannot seem to stop them from calling, and even though my phone number is listed in National Do Not Call Registry for many years, it hasn't worked at all. The only relief is that on my iPhone, I was able to block all calls not found in my contacts (ie whitelist phone numbers only).
Now, my only worry is that I might get a call from someone who I need to talk to, but is blocked and I won't even know it. For example, what if I get an emergency call from police/fire/hospital and I won't even know it. I also tried using "Screen unknown caller" feature, but then, no one likes them and sometimes they think it is AI bot and they usually just hang up (which is great for spam caller but not for legitimate caller)
My only solution that I could think of is to have a dedicated phone line just for friends/family/work, and a second line for banking/shopping/utilities/everything else.
> My only solution that I could think of is to have a dedicated phone line just for friends/family/work, and a second line for banking/shopping/utilities/everything else.
This fails the moment one of your "clean line" contacts downloads a sketchy app that sells all their contacts, and sells an updated list as your appear in their recent calls list - meaning it's not a one-time thing, it's for a few weeks after every time you call them.
It works if you only allow incoming calls from your contacts (e.g. whitelisted numbers) on friends/family/work line. If that number leaks, who cares? The random numbers will be blocked anyway. Probably would want to set it up so the 'public' line is silenced - just periodically check the VM box for anything important.
It seems possible, but maybe not affordable, for scammers to buy information about you and then spoof numbers of places that could/should theoretically call you. If you couple this with the potential victims on the other end being elderly you've greatly increased the risks of the attack being successful.
I get the comfort that "normal person" would send an SMS "it was me Greg, call me back" if you don't pick up and most of my family is on whatsapp anyway.
Scammers or spammers will never send an SMS with clarification that they wanted to call you.
But a normal person could be calling from a doctor's office, a hospital, or your child's school - and not an actual cellphone, and they may not want to text you (or not be allowed to text you) from their personal cellphone, either.
As a parent, the "block all numbers!" approach has always seemed incredibly naive to me.
Those will usually leave a voice mail if it's important. Then you can call the place back and discuss it. If they don't bother to leave a voice mail, then it's not urgent / important.
Same as GP. I silence unknown callers, and unknown text messages. They can leave a voicemail, and I might check it at some point. I check unknown texts a little more often, but they don't interrupt me with an alert which is the important thing.
No police/fire/hospital emergency outcome is going to hinge upon someone else answering a phone call or text messsage.
> I also tried using "Screen unknown caller" feature, but then, no one likes them and sometimes they think it is AI bot and they usually just hang up (which is great for spam caller but not for legitimate caller)
When its someone legit I find that they actually go through the effort. I've had USPS explain who they were to my phone and I was able to answer them as a result.
Live in Europe, last time I got a spam call 4-5 years ago it was my ISP asking of I wanted to add tv to my internet. Told them not to call me again and they didn't.
I live in Europe and I get scam calls and sales calls. Yes, legit companies spam call less in Europe due to regulation but scammers committing crimes don’t care about privacy laws etc it’s their least problems
You are lucky. I been on a financial scam list for the last 18 years. They call maybe twice per year. Almost interesting to see over time what scams are trendy.
Maybe this is a pipe dream, but wouldn't it be better to retire the legacy phone voice and messaging system altogether.
If 99.9% of us have internet phones, why aren't we using PKI, decentralized protocols, crowd sourced reputation to communicate instead of POTS phone numbers, SMS/iChat and relying on the carriers to police spam.
dontscamgrandma.com is probably apropos to share here for the elderly / vulnerable affected by scam proliferation. It's a trainer that roleplays people through getting the confidence to hang up and call their loved ones back.
Full disclosure I'm the founder, and I've got a couple dogs in this fight
An ask: I'm trying to find out where substantive discussion by carriers AND other parties on mitigating phone spam (voice or text) is occurring. I'd very much appreciate replies here, email (see my profile), or hop on this Fediverse thread: <https://toot.cat/@dredmorbius/116984051310517623>
Broadband Breakfast does seem to be one of those entities. ATIS (<https://atis.org/>) is another, though as a telco alliance I consider it highly suss.
I got an obviously-AI voice agent spam call yesterday. Had a bit of fun getting it to answer trivia questions (when was the treaty of westphalia ratified? answer in a rhyming couplet) as a precondition to handing over the keys to my bank accounts.
Regardless, this forces them to steal more tokens. Any token wasted not getting money reduces the efficiency of the scam. The end goal would be increasing the token expenditure above the amount they scam from people.
I get messages (and often don't answer my phone; my ringer is off) in which it's obviously this automated thing but they immediately dock it down to "press 1 if..."
'Kay. So you call people and just clearly have a tone the second you hear a voice which could well be someone's answering machine
(Of course most of it would be automated, I guess)
Funny, the same telecoms that whine about how hard this traffic is to stop... are also selling a "premium" service to customers- who then manually tag unwanted calls so that the telecom can sell that data back to other customers...
I don’t seem to be charged for Scam Shield on my account. I’ve had one unknown number call and not leave a message over the last month, which is a far cry from the 20–40 spam calls per day some people report.
There are a number of options. My view is that carrier-based filtering (rather than on-device filters) are where effort must be focused. Much as we learned with email: if you're routing traffic for many people, mass-contact attempts and patterns become quickly visible. Individuals see only a minuscule fraction of traffic, networks see overall patterns.
The other element is that carriers can act at the network level, noting how much abusive traffic arrives from given peers, and taking direct action against those peers. That could involve rejecting traffic outright, subjecting it to stronger challenges, and/or diverting it to investigative / law-enforcement bodies (I'd suggest both national and state entities) for both tracking and enforcement. Power-law relations mean that at any given time, a small number of networks will account for the overwhelming majority of spam, though which networks will likely change over time.
The key problem with this is getting the carriers to act, which ... will probably involve a few carrots and sticks. I'll address those in another comment, except to mention bonding: <https://oag.ca.gov/consumers/general/telreg>.[1]
Individual action will not solve this problem, but there are steps you can take.
Most major US carriers now offer some form of robocall blocking. "Scam Shield" from T-Mobile, "ActiveArmor" from AT&T, "Call Filter" from Verizon.
MVNOs (mobile virtual network operators) may or may not offer scam / robocall blocking themselves (though IMO they should, and should be required to). Some will identify spam calls, but those are still passed through to your handset.
Beyond this, there are on-device apps which can be used, some are carrier-based (e.g., "Call Filter Plus", from Verizon, similar tools exist for Verizon and AT&T), some are third-party. These of necessity share your voice/text activity with third parties, which is its own concern and consideration.
Full Android, iOS, and several full-featured Android alternatives (GrapheneOS, /e/OS, LineageOS, etc.) offer unknown caller rejection. Numbers not in your contact list are directed to voicemail. At present, few spam calls will leave voicemail, though some do, and as AI expands in capabilities, applications, and adoption this will all but certainly increase. I'd strongly encourage use of this.
Feature phones / dumbphones ... have far less capability. Most cannot even reject unknown numbers, which ... seems a ripe target for legislation and/or regulation. Phone frameworks such as AOSP / KaiOS seem to afford little capability for even creating a call-blocking app. This and other dumb devices (e.g., traditional landlines) are a strong argument for carrier/network level mitigations.
It classifies calls into three categories: high, medium, and low risk.
It adjudicates calls based on risk.
High-risk calls are terminated entirely.
Medium-risk calls are directed to voicemail.
Low-risk calls are subjected to an audio CAPTCHA (enter a two digit value to ring through), otherwise are directed to voicemail.
(It's not clear whether or not a whitelisted number will escape any treatment, perhaps subject to conditions such as originating from the appropriate/approved network for that call.)
I haven't used that system, but in advising people still moving off landlines, or looking at VOIP solutions, it's making Comcast an attractive option.
(I don't know what other VOIP providers, say, Twillo or Asterisk, offer, but suspect at least some have similar if not more-capable systems.)
________________________________
Notes:
1. California requires a $100,000 bond by all telemarketers in the state. The state has a small fraction of the incidence of robocalls of the worst US states. Several others have some bond. My view is that bonding should apply at the carrier level and be surrenderable to both contacted individuals and downstream peering networks, to provide both a strong financial penalty to abusers, and an incentive to downstream networks to pursue abusive calls.
Commerce should never have been made possible to happen on the internet. The moment it became possible to send and receive money through the internet, the end times began.
I genuinely don't understand why this is so hard to tackle.
Phone numbers are a scare resource and the telecommunications networks heavily regulated with numerous central points of control.
This bullshit is scaling because the companies which gate and sell that access have no obligations, legal or otherwise, to deny scammers access to their resources.
I was under the impression that SHAKEN / STIR was supposed to do that by authenticating the phone numbers displayed against the telco that made the call. But as the other comment says, your telco earns money from scam calls and they don't want that to stop.
Identification is insufficient without accountability.
SHAKEN/STIR identifies whether or not a given number is originating from a specific network, but without knowing whether that's an approved network, rejecting unapproved-origin calls, or tracking how much unapproved traffic a given network is emitting and penalising it for this, the information isn't actionable.
"Measure it harder" doesn't solve problems. The information must direct meaningful action.
One word: incentives. You're absolutely right- and telecom networks get us on both sides. They collect fees from the scammers, then fees from customers to block the scammers. Can't get any better than that.
so penalties for telcos have to be higher than they earn from scam calls.
2-5% of scams succeed but penalty should be there accounting for 95-98% that did not succeed.
IANAL but I know failed attempt at robbery or murder is also prosecuted, failed attempts at scam are not, because people just hang up and move on. Then the reality is society doesn’t have enough resources to deal with "scam attempts" - well we have to focus on murder attempts an plain robbery
And I think this is also a problem at the habit/behavior level for people. Most people don't want to know how to set proper boundaries with people and technology and articulate what they want. Once you do that at least you can articulate what you want to come in at you or not.
Without that you get stuck with a weird one-size-fits-all policy which definitely doesn't fit for me at least.
The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the call in question entered his own network from. The last cooperative network in the chain gets stuck with the fee, forcing them to either reclaim the money from the malicious customer, the next network in the chain (in court) or pony up the money themselves.
Result: All routes to non-cooperating networks get dropped within days to weeks and scam-calling stops being a lucrative business basically instantly.
That's pretty much the proposal I've made for some years.[1]
California has introduced bonding to telemarketing firms specifically. I feel that should apply at the carrier level, where networks carry a guaranteed bond, pay regular premiums on it, and are dinged for unwanted calls, with the proceeds being split among the called party and any third-party network(s) traversed by the calls. Downstream networks could seek compensation from ANY upstream network carrying the traffic regardless of whether or not they originated it.
This would both create a penalty for providing, or transiting, unsolicited calls, AND create an incentive for carriers / network providers themselves to pursue unsolicited traffic from their peers.
<https://oag.ca.gov/consumers/general/telreg>
________________________________
Notes:
1. See for example <https://toot.cat/@dredmorbius/111099306069523624>
I think we have to do something this extreme. We have to give the system a total makeover. Somehow we also have to keep it from being fully centralized and have the big brother problem on the other side. Unfortunately these two goals are difficult to get through at the same time, with the system that we have.
If major states like California and New York pass it, and spam basically dies in those states, it wouldn't surprise me if it spreads across the country.
Assuming the nature of the spam and how it makes money.
Cue the crypto bros touting their decentralized spam-detection blockchain
Infeasible. Fraud or spam is usually pretty hard to confirm from one recording without additional context. Many scammers have plausible deniability or are just checking whether the number is active. Moreover, this solution would involve secret non-consensual recording; what if it's not a scam?
Plus, who is ‘confirming’ the spam? The same entity (or group: carriers) that is keeping the $10 and paying the $100 out? That just means the result will always be ‘not spam.’
A lot of scams unfortunately operate right on the line of legality like the car warranty morons
Sure, but that's okay because you don't need 100% of spam calls to be recognized as spam for the incentive to do its job. The system still sounds like it could still work even if a large percent of calls weren't flagged.
This works both ways, if the detection rate is low then nobody would press a "lose $10" button.
How are they listening to a few minutes before the button? A "temporary" recording of the first 2 minutes of every call? I feel like there would be some privacy concerns.
It'd suffice for them to sign the transmitted information (audio and required timing metadata for the packet stream) and make you do the temporary recording on your side, transmitting it back to the provider once you hit the button, to let them handle the backup/safekeeping aspects for you.
Simpler yet: require every call to come with a physical source address, huge (and enforced) jail times for faking it. Let the internet and the pissed callees crowdsource the rest
This would be an enormous invasion of privacy. Other countries have a lot less issues with spam calls without these measures
I spent a little time unsuccessfully looking for a reference, but in some ancient Greek and early Roman governments, newly elected officials who were in charge of money were required to personally indemnify (become responsible for the professional liabilities of) their predecessor.
If your predecessor committed fraud, you were 100% personally responsible for it. You would then gather the evidence and sue your predecessor for your losses.
That sounds like a great way to attract scammers and dissuade honest people, so if it's ever been tried it must have failed spectacularly (I also searched for variations of this idea but didn't turn up anything).
It probably worked for Romans because the taxes you were allowed to collect was so much more than you had to send back to Rome that you could get rich 'honestly'. That and you had options to prove the fraud that meant the other was unlikely to try.
How does your predecessor today have those funds? The problem is politicians get to "play" with wealth beyond their own reaches (typically).
I don’t understand how this works. Suppose someone calls you about some political poll and you hit the button, would it count or not? What about a cold email (there was another such thread about cold emails being praised, i said fundamentally is spam but was downvoted lol).
One of the biggest concerns I have with phone scams is that the people most vulnerable are the elderly, and they don’t have the knowledge on how to block these calls (if a technical solution is the only option).
And further to that, the elderly are also the ones who cannot block unknown numbers, because doctors’ offices seem to have random numbers they call you from (they may have a pool of numbers but it’s not reasonable to add all of them to contacts). Blocking all unknowns would block these important health related calls as well.
> because doctors’ offices seem to have random numbers they call you from
This is a huge issue with scam/security awareness education. Too many legitimate orgs use the exact behaviors we tell people to avoid. Same thing with email, can't tell someone to never click links in emails when services keep relying on magic links, third-party notification domains, etc. SPF, DKIM, and DMARC do nothing because scammers will just typosquat.
In the phone number example, most of those numbers too are unlisted outbound numbers, you couldn't even google them to verify.
Half the battle is getting legitimate organizations to stop acting like scammers in the first place so that shady behavior becomes an obvious red flag again.
Just this week I got an email from Amex to be on the lookout for scams, and the email itself had a "login" button right in the top.
AARP's magazine and bulletin[1] are pretty much filled with scam-awareness articles every issue. It's an absolutely major concern.
________________________________
Notes:
1. Incidentally, the first and second largest-circulation magazines in the US now: <https://www.magazineline.com/blog/most-popular-magazines-in-...>.
It being a major concern doesn't mean there's any solution around said concerns. Give me 100 old peoples phone numbers and I bet I could convince 10 of them that I am AARP trying to make them safe and eventually get money out of them.
And if you think spam calls on your cell phone are bad... oh boy, land lines get about 10x the calls. My theory is that because it's mostly older people who have land lines on top of the fact that spam laws are tighter for cell phones. There aren't enough land line users to complain, so not a big enough voice to make a public outcry. Cell phone users have no idea the problems that land lines have.
I know this because I had to spend 6 months taking care of my dad while he was dying. We had so many medical people calling us and making appointments, and doing tests, etc etc. And on top of it about 10-15 spam calls a day and it's impossible to differentiate via caller ID. This was all while I was also working full time from home. It's a real hellscape, and these phone scammers are really having a negative effect on people's lives. It made my life miserable at one of the hardest times of my life, and I have nothing but contempt for these fuckers, and no empathy left for the people making the phone calls either. They're all scumbags and deserve time in prison.
I no longer can answer my phone. I get at least 20-40 spam/scam calls per day, and many are legitimate companies calling for loans and refinancing offers, which started after I got a home loan. I cannot seem to stop them from calling, and even though my phone number is listed in National Do Not Call Registry for many years, it hasn't worked at all. The only relief is that on my iPhone, I was able to block all calls not found in my contacts (ie whitelist phone numbers only).
Now, my only worry is that I might get a call from someone who I need to talk to, but is blocked and I won't even know it. For example, what if I get an emergency call from police/fire/hospital and I won't even know it. I also tried using "Screen unknown caller" feature, but then, no one likes them and sometimes they think it is AI bot and they usually just hang up (which is great for spam caller but not for legitimate caller)
My only solution that I could think of is to have a dedicated phone line just for friends/family/work, and a second line for banking/shopping/utilities/everything else.
> My only solution that I could think of is to have a dedicated phone line just for friends/family/work, and a second line for banking/shopping/utilities/everything else.
This fails the moment one of your "clean line" contacts downloads a sketchy app that sells all their contacts, and sells an updated list as your appear in their recent calls list - meaning it's not a one-time thing, it's for a few weeks after every time you call them.
It works if you only allow incoming calls from your contacts (e.g. whitelisted numbers) on friends/family/work line. If that number leaks, who cares? The random numbers will be blocked anyway. Probably would want to set it up so the 'public' line is silenced - just periodically check the VM box for anything important.
It seems possible, but maybe not affordable, for scammers to buy information about you and then spoof numbers of places that could/should theoretically call you. If you couple this with the potential victims on the other end being elderly you've greatly increased the risks of the attack being successful.
The fix is a Google Voice number that you replace every few years. Keep your permanent number guarded for critical services only.
I get the comfort that "normal person" would send an SMS "it was me Greg, call me back" if you don't pick up and most of my family is on whatsapp anyway.
Scammers or spammers will never send an SMS with clarification that they wanted to call you.
But a normal person could be calling from a doctor's office, a hospital, or your child's school - and not an actual cellphone, and they may not want to text you (or not be allowed to text you) from their personal cellphone, either.
As a parent, the "block all numbers!" approach has always seemed incredibly naive to me.
Those will usually leave a voice mail if it's important. Then you can call the place back and discuss it. If they don't bother to leave a voice mail, then it's not urgent / important.
Same as GP. I silence unknown callers, and unknown text messages. They can leave a voicemail, and I might check it at some point. I check unknown texts a little more often, but they don't interrupt me with an alert which is the important thing.
No police/fire/hospital emergency outcome is going to hinge upon someone else answering a phone call or text messsage.
> I also tried using "Screen unknown caller" feature, but then, no one likes them and sometimes they think it is AI bot and they usually just hang up (which is great for spam caller but not for legitimate caller)
When its someone legit I find that they actually go through the effort. I've had USPS explain who they were to my phone and I was able to answer them as a result.
I too set it up so all unknown calls go to VM. I figure if legit they will leave a message. If two calls and no message I block the unknown number.
Roughly 100% of my spam calls come from spoofed numbers and don't repeat, so I never bother blocking anything.
Right but what keeps the second line clean? You’re going to get spam there too.
Live in Europe, last time I got a spam call 4-5 years ago it was my ISP asking of I wanted to add tv to my internet. Told them not to call me again and they didn't.
I live in Europe and I get scam calls and sales calls. Yes, legit companies spam call less in Europe due to regulation but scammers committing crimes don’t care about privacy laws etc it’s their least problems
Dont get those either, maybe just an outlier but GF don't get them either.
I get them maybe 3-4 times a year. So, not _never_ but not a big problem either
You are lucky. I been on a financial scam list for the last 18 years. They call maybe twice per year. Almost interesting to see over time what scams are trendy.
I live in Europe and I get spam calls from the US :(
Maybe this is a pipe dream, but wouldn't it be better to retire the legacy phone voice and messaging system altogether.
If 99.9% of us have internet phones, why aren't we using PKI, decentralized protocols, crowd sourced reputation to communicate instead of POTS phone numbers, SMS/iChat and relying on the carriers to police spam.
Is this a USA problem, or world-wide? If other countries don't have such a problem, why not?
Worldwide. It doesn't affect everyone equally though so some in each county are not having a problem while others are swamped with garbage.
dontscamgrandma.com is probably apropos to share here for the elderly / vulnerable affected by scam proliferation. It's a trainer that roleplays people through getting the confidence to hang up and call their loved ones back.
Full disclosure I'm the founder, and I've got a couple dogs in this fight
An ask: I'm trying to find out where substantive discussion by carriers AND other parties on mitigating phone spam (voice or text) is occurring. I'd very much appreciate replies here, email (see my profile), or hop on this Fediverse thread: <https://toot.cat/@dredmorbius/116984051310517623>
Broadband Breakfast does seem to be one of those entities. ATIS (<https://atis.org/>) is another, though as a telco alliance I consider it highly suss.
(Submitter.)
I got an obviously-AI voice agent spam call yesterday. Had a bit of fun getting it to answer trivia questions (when was the treaty of westphalia ratified? answer in a rhyming couplet) as a precondition to handing over the keys to my bank accounts.
Downside is they most likely are using stolen tokens, not paying themselves so it cost them next to nothing.
Regardless, this forces them to steal more tokens. Any token wasted not getting money reduces the efficiency of the scam. The end goal would be increasing the token expenditure above the amount they scam from people.
Perhaps the future of captcha is anti-captcha. What agent can resist responding with a rhyming couplet or inverting a binary tree?
I get messages (and often don't answer my phone; my ringer is off) in which it's obviously this automated thing but they immediately dock it down to "press 1 if..."
'Kay. So you call people and just clearly have a tone the second you hear a voice which could well be someone's answering machine
(Of course most of it would be automated, I guess)
Special place in hell for these people
T-Mobile’s Scam Shield works really well for me. But you have to get the premium tier.
Funny, the same telecoms that whine about how hard this traffic is to stop... are also selling a "premium" service to customers- who then manually tag unwanted calls so that the telecom can sell that data back to other customers...
Unsurprisingly: telcos sell outbound dialing capabilities to business customers.
For spam mitigations to work, the cost of selling that business must exceed its revenue.
Some, and I won't mention AT&T by name, are very curiously opposed to any regulations touching this.
I don’t seem to be charged for Scam Shield on my account. I’ve had one unknown number call and not leave a message over the last month, which is a far cry from the 20–40 spam calls per day some people report.
There are a number of options. My view is that carrier-based filtering (rather than on-device filters) are where effort must be focused. Much as we learned with email: if you're routing traffic for many people, mass-contact attempts and patterns become quickly visible. Individuals see only a minuscule fraction of traffic, networks see overall patterns.
The other element is that carriers can act at the network level, noting how much abusive traffic arrives from given peers, and taking direct action against those peers. That could involve rejecting traffic outright, subjecting it to stronger challenges, and/or diverting it to investigative / law-enforcement bodies (I'd suggest both national and state entities) for both tracking and enforcement. Power-law relations mean that at any given time, a small number of networks will account for the overwhelming majority of spam, though which networks will likely change over time.
The key problem with this is getting the carriers to act, which ... will probably involve a few carrots and sticks. I'll address those in another comment, except to mention bonding: <https://oag.ca.gov/consumers/general/telreg>.[1]
Individual action will not solve this problem, but there are steps you can take.
Most major US carriers now offer some form of robocall blocking. "Scam Shield" from T-Mobile, "ActiveArmor" from AT&T, "Call Filter" from Verizon.
MVNOs (mobile virtual network operators) may or may not offer scam / robocall blocking themselves (though IMO they should, and should be required to). Some will identify spam calls, but those are still passed through to your handset.
Beyond this, there are on-device apps which can be used, some are carrier-based (e.g., "Call Filter Plus", from Verizon, similar tools exist for Verizon and AT&T), some are third-party. These of necessity share your voice/text activity with third parties, which is its own concern and consideration.
Full Android, iOS, and several full-featured Android alternatives (GrapheneOS, /e/OS, LineageOS, etc.) offer unknown caller rejection. Numbers not in your contact list are directed to voicemail. At present, few spam calls will leave voicemail, though some do, and as AI expands in capabilities, applications, and adoption this will all but certainly increase. I'd strongly encourage use of this.
Feature phones / dumbphones ... have far less capability. Most cannot even reject unknown numbers, which ... seems a ripe target for legislation and/or regulation. Phone frameworks such as AOSP / KaiOS seem to afford little capability for even creating a call-blocking app. This and other dumb devices (e.g., traditional landlines) are a strong argument for carrier/network level mitigations.
The company everyone loves to hate, Comcast/Xfinity, actually has one of the most sophisticated voice/text spam blocking systems, and one I'd like to see mandated to all carriers: <https://www.xfinity.com/support/articles/spam-blocker-overvi...>
It's risk based.
It classifies calls into three categories: high, medium, and low risk.
It adjudicates calls based on risk.
High-risk calls are terminated entirely.
Medium-risk calls are directed to voicemail.
Low-risk calls are subjected to an audio CAPTCHA (enter a two digit value to ring through), otherwise are directed to voicemail.
(It's not clear whether or not a whitelisted number will escape any treatment, perhaps subject to conditions such as originating from the appropriate/approved network for that call.)
I haven't used that system, but in advising people still moving off landlines, or looking at VOIP solutions, it's making Comcast an attractive option.
(I don't know what other VOIP providers, say, Twillo or Asterisk, offer, but suspect at least some have similar if not more-capable systems.)
________________________________
Notes:
1. California requires a $100,000 bond by all telemarketers in the state. The state has a small fraction of the incidence of robocalls of the worst US states. Several others have some bond. My view is that bonding should apply at the carrier level and be surrenderable to both contacted individuals and downstream peering networks, to provide both a strong financial penalty to abusers, and an incentive to downstream networks to pursue abusive calls.
Fuck everything about this. It's like your drug dealer running AA meetings.
Why are phones still so fucking far behind in the dark ages??
Instant messaging solved all this shit 700 years ago!
Let each number act as an "account" on the phone network/company, just like IM accounts, each with its list of contacts, and blocked numbers.
Shove incoming calls into "Strangers" with low-annoyance notifications (ringtones) by default unless they're from a "verified" company etc.
Oh and yeah as others said, a "Report Abuse" button.
Commerce should never have been made possible to happen on the internet. The moment it became possible to send and receive money through the internet, the end times began.
Hi - we're doing tree removal in your area. Call us back at 1-800-SCAM
Cheap messaging is as annoying now as calling. Ruining the phone experience overall. Soon Apple will have to do something.
I genuinely don't understand why this is so hard to tackle.
Phone numbers are a scare resource and the telecommunications networks heavily regulated with numerous central points of control.
This bullshit is scaling because the companies which gate and sell that access have no obligations, legal or otherwise, to deny scammers access to their resources.
I was under the impression that SHAKEN / STIR was supposed to do that by authenticating the phone numbers displayed against the telco that made the call. But as the other comment says, your telco earns money from scam calls and they don't want that to stop.
Identification is insufficient without accountability.
SHAKEN/STIR identifies whether or not a given number is originating from a specific network, but without knowing whether that's an approved network, rejecting unapproved-origin calls, or tracking how much unapproved traffic a given network is emitting and penalising it for this, the information isn't actionable.
"Measure it harder" doesn't solve problems. The information must direct meaningful action.
One word: incentives. You're absolutely right- and telecom networks get us on both sides. They collect fees from the scammers, then fees from customers to block the scammers. Can't get any better than that.
so penalties for telcos have to be higher than they earn from scam calls.
2-5% of scams succeed but penalty should be there accounting for 95-98% that did not succeed.
IANAL but I know failed attempt at robbery or murder is also prosecuted, failed attempts at scam are not, because people just hang up and move on. Then the reality is society doesn’t have enough resources to deal with "scam attempts" - well we have to focus on murder attempts an plain robbery
I think making noise is cheaper than reducing it.
And I think this is also a problem at the habit/behavior level for people. Most people don't want to know how to set proper boundaries with people and technology and articulate what they want. Once you do that at least you can articulate what you want to come in at you or not.
Without that you get stuck with a weird one-size-fits-all policy which definitely doesn't fit for me at least.