The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the call in question entered his own network from. The last cooperative network in the chain gets stuck with the fee, forcing them to either reclaim the money from the malicious customer, the next network in the chain (in court) or pony up the money themselves.
Result: All routes to non-cooperating networks get dropped within days to weeks and scam-calling stops being a lucrative business basically instantly.
dredmorbius 1 days ago [-]
That's pretty much the proposal I've made for some years.[1]
California has introduced bonding to telemarketing firms specifically. I feel that should apply at the carrier level, where networks carry a guaranteed bond, pay regular premiums on it, and are dinged for unwanted calls, with the proceeds being split among the called party and any third-party network(s) traversed by the calls. Downstream networks could seek compensation from ANY upstream network carrying the traffic regardless of whether or not they originated it.
This would both create a penalty for providing, or transiting, unsolicited calls, AND create an incentive for carriers / network providers themselves to pursue unsolicited traffic from their peers.
Do you really want the network to be so locked down you can't get access to it?
dredmorbius 17 hours ago [-]
How do you reach that conclusion based on what I've written?
inigyou 12 hours ago [-]
Because it happened to everything else where this idea was tried.
dredmorbius 4 hours ago [-]
In other words: nothing to do with what I'd written.
And no specific instances or mechanisms detailed, to boot.
Thanks.
inigyou 58 minutes ago [-]
The financial system. And the phone system in India.
bckr 1 days ago [-]
I think we have to do something this extreme. We have to give the system a total makeover. Somehow we also have to keep it from being fully centralized and have the big brother problem on the other side. Unfortunately these two goals are difficult to get through at the same time, with the system that we have.
giancarlostoro 1 days ago [-]
If major states like California and New York pass it, and spam basically dies in those states, it wouldn't surprise me if it spreads across the country.
pixl97 1 days ago [-]
Assuming the nature of the spam and how it makes money.
LorenPechtel 6 hours ago [-]
They are impossible.
You can't make a system that can force bad actors off the system that can't also be used to force politically undesirable actors off the system.
ssalka 1 days ago [-]
Cue the crypto bros touting their decentralized spam-detection blockchain
orbital-decay 1 days ago [-]
Infeasible. Fraud or spam is usually pretty hard to confirm from one recording without additional context. Many scammers have plausible deniability or are just checking whether the number is active. Moreover, this solution would involve secret non-consensual recording; what if it's not a scam?
ryandrake 1 days ago [-]
Plus, who is ‘confirming’ the spam? The same entity (or group: carriers) that is keeping the $10 and paying the $100 out? That just means the result will always be ‘not spam.’
dredmorbius 22 hours ago [-]
This is why fees should be structured such that all carriers are on the hook, but upstream carriers inherit the obligation, possibly with an increased liability per hop, implying that downstream carriers can utilise enforcement as a profit rather than cost centre.
Scenario:
- Spamford places an unsolicited call to subscriber Alice initiating from MalTelCo, transiting carrier hops BunnTel1 and BunnTel2, to Alice's telco carrier, EndTelCo.
- Carriers MalTelCo, BunnTel1, BunnTel2,[1] and EndTelCo have all placed surety bonds, held by BondCo, to practice telephony operations within the jurisdiction (regional/national). The carriers are the Principals, BondCo is the Surety, and receiving subscribers (or telcos, see below) are the Obligees.[2]
- Unbonded carriers may have their traffic refused by peers. Peering to an unbonded carrier places the bond obligation on the receiving carrier.
- Alice flags the call as spam. A per-call surety of $100 is paid to Alice, and charged to EndTelCo against its BondCo contract. As an additional option the call may be flagged as fraud through the phone system, in which case it is automatically referred to LEO by EndTelCo. Obligation of surety is independent of any fraud finding and is based SOLELY on the unsolicited nature of the call.
- EndTelCo has the option of 1) eating the charge or 2) filing a claim against its peer, BunnTel2, the 2nd hop in the chain, which EndTelCo does.
- BunnTel1 similarly files a claim on BunnTel2.
- BunnTel2 files a claim on MalTelCo.
- MalTelCo now eats the claim (it's paid out by BondCo). MalTelCo may seek further compensation from Spamford, but that's Out Of Scope of the bonding / surety schema, and would be covered by MalTelCo's own terms of use.
- BondCo assesses risks and adjusts its surety rates correspondingly based on observed behaviours (and financial risks) of EndTelCo, BunnTel1, BunnTel2, and MalTelCo. If risks are excessive and no surety can be issued, MalTelCo is unbonded, and hence, decertified. Peers may now refuse traffic without penalty.
Note that no one carrier needs to know anything more about a call's routing than its own network boundary. If EndTelCo has no idea that BunnTel2 and MalTelCo were involved, it doesn't matter, because BunnTel1 is on the hook for passing on the call. Spoofing or falsifying records doesn't save you.
There are some questions over how this might be implemented, though generally:
- If Spamford and Alice are both subscribers to EndTelCo, then EndTelCo eats the surety, which is paid to Alice. There's no upstream. Moral: Telcos, don't spam your own customers.
- One thought is that the surety is split among telcos and the subscriber. Rather than just facing a potential cost, transiting and reciving-end-point carriers could see revenue by tracking and prosecuting unsolicited calls. This could include calls received by monitoring numbers set up strictly to assess unsolicited call activity directed to the network. This would mean that calls transiting multiple carriers would be subject to compounded surety claims ... and ... I think I'm OK with that.
- There would all but certainly be classes of calls which would be exempted from claims. Those should be very limited, preferably to government and specifically qualified emergency services only. No political exemptions, no non-profit / NGO exemptions.
- How often claims are settled and risks re-assessed is open for discussion. Daily might be too often, weekly or monthly seems most likely. Longer than that gives too much free-run for malevolent actors to operate.
I'd make one significant change to the proposal in the comment.
The delivery penalty applies to any unsolicited email, as determined by the recipient.
If also tagged as scam, those are further forwarded to law enforcement (state, national) for investigation.
Many US states are one-party regarding recording. Even in two-party states (CA, OR, WA, MT, IL, PA, MA, CT, NH, MD, DE, FL), disclosed recording and continuing a call will generally be construed as consent. If that's not the case, proposed state or national legislation could carve out exceptions as needed, and there'll likely need to be some legislation required anyway, so that's part of the process.
But shifting the fee element from fraud (one class of unsolicited call/text abuse) to undesired contact makes sorting when the fee applies far more evident, and eliminates a class of other objections (e.g., due process) from consideration.
inigyou 22 hours ago [-]
I sign up for a newsletter from Google, then I report it as unsolicited. Boom, I just made Google pay me $10.
dredmorbius 17 hours ago [-]
That's a familiar complaint from the world of email, where it's usually applied to mailing lists.
If I were to steelman the concern, I'd look at a few related scenarios, say, where a subscriber is running a poorly-secured VOIP system and spammers hijack that to make calls. I'll ... get to that.
First: the scenario here is phone systems, not email, so the traffic would be voice calls, possibly texts. That said, I'll consider your question as if it was calls and not newsletters.
I've given a more detailed breakdown of how I see a bonding system working here, you might want to read it before continuing with this comment: <https://news.ycombinator.com/item?id=49129679>.
Second: It's not subscribers who are on the hook for spam calls, but carriers. So Google isn't paying you, your carrier is paying you (via a Surety agent), with the option of recouping that penalty from an upstream carrier, if any. If you and Google are on the same carrier, and the call didn't transit any other networks, it's just you and your own telephony service provider (carrier).
A carrier might have its own TOU/TOS with its subscribers, and subscribers originating calls could and likely would attempt to recover abuse costs if they were incurred. That subscriber (say, Google) might also have its own TOU/TOS addressing the case of mis-reporting of authorised contacts. Those actions would be outside the bonding system itself. A party repeatedly abusing the system could be liable for other actions, including fraud or malicious damages.
Note that one of the interesting elements of bonding is that call origination becomes a risky activity for telcos. Presently, telcos are eager to enter such business, put few restrictions or obligations on their customers, and to prefer outbound traffic to inbound traffic. Under a bonding programme, this changes dramatically. Large-volume outbound traffic is a liability, where it does occur, it needs to be closely monitored and managed. Our poorly-secured VOIP system mentioned earlier would probably be subject to configuration/operation validation, pen testing, close monitoring for activity, and alerts/throttling if unexpected usage patterns emerge. All of this is now in the carrier's interest.
Third: The bonding scheme would be periodically settled among carriers. I've hand-waved how often this would occur, though somewhere between daily and monthly, with a shorter term more likely (malicious actors often shoot-and-scoot, we want to avoid that). So low-level skirmish actions such as you describe would tend to result in a net wash between carriers: claims on one would be balanced by claims on others.
Fourth: Just how Google came to communicate, what it's communicating, and the degree to which it's coercing, say, receipt of sales/marketing messages vs. strictly advisory messages tied to a service ... would probably have to be considered in a larger context, but would still be outside the bonding system itself.
- New relationships might be permitted through a contact request. This itself could be mediated by a known third party. Private individuals for personal contacts, commercial or governmental trusted parties in other cases. Effectively it's the social-introduction problem from before the age of mass communications brought forward. Such systems will have some friction (necessary to defeat spammers), but not so much friction that the system as a whole doesn't work.
- Bonding does not require strong KYC for small accounts. That is, the person wanting to buy a mobile phone and service anonymously could, but their device and service would be monitored for abuse. I expect a tiered system to emerge, with individuals, small, mid-sized, and large accounts, with increased controls and obligations proceeding with scale and/or capability.
- Generally, it's not individual accounts which are responsible for large volumes of outbound calls, absent an issue such as a proxy hijacking. Large outbound volumes will tend to be associated with known call- or data-centres, and can be managed as such.
- The goal is preservation of a general-availability, universally-accessible phone system. That works only if it is not systematically abused, which is presently the case. If trust in public-switched telephone networks, permitting direct-dial access to any other number, anywhere in the world, is lost, what we'll see is desertion to other options which serve specific individuals' and organisations' interest. We are already beginning to see this, though no one clear winner has emerged. Unfortunately, most of the alternatives are proprietary, though some federated networks might prove to be viable alternatives.
inigyou 12 hours ago [-]
So I just sign up for $60, collect a bunch of calls and then report them all a spam, earning me a guaranteed $1000 from the phone company?
dredmorbius 7 hours ago [-]
Please see my second point above, particularly the 2nd 'graph.
If you're acting fraudulently and at scale, there will likely be consequences.
If this happens occasionally, it's a feature of the system, and your reports effectively become a super-opt-out.
And if perhaps the problem does become sufficiently widespread, I'd be interested in seeing how you'd address it given one constraint: operating within the bonding/surety system I've suggested. And that the State of California and others have already enacted in some form.
Viliam1234 23 hours ago [-]
> Many scammers have plausible deniability
The scammers who call me are perfectly obvious.
First, they tell me the company they are from (almost certainly a fake one -- could be easy to verify). Then they try to convince me that two years ago I have created an account on their website, they gave me some free money that was managed by an AI, and now I have a ton of money, and they need to send it to me (a completely bullshit story). Then they tell me that in order to get that money, I need to install a software, that I know happens to be a remote control software (no legitimate financial institution would ever do that).
There is no way to make this plausibly deniable. Especially the part about the need to install the remote control software... which is the entire point of the operation.
bluefirebrand 20 hours ago [-]
> Moreover, this solution would involve secret non-consensual recording
In Canada at least, only one party has to consent to the recording
If you record your own phone calls that's not remotely illegal. Nor is it in my opinion unethical
Maskawanian 20 hours ago [-]
Almost, as someone who used to work with telecom systems in Canada, while it is true that felony wiretapping requires 1 party to consent to not be illegal, it is not the only law. PIPEDA applies to only commercial endeavors, and requires two party consent.
This is why a company must inform you of the recording, but you do not have to inform them.
bluefirebrand 19 hours ago [-]
I didn't know that, thanks for clarifying
Still, as an individual wanting to record scam callers, you're in the clear to record calls that you are a part of
LorenPechtel 6 hours ago [-]
That's where I stand, also. You're a party to the conversation, it's not something that would implicitly be expected to be private (thus no bedroom recordings etc), it should be legal to record. I can see no justification for prohibiting it.
verall 1 days ago [-]
A lot of scams unfortunately operate right on the line of legality like the car warranty morons
cj 1 days ago [-]
Sure, but that's okay because you don't need 100% of spam calls to be recognized as spam for the incentive to do its job. The system still sounds like it could still work even if a large percent of calls weren't flagged.
orbital-decay 1 days ago [-]
This works both ways, if the detection rate is low then nobody would press a "lose $10" button.
flatline 1 days ago [-]
Unscrupulous operators will just run up huge liabilities and close up shop by the time they can be identified and dragged into court, meanwhile having started another similar operation under a different name. That's basically already what's happening, and the speed differential between the technology and the law will be forever in their favor.
dredmorbius 6 hours ago [-]
Which is why bonding is applied, as with other high-risk ventures.
The bonding agent (the Surety) sets the bond rate based on the perceived risk of the venture.
Unbonded ventures are not permitted to operate. In a telco context, unbonded carriers would not be peered to other carriers.
The idea is that telecoms would be on the hook for these folks' behavior; they'd be incentivized to scrutinize them more thoroughly.
edoceo 1 days ago [-]
How are they listening to a few minutes before the button? A "temporary" recording of the first 2 minutes of every call? I feel like there would be some privacy concerns.
namibj 1 days ago [-]
It'd suffice for them to sign the transmitted information (audio and required timing metadata for the packet stream) and make you do the temporary recording on your side, transmitting it back to the provider once you hit the button, to let them handle the backup/safekeeping aspects for you.
LorenPechtel 5 hours ago [-]
Recording into the recent past is quite common. You implement it by storing the data *to memory only* until the trigger event happens, then you write out what's currently in memory.
It's a common feature in better dashcams--you get say the 30 seconds before the thump that triggered it. Likewise, many high speed cameras that record some short action. They're actually always running, but dumping the end of the data, they only "record" when the trigger happens.
RobRivera 21 hours ago [-]
Oddly specific with the dollar ounts, but I like the general idea.
dmitrygr 1 days ago [-]
Simpler yet: require every call to come with a physical source address, huge (and enforced) jail times for faking it. Let the internet and the pissed callees crowdsource the rest
hutattedonmyarm 1 days ago [-]
This would be an enormous invasion of privacy. Other countries have a lot less issues with spam calls without these measures
inigyou 22 hours ago [-]
Other countries have this rule, actually. At least most of Europe records your passport and address.
amazingamazing 1 days ago [-]
I don’t understand how this works. Suppose someone calls you about some political poll and you hit the button, would it count or not? What about a cold email (there was another such thread about cold emails being praised, i said fundamentally is spam but was downvoted lol).
pessimizer 1 days ago [-]
I spent a little time unsuccessfully looking for a reference, but in some ancient Greek and early Roman governments, newly elected officials who were in charge of money were required to personally indemnify (become responsible for the professional liabilities of) their predecessor.
If your predecessor committed fraud, you were 100% personally responsible for it. You would then gather the evidence and sue your predecessor for your losses.
Luc 1 days ago [-]
That sounds like a great way to attract scammers and dissuade honest people, so if it's ever been tried it must have failed spectacularly (I also searched for variations of this idea but didn't turn up anything).
bluGill 1 days ago [-]
It probably worked for Romans because the taxes you were allowed to collect was so much more than you had to send back to Rome that you could get rich 'honestly'. That and you had options to prove the fraud that meant the other was unlikely to try.
giancarlostoro 1 days ago [-]
How does your predecessor today have those funds? The problem is politicians get to "play" with wealth beyond their own reaches (typically).
otterpro 1 days ago [-]
I no longer can answer my phone. I get at least 20-40 spam/scam calls per day, and many are legitimate companies calling for loans and refinancing offers, which started after I got a home loan. I cannot seem to stop them from calling, and even though my phone number is listed in National Do Not Call Registry for many years, it hasn't worked at all. The only relief is that on my iPhone, I was able to block all calls not found in my contacts (ie whitelist phone numbers only).
Now, my only worry is that I might get a call from someone who I need to talk to, but is blocked and I won't even know it. For example, what if I get an emergency call from police/fire/hospital and I won't even know it. I also tried using "Screen unknown caller" feature, but then, no one likes them and sometimes they think it is AI bot and they usually just hang up (which is great for spam caller but not for legitimate caller)
My only solution that I could think of is to have a dedicated phone line just for friends/family/work, and a second line for banking/shopping/utilities/everything else.
xethos 1 days ago [-]
> My only solution that I could think of is to have a dedicated phone line just for friends/family/work, and a second line for banking/shopping/utilities/everything else.
This fails the moment one of your "clean line" contacts downloads a sketchy app that sells all their contacts, and sells an updated list as your appear in their recent calls list - meaning it's not a one-time thing, it's for a few weeks after every time you call them.
Leif24 1 days ago [-]
It works if you only allow incoming calls from your contacts (e.g. whitelisted numbers) on friends/family/work line. If that number leaks, who cares? The random numbers will be blocked anyway. Probably would want to set it up so the 'public' line is silenced - just periodically check the VM box for anything important.
pixl97 1 days ago [-]
It seems possible, but maybe not affordable, for scammers to buy information about you and then spoof numbers of places that could/should theoretically call you. If you couple this with the potential victims on the other end being elderly you've greatly increased the risks of the attack being successful.
xethos 20 hours ago [-]
But then you're right back where you started: When you need a clean number for a hospital or similarly important service to call (Wife's work, daycare, school office), it goes to the distrusted, silent-by-default line, or, just as bad, it doesn't ring the clean, only-whitelsisted-numbers-ring line
giancarlostoro 1 days ago [-]
> I also tried using "Screen unknown caller" feature, but then, no one likes them and sometimes they think it is AI bot and they usually just hang up (which is great for spam caller but not for legitimate caller)
When its someone legit I find that they actually go through the effort. I've had USPS explain who they were to my phone and I was able to answer them as a result.
ozim 1 days ago [-]
I get the comfort that "normal person" would send an SMS "it was me Greg, call me back" if you don't pick up and most of my family is on whatsapp anyway.
Scammers or spammers will never send an SMS with clarification that they wanted to call you.
pavel_lishin 1 days ago [-]
But a normal person could be calling from a doctor's office, a hospital, or your child's school - and not an actual cellphone, and they may not want to text you (or not be allowed to text you) from their personal cellphone, either.
As a parent, the "block all numbers!" approach has always seemed incredibly naive to me.
swat535 1 days ago [-]
Those will usually leave a voice mail if it's important. Then you can call the place back and discuss it. If they don't bother to leave a voice mail, then it's not urgent / important.
dredmorbius 20 hours ago [-]
Doctors' offices, hospitals, and schools are well aware of this problem because they're dealing with both the outgoing and incoming elements of it. Many hospitals no longer permit direct calls to inpatient rooms because of the spam and fraud rates. Outbound communications are similarly frustrated, and are driving use of online and app-based contact methods (with ... their own issues).
Other organisations, institutions, and businesses too. HN discussion tends to focus on the consumer side of this, it's what most commenters have most familiarity with themselves, but you'd better believe that pretty much the entire phone customer base is fed up to there on this. Which puts the entire network at risk of defection, a risk that telcos have been talking publicly about for over a decade now:
[S]ince mid-2015, a consortium of engineers from phone carriers and others in the telecom industry have worked on a way to [stop call-spoofing], worried that spam phone calls could eventually endanger the whole system. “We’re getting to the point where nobody trusts the phone network,” says Jim McEachern, principal technologist at the Alliance for Telecommunications Industry Solutions (ATIS.) “When they stop trusting the phone network, they stop using it.”
Jim is a good guy and ATIS tried real hard with STIR/SHAKEN, but technology cannot overcome the commercial incentives that carriers have to let this nonsense continue. I've written about this before too [0].
Your follow-up, here (<https://news.ycombinator.com/item?id=48938169>), was particularly insightful, and has influenced my thinking. Essentially: authentication / validation should happen out of band with phone number itself, for the reasons you've given.
I do suspect that for routing authentication, header-level signifiers should be reasonably useful, but for strong identity or authority attestation, they're not. That's ... a deeper problem, but also one which can be solved independently.
Oh, and I'd love to see that Dallas Morning News AT&T CEO interview story, if you could find it.
Yeah. A few months ago my wife and I had a miscommunication that ended up with her one place without her phone and me waiting for her in a different place. Completely unknown number, but since it didn't come up as suspected spam I answered it.
SoftTalker 1 days ago [-]
Same as GP. I silence unknown callers, and unknown text messages. They can leave a voicemail, and I might check it at some point. I check unknown texts a little more often, but they don't interrupt me with an alert which is the important thing.
No police/fire/hospital emergency outcome is going to hinge upon someone else answering a phone call or text messsage.
Maskawanian 19 hours ago [-]
What I did was implement a SIP number that asks for a random digit to be pressed before allowing the call through. It also connects to my CardDAV server, and any numbers in my address book don't get the prompt. This works for 95% of bogus calls. The only thing this stops is people not on my address book calling from hands-free. But this has never come up in conversation so I think I'm OK!
kevin_thibedeau 1 days ago [-]
The fix is a Google Voice number that you replace every few years. Keep your permanent number guarded for critical services only.
gbourne1 1 days ago [-]
I too set it up so all unknown calls go to VM. I figure if legit they will leave a message. If two calls and no message I block the unknown number.
Marsymars 1 days ago [-]
Roughly 100% of my spam calls come from spoofed numbers and don't repeat, so I never bother blocking anything.
dredmorbius 20 hours ago [-]
There's a technical hack available here as well.
Some carriers offer blocking all unknown calls from specified area codes. On Verizon that is "Neighborhood Filter", part of their "Call Filter" toolkit:
The way it's meant to be used is that the subscriber would block their own area code, and perhaps co-located overlays or neighbouring area codes. The limit for now is ten area codes.
Known or explicitly approved numbers are passed through.
The additional hack is that it's possible to request a number in any arbitrary area code, and spam and robocall rates vary tremendously across area codes. They're generally worst across the Deep South / Southeast (TX, OK, AR, AL, MS, TN, GA, SC, NC), and lowest in Alaska, Utah, Massachussetts, Washington, and North Dakota.
Pick a low-spam, low-population state, request a number from one of its area codes (if not its one area code ;-), and then block all but known numbers from that area code.
radicality 5 hours ago [-]
Ha, for a brief moment I thought VM=virtual machine and not voice mail and was scratching my head how you set that up and what the VM is doing with the call
bckr 1 days ago [-]
Right but what keeps the second line clean? You’re going to get spam there too.
coldpie 23 hours ago [-]
> The only relief is that on my iPhone, I was able to block all calls not found in my contacts (ie whitelist phone numbers only).
It is insane that Android still does not have this option. It has to be some kind of software patent horseshit preventing them from adding the feature.
Hikikomori 1 days ago [-]
Live in Europe, last time I got a spam call 4-5 years ago it was my ISP asking of I wanted to add tv to my internet. Told them not to call me again and they didn't.
victorbjorklund 1 days ago [-]
I live in Europe and I get scam calls and sales calls. Yes, legit companies spam call less in Europe due to regulation but scammers committing crimes don’t care about privacy laws etc it’s their least problems
inigyou 22 hours ago [-]
From European numbers? Someone had to scan their passport to get that number. The police can check.
Hikikomori 1 days ago [-]
Dont get those either, maybe just an outlier but GF don't get them either.
hutattedonmyarm 1 days ago [-]
I get them maybe 3-4 times a year. So, not _never_ but not a big problem either
victorbjorklund 1 days ago [-]
You are lucky. I been on a financial scam list for the last 18 years. They call maybe twice per year. Almost interesting to see over time what scams are trendy.
22 hours ago [-]
stavros 1 days ago [-]
I live in Europe and I get spam calls from the US :(
mannanj 1 days ago [-]
[dead]
orev 1 days ago [-]
One of the biggest concerns I have with phone scams is that the people most vulnerable are the elderly, and they don’t have the knowledge on how to block these calls (if a technical solution is the only option).
And further to that, the elderly are also the ones who cannot block unknown numbers, because doctors’ offices seem to have random numbers they call you from (they may have a pool of numbers but it’s not reasonable to add all of them to contacts). Blocking all unknowns would block these important health related calls as well.
thewebguyd 1 days ago [-]
> because doctors’ offices seem to have random numbers they call you from
This is a huge issue with scam/security awareness education. Too many legitimate orgs use the exact behaviors we tell people to avoid. Same thing with email, can't tell someone to never click links in emails when services keep relying on magic links, third-party notification domains, etc. SPF, DKIM, and DMARC do nothing because scammers will just typosquat.
In the phone number example, most of those numbers too are unlisted outbound numbers, you couldn't even google them to verify.
Half the battle is getting legitimate organizations to stop acting like scammers in the first place so that shady behavior becomes an obvious red flag again.
bugcheck7b 1 days ago [-]
Just this week I got an email from Amex to be on the lookout for scams, and the email itself had a "login" button right in the top.
LarsAlereon 21 hours ago [-]
I work in this industry, and a big issue is that a major customer of the cheapest, shadiest telcos is the US federal government. Because they're "being responsible with your tax money." So cracking down on them will affect government calls and quickly generate too much pushback. "I don't care how scammy Bill's Discount No-Questions-Asked VoIP LLC is, the army uses them!"
dredmorbius 20 hours ago [-]
Got any references on this?
Which telcos?
olyjohn 1 days ago [-]
And if you think spam calls on your cell phone are bad... oh boy, land lines get about 10x the calls. My theory is that because it's mostly older people who have land lines on top of the fact that spam laws are tighter for cell phones. There aren't enough land line users to complain, so not a big enough voice to make a public outcry. Cell phone users have no idea the problems that land lines have.
I know this because I had to spend 6 months taking care of my dad while he was dying. We had so many medical people calling us and making appointments, and doing tests, etc etc. And on top of it about 10-15 spam calls a day and it's impossible to differentiate via caller ID. This was all while I was also working full time from home. It's a real hellscape, and these phone scammers are really having a negative effect on people's lives. It made my life miserable at one of the hardest times of my life, and I have nothing but contempt for these fuckers, and no empathy left for the people making the phone calls either. They're all scumbags and deserve time in prison.
kjellsbells 19 hours ago [-]
In rural America, the major telcos choose not to help, and that is a big factor here. You can't do stir/shaken crypto attestation of calls over TDM, but the big guys refuse to sell SIP trunks to rural operators.
see [1] for more on why stir/shaken hasnt helped as much as it ought to.
It being a major concern doesn't mean there's any solution around said concerns. Give me 100 old peoples phone numbers and I bet I could convince 10 of them that I am AARP trying to make them safe and eventually get money out of them.
LorenPechtel 5 hours ago [-]
Yup. My doc's appointment reminders come from some service in another state. It's a pool of numbers, sometimes they come up as suspected spam. I suspect the dodgy guys deliberately offer very good rates for things like this so people won't block them.
bickfordb 1 days ago [-]
Maybe this is a pipe dream, but wouldn't it be better to retire the legacy phone voice and messaging system altogether.
If 99.9% of us have internet phones, why aren't we using PKI, decentralized protocols, crowd sourced reputation to communicate instead of POTS phone numbers, SMS/iChat and relying on the carriers to police spam.
dredmorbius 6 hours ago [-]
The traditional (POTS-based, circuit-switched, fully-analogue system) has largely been retired. Even where existing POTS twisted-pair service exists, it's generally VOIP until the last few hundred metres, if that.
In much of the US, the push is on to retire the last twisted pair within a very few years, if not months. Utilisation rates are well into the single-digits and falling, which makes continued support quite expensive.
The problem for many holdouts is that alternatives fail to deliver reliability, or the equivalent of a site-centred service (as opposed to personal mobile devices). Residential VOIP is confusing from the subscriber's perspective, and the telcos aren't making choosing options much easier.
SMS itself is highly problematic, as it's grossly insecure, unreliable, and very subject to surveillance and other abuse. Secure chat alternatives tend to be proprietary (e.g., RCS, effectively specific to Apple and Google, see: <https://en.wikipedia.org/wiki/Rich_Communication_Services>), or aren't supported on all devices (Signal would be excellent, but isn't supported on most Feature Phone / Dumbphone OSes, such as KaiOS/AOSP). And Signal too is ultimately a single provider.
tacocataco 24 hours ago [-]
Redundancy in case of natural disasters.
timoth3y 22 hours ago [-]
This is actually an easily solvable problem. In fact, most of the world has already solved it by not allowing caller-ID spoofing and by blocking bad actors similar to the way that ISPs block email coming from known bad IPs.
The US has the STIR/SHAKEN authentication protocols, but the telcos seem to have no financial are regulatory pressure to clamp down on all the sketchy intermediate carriers the scammers use to bypass them.
Rather then actually solve the problem, the US prefers to turn it into a business opportunity with the telcos selling subscriptions to blocking software and an entire ecosystem of moderately effective apps.
TimBurman 6 hours ago [-]
I've been using the Android app SpamBlocker off F-Droid for several years to block unwanted calls and SMS. It blocks entire area codes, individual numbers, names and any pattern using regular expressions. It can silence, pickup and hangup or just send to VM. The developer has a github page and has provided many updates. https://f-droid.org/en/packages/spam.blocker/
dredmorbius 6 hours ago [-]
This rehashes much of the experience fighting email spam in the late 1990s / early aughts.
Initially the approach was a long list of rules, usually a whitelist and blacklist of known good and bad contacts, and then a large set of specific patterns and assigned weights. Procmail was an early standard here, later Spamassassin.
The biggest revolution came with Bayesian classification. YCombinator's Paul Graham (@pg) developed one such system. The idea here was that a small set of mail was classified into two categories, spam (unwanted) and ham (wanted), and the classifier went looking for patterns within each corpus, automatically assigning weights. This took much of the guesswork and assumptions out of the process, but still relied on contextual clues within the mail itself, though both data (the message payload) and metadata (email headers) could be used.
Following that were reputation-based systems, generally looking at domains or IP address space, where a sufficiently large-scale survey of mail patterns, initially based on honeypots, later largely conducted by large email providers themselves such as AOL, Yahoo, Hotmail, (this was the aughts, they still existed), and eventually Gmail and a few others. Senderbase/Ironport (later bought by Cisco) were another major contender here. These approaches strongly leveraged power-law relations, in which a small number of origins (IPs, CIDR blocks, ASNs) account for the vast majority of email spam. Generally: poor network hygiene practices, whether intentional or otherwise, show, and are actionable by peers / others.
Google especially, through Gmail, had access to a phenomenal amount of activity, and could detect both datacenter-based bulk mailing activity and residential proxy campaigns. Effectively its Gmail service serves as a huge, distributed, collection observatory, and can respond to new spam campaigns incredibly quickly. I don't have specific insights, but suspect that response times are measured in minutes if not seconds.
Google of course also has insight to the contents of emails, but network- and header-level adjudication is much faster, cheaper, and surprisingly effective.
This is why I'm strongly advocating carrier-based, network-level phone-spam mitigations, and whatever regulatory changes are necessary to incentivise providers to adopt these. On-device apps are fine, so far as they go, but would best work in concert with network-level countermeasures.
sdenton4 1 days ago [-]
I got an obviously-AI voice agent spam call yesterday. Had a bit of fun getting it to answer trivia questions (when was the treaty of westphalia ratified? answer in a rhyming couplet) as a precondition to handing over the keys to my bank accounts.
nojs 1 days ago [-]
Perhaps the future of captcha is anti-captcha. What agent can resist responding with a rhyming couplet or inverting a binary tree?
ozim 1 days ago [-]
Downside is they most likely are using stolen tokens, not paying themselves so it cost them next to nothing.
pixl97 1 days ago [-]
Regardless, this forces them to steal more tokens. Any token wasted not getting money reduces the efficiency of the scam. The end goal would be increasing the token expenditure above the amount they scam from people.
dpkirchner 7 hours ago [-]
And recording your voice for fine tuning models they could then use to trick your friends/family/banks.
f1ay 1 days ago [-]
dontscamgrandma.com is probably apropos to share here for the elderly / vulnerable affected by scam proliferation. It's a trainer that roleplays people through getting the confidence to hang up and call their loved ones back.
Full disclosure I'm the founder, and I've got a couple dogs in this fight
dredmorbius 1 days ago [-]
An ask: I'm trying to find out where substantive discussion by carriers AND other parties on mitigating phone spam (voice or text) is occurring. I'd very much appreciate replies here, email (see my profile), or hop on this Fediverse thread: <https://toot.cat/@dredmorbius/116984051310517623>
Broadband Breakfast does seem to be one of those entities. ATIS (<https://atis.org/>) is another, though as a telco alliance I consider it highly suss.
(Submitter.)
ogou 23 hours ago [-]
My Google Voice number got 37 calls from the same region in the past 2 days. All day, about every 50 minutes, rotating different 404 based numbers. It happens about twice a year from this area code (404). I know exactly where it is from. I had to park in Atlanta once and it required me to create an account on an app for that parking lot to pay. Of course I used my Google number. That service must have transferred or sold my number. Now my account gets bombed by them on a regular basis.
SoftTalker 1 days ago [-]
Is this a USA problem, or world-wide? If other countries don't have such a problem, why not?
dredmorbius 16 hours ago [-]
It seems to be much worse in the US for now, though why is the subject of a great deal of speculation.
There's not much publicly-available research on the topic. One better source I've found is "Robocalls: A Worldwide or US-only Problem? Analyzing Spam and Fraud in International Phone Calls" (30 Jun 2026)
Even though robocalls are an international problem, our findings indicate that US citizens are substantially more affected than the rest of the world. The median number of phone numbers in our US honeypot was 11 751, compared to 101 913 international phone numbers. Despite an almost tenfold difference in the number of available phone lines, the US honeypot numbers received 8 314 813 calls (95.1%) compared to 432 538 calls (4.9%) received by the international numbers. On average, a single phone number in our US honeypot received 707.5 calls during a nine-month period, about 2.62 calls per day. Non-US numbers received, on average 4.24 calls during the same period, about 0.016 calls per day.
The paper does not break out calls per person by country, though it discusses general patterns.
Hiya has an accessible report which highlights "seven key countries", with calls per month in parenthesis: The US (22), UK (5), Canada (6), Spain (13), France (18), Germany (3), and Brazil (29, highest in the world).
Americas: Brazil (29), Mexico (26), Chile (23), and the US (22) lead.
In Asia: HK (23), Indonesia (16), the Philippines (12), and India (8) lead.
Worldwide. It doesn't affect everyone equally though so some in each county are not having a problem while others are swamped with garbage.
alightsoul 22 hours ago [-]
Because the US market is very lucrative. In other countries they aren't calls, they're WhatsApp messages just asking for money. Sometimes they somehow hack into people's WhatsApp accounts and then ask their friends for money.
nicbou 23 hours ago [-]
I get spam calls in Germany, but it's maybe two dozen a year in random bursts.
inigyou 22 hours ago [-]
Pervasive KYC.
inigyou 22 hours ago [-]
This must be why every country is locking down the phone network. KYC or you don't get connected. You get a spam call? Good, caller ID is authenticated so it's easy for the police to find out who called you.
stalfosknight 1 days ago [-]
T-Mobile’s Scam Shield works really well for me. But you have to get the premium tier.
ipython 1 days ago [-]
Funny, the same telecoms that whine about how hard this traffic is to stop... are also selling a "premium" service to customers- who then manually tag unwanted calls so that the telecom can sell that data back to other customers...
dredmorbius 1 days ago [-]
Unsurprisingly: telcos sell outbound dialing capabilities to business customers.
For spam mitigations to work, the cost of selling that business must exceed its revenue.
Some, and I won't mention AT&T by name, are very curiously opposed to any regulations touching this.
dhosek 1 days ago [-]
I don’t seem to be charged for Scam Shield on my account. I’ve had one unknown number call and not leave a message over the last month, which is a far cry from the 20–40 spam calls per day some people report.
The free tier seems to identify but not block likely scam calls. T-Mobile's website skews sales-heavy, and doesn't feature much technical information.
The premium features appear to be app-dependent, and may not work on feature phones.
dredmorbius 1 days ago [-]
There are a number of options. My view is that carrier-based filtering (rather than on-device filters) are where effort must be focused. Much as we learned with email: if you're routing traffic for many people, mass-contact attempts and patterns become quickly visible. Individuals see only a minuscule fraction of traffic, networks see overall patterns.
The other element is that carriers can act at the network level, noting how much abusive traffic arrives from given peers, and taking direct action against those peers. That could involve rejecting traffic outright, subjecting it to stronger challenges, and/or diverting it to investigative / law-enforcement bodies (I'd suggest both national and state entities) for both tracking and enforcement. Power-law relations mean that at any given time, a small number of networks will account for the overwhelming majority of spam, though which networks will likely change over time.
The key problem with this is getting the carriers to act, which ... will probably involve a few carrots and sticks. I'll address those in another comment, except to mention bonding: <https://oag.ca.gov/consumers/general/telreg>.[1]
Individual action will not solve this problem, but there are steps you can take.
Most major US carriers now offer some form of robocall blocking. "Scam Shield" from T-Mobile, "ActiveArmor" from AT&T, "Call Filter" from Verizon.
MVNOs (mobile virtual network operators) may or may not offer scam / robocall blocking themselves (though IMO they should, and should be required to). Some will identify spam calls, but those are still passed through to your handset.
Beyond this, there are on-device apps which can be used, some are carrier-based (e.g., "Call Filter Plus", from Verizon, similar tools exist for Verizon and AT&T), some are third-party. These of necessity share your voice/text activity with third parties, which is its own concern and consideration.
Full Android, iOS, and several full-featured Android alternatives (GrapheneOS, /e/OS, LineageOS, etc.) offer unknown caller rejection. Numbers not in your contact list are directed to voicemail. At present, few spam calls will leave voicemail, though some do, and as AI expands in capabilities, applications, and adoption this will all but certainly increase. I'd strongly encourage use of this.
Feature phones / dumbphones ... have far less capability. Most cannot even reject unknown numbers, which ... seems a ripe target for legislation and/or regulation. Phone frameworks such as AOSP / KaiOS seem to afford little capability for even creating a call-blocking app. This and other dumb devices (e.g., traditional landlines) are a strong argument for carrier/network level mitigations.
It classifies calls into three categories: high, medium, and low risk.
It adjudicates calls based on risk.
High-risk calls are terminated entirely.
Medium-risk calls are directed to voicemail.
Low-risk calls are subjected to an audio CAPTCHA (enter a two digit value to ring through), otherwise are directed to voicemail.
(It's not clear whether or not a whitelisted number will escape any treatment, perhaps subject to conditions such as originating from the appropriate/approved network for that call.)
I haven't used that system, but in advising people still moving off landlines, or looking at VOIP solutions, it's making Comcast an attractive option.
(I don't know what other VOIP providers, say, Twillo or Asterisk, offer, but suspect at least some have similar if not more-capable systems.)
________________________________
Notes:
1. California requires a $100,000 bond by all telemarketers in the state. The state has a small fraction of the incidence of robocalls of the worst US states. Several others have some bond. My view is that bonding should apply at the carrier level and be surrenderable to both contacted individuals and downstream peering networks, to provide both a strong financial penalty to abusers, and an incentive to downstream networks to pursue abusive calls.
olyjohn 1 days ago [-]
Fuck everything about this. It's like your drug dealer running AA meetings.
stalfosknight 1 days ago [-]
It is indeed rather fucked but I’d rather spend $4 a month to have scam calls be a rarity than the alternative…
alex1138 1 days ago [-]
I get messages (and often don't answer my phone; my ringer is off) in which it's obviously this automated thing but they immediately dock it down to "press 1 if..."
'Kay. So you call people and just clearly have a tone the second you hear a voice which could well be someone's answering machine
(Of course most of it would be automated, I guess)
Special place in hell for these people
cindyllm 1 days ago [-]
[dead]
shadowtree 1 days ago [-]
Hi - we're doing tree removal in your area. Call us back at 1-800-SCAM
Cheap messaging is as annoying now as calling. Ruining the phone experience overall. Soon Apple will have to do something.
LocalH 1 days ago [-]
Commerce should never have been made possible to happen on the internet. The moment it became possible to send and receive money through the internet, the end times began.
dredmorbius 17 hours ago [-]
Or phones, or telegraph, or mail, or roads, or ...
Commerce and crime go hand-in-hand.
The Greek and Roman gods of travel and communication were also the gods of tricksters (frauds) and thieves. The etymology of "Mercury" may be related to that of "merchant". (Hermes rather less so.)
Allow list for phone numbers. All else goes to VM. Job done.
Razengan 1 days ago [-]
Why are phones still so fucking far behind in the dark ages??
Instant messaging solved all this shit 700 years ago!
Let each number act as an "account" on the phone network/company, just like IM accounts, each with its list of contacts, and blocked numbers.
Shove incoming calls into "Strangers" with low-annoyance notifications (ringtones) by default unless they're from a "verified" company etc.
Oh and yeah as others said, a "Report Abuse" button.
etchalon 1 days ago [-]
I genuinely don't understand why this is so hard to tackle.
Phone numbers are a scare resource and the telecommunications networks heavily regulated with numerous central points of control.
This bullshit is scaling because the companies which gate and sell that access have no obligations, legal or otherwise, to deny scammers access to their resources.
ipython 1 days ago [-]
One word: incentives. You're absolutely right- and telecom networks get us on both sides. They collect fees from the scammers, then fees from customers to block the scammers. Can't get any better than that.
ozim 1 days ago [-]
so penalties for telcos have to be higher than they earn from scam calls.
2-5% of scams succeed but penalty should be there accounting for 95-98% that did not succeed.
IANAL but I know failed attempt at robbery or murder is also prosecuted, failed attempts at scam are not, because people just hang up and move on. Then the reality is society doesn’t have enough resources to deal with "scam attempts" - well we have to focus on murder attempts an plain robbery
inigyou 22 hours ago [-]
I don't think we want telcos to block scam calls themselves. We want them to be forced to give the subscriber's actual address to the police.
dredmorbius 17 hours ago [-]
Why not?
And why would you impose a highly-intrusive personal-tracking system across billions of subscribers?
inigyou 12 hours ago [-]
Because I don't want some stupid AI system to randomly decide I'm a spam caller.
And you know every other country has full KYC for phone connections, right?
dredmorbius 7 hours ago [-]
What would be a sufficient appeals process or remedy action that might address your concern?
What activities are you engaged in which make you think you'd likely be considered a spammer? What specific harms do you see occurring? Might these be related to your present line of business / profession / employment?
inigyou 6 hours ago [-]
Sure, if someone gave me a false phone number to call them on, I could be declared a spammer. If I had to call more than 3 people a day ordinarily, I could be declared a spammer. I'm basing these on what already happens in the banking sector as a direct result of the regulation you want.
dredmorbius 4 hours ago [-]
What would be a sufficient appeals process or remedy action that might address your concern?
What activities are you engaged in which make you think you'd likely be considered a spammer? What specific harms do you see occurring? Might these be related to your present line of business / profession / employment?
inigyou 60 minutes ago [-]
You have just copy-pasted your previous comment. That is a form of spam, and I'm flagging it as such.
etchalon 16 hours ago [-]
They don't to block scam calls. They can easily limit who gets access to make them, making the resource itself precious enough no one would risk wasting it on a dial scam.
mook 1 days ago [-]
I was under the impression that SHAKEN / STIR was supposed to do that by authenticating the phone numbers displayed against the telco that made the call. But as the other comment says, your telco earns money from scam calls and they don't want that to stop.
dredmorbius 1 days ago [-]
Identification is insufficient without accountability.
SHAKEN/STIR identifies whether or not a given number is originating from a specific network, but without knowing whether that's an approved network, rejecting unapproved-origin calls, or tracking how much unapproved traffic a given network is emitting and penalising it for this, the information isn't actionable.
"Measure it harder" doesn't solve problems. The information must direct meaningful action.
inigyou 22 hours ago [-]
SHAKEN/STIR has a loophole for calls passing through legacy trunks that don't support it. So now certain carriers made a business model off of routing your scam calls through those trunks so they won't have to be verified.
dredmorbius 17 hours ago [-]
Which is why we turn originating / sourcing / routing calls into a risk. See:
There's a related issue apparently of small operators who can't afford (or haven't been bothered) to implement STIR/SHAKEN. Many of these are apparently small rural phone co-ops (its own interesting bit of telecoms history). There should be both support in providing them with such capabilities, and penalties for failing to do so, including liability for transiting spam calls to their own or other carriers' subscribers.
inigyou 12 hours ago [-]
Well then phone companies will stop originating/routing/sourcing calls. Do you want that? Your idea has been implemented for banks already, and the result is that machine learning algorithms randomly block transactions and close people's accounts for no reason.
dredmorbius 7 hours ago [-]
Telcos will stop originating high-risk calls.
Where there's legitimate business, and the risks are low (including the overwhelming majority of personal / residential lines, as well as most business / institutional lines), there's absolutely no problem.
The key is getting incentives right. Indexing bonding and payouts to the spam level, and having a target, is one way to approach this.
The problem with cheap comms, or cheap anything, is that it makes low-return, high-volume activities viable, including especially those which externalise costs and internalise benefits. Such as, say, fraud or spam generally.
What my proposal does is internalise those costs to spammer and telcos which facilitate them, by raising effort (most bulk calls are blocked) and shifting the financial incentives. From participating in the fight against spam for the past 30 years I've a pretty good notion that this will work. And unlike email, the phone system already has a costing and payment system built in.
With single spam operations generating hundreds of millions to billions of calls monthly and barely achieving profitability, I'm pretty sure we can knock things back a lot without inconveniencing legitimate players.
inigyou 6 hours ago [-]
Banks have this rule and it's terrible. My proposed alternative: if someone spams you, get them arrested.
dredmorbius 6 hours ago [-]
Please walk through just how you'd accomplish this, at scale, in a system with many chain-of-authentication holes, spanning international jurisdictions.
Please walk through as well, what the privacy, surveillance, data-disclosure, third-party bad-actor, and authoritarian-government risks of such a system would be.
inigyou 6 hours ago [-]
Exactly the same as it already works in most countries
And I think this is also a problem at the habit/behavior level for people. Most people don't want to know how to set proper boundaries with people and technology and articulate what they want. Once you do that at least you can articulate what you want to come in at you or not.
Without that you get stuck with a weird one-size-fits-all policy which definitely doesn't fit for me at least.
Rendered at 21:05:28 GMT+0000 (Coordinated Universal Time) with Vercel.
Result: All routes to non-cooperating networks get dropped within days to weeks and scam-calling stops being a lucrative business basically instantly.
California has introduced bonding to telemarketing firms specifically. I feel that should apply at the carrier level, where networks carry a guaranteed bond, pay regular premiums on it, and are dinged for unwanted calls, with the proceeds being split among the called party and any third-party network(s) traversed by the calls. Downstream networks could seek compensation from ANY upstream network carrying the traffic regardless of whether or not they originated it.
This would both create a penalty for providing, or transiting, unsolicited calls, AND create an incentive for carriers / network providers themselves to pursue unsolicited traffic from their peers.
<https://oag.ca.gov/consumers/general/telreg>
________________________________
Notes:
1. See for example <https://toot.cat/@dredmorbius/111099306069523624>
And no specific instances or mechanisms detailed, to boot.
Thanks.
You can't make a system that can force bad actors off the system that can't also be used to force politically undesirable actors off the system.
Scenario:
- Spamford places an unsolicited call to subscriber Alice initiating from MalTelCo, transiting carrier hops BunnTel1 and BunnTel2, to Alice's telco carrier, EndTelCo.
- Carriers MalTelCo, BunnTel1, BunnTel2,[1] and EndTelCo have all placed surety bonds, held by BondCo, to practice telephony operations within the jurisdiction (regional/national). The carriers are the Principals, BondCo is the Surety, and receiving subscribers (or telcos, see below) are the Obligees.[2]
- Unbonded carriers may have their traffic refused by peers. Peering to an unbonded carrier places the bond obligation on the receiving carrier.
- Alice flags the call as spam. A per-call surety of $100 is paid to Alice, and charged to EndTelCo against its BondCo contract. As an additional option the call may be flagged as fraud through the phone system, in which case it is automatically referred to LEO by EndTelCo. Obligation of surety is independent of any fraud finding and is based SOLELY on the unsolicited nature of the call.
- EndTelCo has the option of 1) eating the charge or 2) filing a claim against its peer, BunnTel2, the 2nd hop in the chain, which EndTelCo does.
- BunnTel1 similarly files a claim on BunnTel2.
- BunnTel2 files a claim on MalTelCo.
- MalTelCo now eats the claim (it's paid out by BondCo). MalTelCo may seek further compensation from Spamford, but that's Out Of Scope of the bonding / surety schema, and would be covered by MalTelCo's own terms of use.
- BondCo assesses risks and adjusts its surety rates correspondingly based on observed behaviours (and financial risks) of EndTelCo, BunnTel1, BunnTel2, and MalTelCo. If risks are excessive and no surety can be issued, MalTelCo is unbonded, and hence, decertified. Peers may now refuse traffic without penalty.
Note that no one carrier needs to know anything more about a call's routing than its own network boundary. If EndTelCo has no idea that BunnTel2 and MalTelCo were involved, it doesn't matter, because BunnTel1 is on the hook for passing on the call. Spoofing or falsifying records doesn't save you.
There are some questions over how this might be implemented, though generally:
- If Spamford and Alice are both subscribers to EndTelCo, then EndTelCo eats the surety, which is paid to Alice. There's no upstream. Moral: Telcos, don't spam your own customers.
- One thought is that the surety is split among telcos and the subscriber. Rather than just facing a potential cost, transiting and reciving-end-point carriers could see revenue by tracking and prosecuting unsolicited calls. This could include calls received by monitoring numbers set up strictly to assess unsolicited call activity directed to the network. This would mean that calls transiting multiple carriers would be subject to compounded surety claims ... and ... I think I'm OK with that.
- There would all but certainly be classes of calls which would be exempted from claims. Those should be very limited, preferably to government and specifically qualified emergency services only. No political exemptions, no non-profit / NGO exemptions.
- How often claims are settled and risks re-assessed is open for discussion. Daily might be too often, weekly or monthly seems most likely. Longer than that gives too much free-run for malevolent actors to operate.
________________________________
Notes:
1. "BunnTel", because bunnies hop.
2. For an overview of surety bonds, see <https://www.suretybondsdirect.com/educate/what-is-surety-bon...>.
The delivery penalty applies to any unsolicited email, as determined by the recipient.
If also tagged as scam, those are further forwarded to law enforcement (state, national) for investigation.
Many US states are one-party regarding recording. Even in two-party states (CA, OR, WA, MT, IL, PA, MA, CT, NH, MD, DE, FL), disclosed recording and continuing a call will generally be construed as consent. If that's not the case, proposed state or national legislation could carve out exceptions as needed, and there'll likely need to be some legislation required anyway, so that's part of the process.
But shifting the fee element from fraud (one class of unsolicited call/text abuse) to undesired contact makes sorting when the fee applies far more evident, and eliminates a class of other objections (e.g., due process) from consideration.
If I were to steelman the concern, I'd look at a few related scenarios, say, where a subscriber is running a poorly-secured VOIP system and spammers hijack that to make calls. I'll ... get to that.
First: the scenario here is phone systems, not email, so the traffic would be voice calls, possibly texts. That said, I'll consider your question as if it was calls and not newsletters.
I've given a more detailed breakdown of how I see a bonding system working here, you might want to read it before continuing with this comment: <https://news.ycombinator.com/item?id=49129679>.
Second: It's not subscribers who are on the hook for spam calls, but carriers. So Google isn't paying you, your carrier is paying you (via a Surety agent), with the option of recouping that penalty from an upstream carrier, if any. If you and Google are on the same carrier, and the call didn't transit any other networks, it's just you and your own telephony service provider (carrier).
A carrier might have its own TOU/TOS with its subscribers, and subscribers originating calls could and likely would attempt to recover abuse costs if they were incurred. That subscriber (say, Google) might also have its own TOU/TOS addressing the case of mis-reporting of authorised contacts. Those actions would be outside the bonding system itself. A party repeatedly abusing the system could be liable for other actions, including fraud or malicious damages.
Note that one of the interesting elements of bonding is that call origination becomes a risky activity for telcos. Presently, telcos are eager to enter such business, put few restrictions or obligations on their customers, and to prefer outbound traffic to inbound traffic. Under a bonding programme, this changes dramatically. Large-volume outbound traffic is a liability, where it does occur, it needs to be closely monitored and managed. Our poorly-secured VOIP system mentioned earlier would probably be subject to configuration/operation validation, pen testing, close monitoring for activity, and alerts/throttling if unexpected usage patterns emerge. All of this is now in the carrier's interest.
Third: The bonding scheme would be periodically settled among carriers. I've hand-waved how often this would occur, though somewhere between daily and monthly, with a shorter term more likely (malicious actors often shoot-and-scoot, we want to avoid that). So low-level skirmish actions such as you describe would tend to result in a net wash between carriers: claims on one would be balanced by claims on others.
Fourth: Just how Google came to communicate, what it's communicating, and the degree to which it's coercing, say, receipt of sales/marketing messages vs. strictly advisory messages tied to a service ... would probably have to be considered in a larger context, but would still be outside the bonding system itself.
Fifth: There's a model for how surety bonds and claims work in the State of California's syste. For a breakdown of that see: <https://www.jwsuretybonds.com/states/california/telemarketin...>.
A few other points:
- New relationships might be permitted through a contact request. This itself could be mediated by a known third party. Private individuals for personal contacts, commercial or governmental trusted parties in other cases. Effectively it's the social-introduction problem from before the age of mass communications brought forward. Such systems will have some friction (necessary to defeat spammers), but not so much friction that the system as a whole doesn't work.
- Bonding does not require strong KYC for small accounts. That is, the person wanting to buy a mobile phone and service anonymously could, but their device and service would be monitored for abuse. I expect a tiered system to emerge, with individuals, small, mid-sized, and large accounts, with increased controls and obligations proceeding with scale and/or capability.
- Generally, it's not individual accounts which are responsible for large volumes of outbound calls, absent an issue such as a proxy hijacking. Large outbound volumes will tend to be associated with known call- or data-centres, and can be managed as such.
- The goal is preservation of a general-availability, universally-accessible phone system. That works only if it is not systematically abused, which is presently the case. If trust in public-switched telephone networks, permitting direct-dial access to any other number, anywhere in the world, is lost, what we'll see is desertion to other options which serve specific individuals' and organisations' interest. We are already beginning to see this, though no one clear winner has emerged. Unfortunately, most of the alternatives are proprietary, though some federated networks might prove to be viable alternatives.
If you're acting fraudulently and at scale, there will likely be consequences.
If this happens occasionally, it's a feature of the system, and your reports effectively become a super-opt-out.
And if perhaps the problem does become sufficiently widespread, I'd be interested in seeing how you'd address it given one constraint: operating within the bonding/surety system I've suggested. And that the State of California and others have already enacted in some form.
The scammers who call me are perfectly obvious.
First, they tell me the company they are from (almost certainly a fake one -- could be easy to verify). Then they try to convince me that two years ago I have created an account on their website, they gave me some free money that was managed by an AI, and now I have a ton of money, and they need to send it to me (a completely bullshit story). Then they tell me that in order to get that money, I need to install a software, that I know happens to be a remote control software (no legitimate financial institution would ever do that).
There is no way to make this plausibly deniable. Especially the part about the need to install the remote control software... which is the entire point of the operation.
In Canada at least, only one party has to consent to the recording
If you record your own phone calls that's not remotely illegal. Nor is it in my opinion unethical
This is why a company must inform you of the recording, but you do not have to inform them.
Still, as an individual wanting to record scam callers, you're in the clear to record calls that you are a part of
The bonding agent (the Surety) sets the bond rate based on the perceived risk of the venture.
Unbonded ventures are not permitted to operate. In a telco context, unbonded carriers would not be peered to other carriers.
Overview of how surety bonds work: <https://www.suretybondsdirect.com/educate/what-is-surety-bon...>.
California's present regulation: <https://oag.ca.gov/consumers/general/telreg>
It's a common feature in better dashcams--you get say the 30 seconds before the thump that triggered it. Likewise, many high speed cameras that record some short action. They're actually always running, but dumping the end of the data, they only "record" when the trigger happens.
If your predecessor committed fraud, you were 100% personally responsible for it. You would then gather the evidence and sue your predecessor for your losses.
Now, my only worry is that I might get a call from someone who I need to talk to, but is blocked and I won't even know it. For example, what if I get an emergency call from police/fire/hospital and I won't even know it. I also tried using "Screen unknown caller" feature, but then, no one likes them and sometimes they think it is AI bot and they usually just hang up (which is great for spam caller but not for legitimate caller)
My only solution that I could think of is to have a dedicated phone line just for friends/family/work, and a second line for banking/shopping/utilities/everything else.
This fails the moment one of your "clean line" contacts downloads a sketchy app that sells all their contacts, and sells an updated list as your appear in their recent calls list - meaning it's not a one-time thing, it's for a few weeks after every time you call them.
When its someone legit I find that they actually go through the effort. I've had USPS explain who they were to my phone and I was able to answer them as a result.
Scammers or spammers will never send an SMS with clarification that they wanted to call you.
As a parent, the "block all numbers!" approach has always seemed incredibly naive to me.
Other organisations, institutions, and businesses too. HN discussion tends to focus on the consumer side of this, it's what most commenters have most familiarity with themselves, but you'd better believe that pretty much the entire phone customer base is fed up to there on this. Which puts the entire network at risk of defection, a risk that telcos have been talking publicly about for over a decade now:
[S]ince mid-2015, a consortium of engineers from phone carriers and others in the telecom industry have worked on a way to [stop call-spoofing], worried that spam phone calls could eventually endanger the whole system. “We’re getting to the point where nobody trusts the phone network,” says Jim McEachern, principal technologist at the Alliance for Telecommunications Industry Solutions (ATIS.) “When they stop trusting the phone network, they stop using it.”
<https://nymag.com/intelligencer/2018/05/how-to-stop-spam-rob...>
I've mentioned this on HN a few times: <https://news.ycombinator.com/item?id=21494300> <https://news.ycombinator.com/item?id=21542926> <https://news.ycombinator.com/item?id=28756827> <https://news.ycombinator.com/item?id=29003329> <https://news.ycombinator.com/item?id=31939562>.
Broadband Breakfast just addressed the issue as well in this Fediverse toot, calling out not just schools (subject of the legislation) but other affected entities: <https://mastodon.social/@BroadbandBreakfast/1169990755811584...>.
[0] https://news.ycombinator.com/item?id=48920432#48928781
Your follow-up, here (<https://news.ycombinator.com/item?id=48938169>), was particularly insightful, and has influenced my thinking. Essentially: authentication / validation should happen out of band with phone number itself, for the reasons you've given.
I do suspect that for routing authentication, header-level signifiers should be reasonably useful, but for strong identity or authority attestation, they're not. That's ... a deeper problem, but also one which can be solved independently.
Oh, and I'd love to see that Dallas Morning News AT&T CEO interview story, if you could find it.
Would this be it?
"Watchdog Memo to AT&T's CEO: Didn't mean to get you in trouble", by Dave Lieber (July 8, 2016) <https://www.dallasnews.com/news/watchdog/2016/07/08/watchdog...>
No police/fire/hospital emergency outcome is going to hinge upon someone else answering a phone call or text messsage.
Some carriers offer blocking all unknown calls from specified area codes. On Verizon that is "Neighborhood Filter", part of their "Call Filter" toolkit:
<https://www.verizon.com/support/knowledge-base-238154/>
<https://www.pcmag.com/news/verizons-neighborhood-filter-bloc...>
The way it's meant to be used is that the subscriber would block their own area code, and perhaps co-located overlays or neighbouring area codes. The limit for now is ten area codes.
Known or explicitly approved numbers are passed through.
The additional hack is that it's possible to request a number in any arbitrary area code, and spam and robocall rates vary tremendously across area codes. They're generally worst across the Deep South / Southeast (TX, OK, AR, AL, MS, TN, GA, SC, NC), and lowest in Alaska, Utah, Massachussetts, Washington, and North Dakota.
See:
"The Robocall Epidemic: Which states are hit hardest by spam calls?" (10 March 2026) <https://www.whistleout.com/CellPhones/Guides/robocall-epidem...>
"The Robocall Geography Tax: Why Your ZIP Code Determines Your Spam Reality" (23 October 2025) <https://www.karmacall.com/blog/southeast-spam-call-geography...>
I'd submitted the latter a few days ago: <https://news.ycombinator.com/item?id=49082473>.
Pick a low-spam, low-population state, request a number from one of its area codes (if not its one area code ;-), and then block all but known numbers from that area code.
It is insane that Android still does not have this option. It has to be some kind of software patent horseshit preventing them from adding the feature.
And further to that, the elderly are also the ones who cannot block unknown numbers, because doctors’ offices seem to have random numbers they call you from (they may have a pool of numbers but it’s not reasonable to add all of them to contacts). Blocking all unknowns would block these important health related calls as well.
This is a huge issue with scam/security awareness education. Too many legitimate orgs use the exact behaviors we tell people to avoid. Same thing with email, can't tell someone to never click links in emails when services keep relying on magic links, third-party notification domains, etc. SPF, DKIM, and DMARC do nothing because scammers will just typosquat.
In the phone number example, most of those numbers too are unlisted outbound numbers, you couldn't even google them to verify.
Half the battle is getting legitimate organizations to stop acting like scammers in the first place so that shady behavior becomes an obvious red flag again.
Which telcos?
I know this because I had to spend 6 months taking care of my dad while he was dying. We had so many medical people calling us and making appointments, and doing tests, etc etc. And on top of it about 10-15 spam calls a day and it's impossible to differentiate via caller ID. This was all while I was also working full time from home. It's a real hellscape, and these phone scammers are really having a negative effect on people's lives. It made my life miserable at one of the hardest times of my life, and I have nothing but contempt for these fuckers, and no empathy left for the people making the phone calls either. They're all scumbags and deserve time in prison.
see [1] for more on why stir/shaken hasnt helped as much as it ought to.
[1] https://news.ycombinator.com/item?id=48920432#48928781
________________________________
Notes:
1. Incidentally, the first and second largest-circulation magazines in the US now: <https://www.magazineline.com/blog/most-popular-magazines-in-...>.
If 99.9% of us have internet phones, why aren't we using PKI, decentralized protocols, crowd sourced reputation to communicate instead of POTS phone numbers, SMS/iChat and relying on the carriers to police spam.
In much of the US, the push is on to retire the last twisted pair within a very few years, if not months. Utilisation rates are well into the single-digits and falling, which makes continued support quite expensive.
The problem for many holdouts is that alternatives fail to deliver reliability, or the equivalent of a site-centred service (as opposed to personal mobile devices). Residential VOIP is confusing from the subscriber's perspective, and the telcos aren't making choosing options much easier.
SMS itself is highly problematic, as it's grossly insecure, unreliable, and very subject to surveillance and other abuse. Secure chat alternatives tend to be proprietary (e.g., RCS, effectively specific to Apple and Google, see: <https://en.wikipedia.org/wiki/Rich_Communication_Services>), or aren't supported on all devices (Signal would be excellent, but isn't supported on most Feature Phone / Dumbphone OSes, such as KaiOS/AOSP). And Signal too is ultimately a single provider.
The US has the STIR/SHAKEN authentication protocols, but the telcos seem to have no financial are regulatory pressure to clamp down on all the sketchy intermediate carriers the scammers use to bypass them.
Rather then actually solve the problem, the US prefers to turn it into a business opportunity with the telcos selling subscriptions to blocking software and an entire ecosystem of moderately effective apps.
Initially the approach was a long list of rules, usually a whitelist and blacklist of known good and bad contacts, and then a large set of specific patterns and assigned weights. Procmail was an early standard here, later Spamassassin.
The biggest revolution came with Bayesian classification. YCombinator's Paul Graham (@pg) developed one such system. The idea here was that a small set of mail was classified into two categories, spam (unwanted) and ham (wanted), and the classifier went looking for patterns within each corpus, automatically assigning weights. This took much of the guesswork and assumptions out of the process, but still relied on contextual clues within the mail itself, though both data (the message payload) and metadata (email headers) could be used.
Following that were reputation-based systems, generally looking at domains or IP address space, where a sufficiently large-scale survey of mail patterns, initially based on honeypots, later largely conducted by large email providers themselves such as AOL, Yahoo, Hotmail, (this was the aughts, they still existed), and eventually Gmail and a few others. Senderbase/Ironport (later bought by Cisco) were another major contender here. These approaches strongly leveraged power-law relations, in which a small number of origins (IPs, CIDR blocks, ASNs) account for the vast majority of email spam. Generally: poor network hygiene practices, whether intentional or otherwise, show, and are actionable by peers / others.
Google especially, through Gmail, had access to a phenomenal amount of activity, and could detect both datacenter-based bulk mailing activity and residential proxy campaigns. Effectively its Gmail service serves as a huge, distributed, collection observatory, and can respond to new spam campaigns incredibly quickly. I don't have specific insights, but suspect that response times are measured in minutes if not seconds.
Google of course also has insight to the contents of emails, but network- and header-level adjudication is much faster, cheaper, and surprisingly effective.
This is why I'm strongly advocating carrier-based, network-level phone-spam mitigations, and whatever regulatory changes are necessary to incentivise providers to adopt these. On-device apps are fine, so far as they go, but would best work in concert with network-level countermeasures.
Full disclosure I'm the founder, and I've got a couple dogs in this fight
Broadband Breakfast does seem to be one of those entities. ATIS (<https://atis.org/>) is another, though as a telco alliance I consider it highly suss.
(Submitter.)
There's not much publicly-available research on the topic. One better source I've found is "Robocalls: A Worldwide or US-only Problem? Analyzing Spam and Fraud in International Phone Calls" (30 Jun 2026)
<https://arxiv.org/html/2606.31790>
On the magnitude in the US vs. elsewhere:
Even though robocalls are an international problem, our findings indicate that US citizens are substantially more affected than the rest of the world. The median number of phone numbers in our US honeypot was 11 751, compared to 101 913 international phone numbers. Despite an almost tenfold difference in the number of available phone lines, the US honeypot numbers received 8 314 813 calls (95.1%) compared to 432 538 calls (4.9%) received by the international numbers. On average, a single phone number in our US honeypot received 707.5 calls during a nine-month period, about 2.62 calls per day. Non-US numbers received, on average 4.24 calls during the same period, about 0.016 calls per day.
The paper does not break out calls per person by country, though it discusses general patterns.
Hiya has an accessible report which highlights "seven key countries", with calls per month in parenthesis: The US (22), UK (5), Canada (6), Spain (13), France (18), Germany (3), and Brazil (29, highest in the world).
Americas: Brazil (29), Mexico (26), Chile (23), and the US (22) lead.
In Asia: HK (23), Indonesia (16), the Philippines (12), and India (8) lead.
<https://work.hiya.com/hubfs/2025/Global%20Call%20Threat%20Re...>
For spam mitigations to work, the cost of selling that business must exceed its revenue.
Some, and I won't mention AT&T by name, are very curiously opposed to any regulations touching this.
<https://www.t-mobile.com/benefits/scam-shield>
The free tier seems to identify but not block likely scam calls. T-Mobile's website skews sales-heavy, and doesn't feature much technical information.
The premium features appear to be app-dependent, and may not work on feature phones.
The other element is that carriers can act at the network level, noting how much abusive traffic arrives from given peers, and taking direct action against those peers. That could involve rejecting traffic outright, subjecting it to stronger challenges, and/or diverting it to investigative / law-enforcement bodies (I'd suggest both national and state entities) for both tracking and enforcement. Power-law relations mean that at any given time, a small number of networks will account for the overwhelming majority of spam, though which networks will likely change over time.
The key problem with this is getting the carriers to act, which ... will probably involve a few carrots and sticks. I'll address those in another comment, except to mention bonding: <https://oag.ca.gov/consumers/general/telreg>.[1]
Individual action will not solve this problem, but there are steps you can take.
Most major US carriers now offer some form of robocall blocking. "Scam Shield" from T-Mobile, "ActiveArmor" from AT&T, "Call Filter" from Verizon.
MVNOs (mobile virtual network operators) may or may not offer scam / robocall blocking themselves (though IMO they should, and should be required to). Some will identify spam calls, but those are still passed through to your handset.
Beyond this, there are on-device apps which can be used, some are carrier-based (e.g., "Call Filter Plus", from Verizon, similar tools exist for Verizon and AT&T), some are third-party. These of necessity share your voice/text activity with third parties, which is its own concern and consideration.
Full Android, iOS, and several full-featured Android alternatives (GrapheneOS, /e/OS, LineageOS, etc.) offer unknown caller rejection. Numbers not in your contact list are directed to voicemail. At present, few spam calls will leave voicemail, though some do, and as AI expands in capabilities, applications, and adoption this will all but certainly increase. I'd strongly encourage use of this.
Feature phones / dumbphones ... have far less capability. Most cannot even reject unknown numbers, which ... seems a ripe target for legislation and/or regulation. Phone frameworks such as AOSP / KaiOS seem to afford little capability for even creating a call-blocking app. This and other dumb devices (e.g., traditional landlines) are a strong argument for carrier/network level mitigations.
The company everyone loves to hate, Comcast/Xfinity, actually has one of the most sophisticated voice/text spam blocking systems, and one I'd like to see mandated to all carriers: <https://www.xfinity.com/support/articles/spam-blocker-overvi...>
It's risk based.
It classifies calls into three categories: high, medium, and low risk.
It adjudicates calls based on risk.
High-risk calls are terminated entirely.
Medium-risk calls are directed to voicemail.
Low-risk calls are subjected to an audio CAPTCHA (enter a two digit value to ring through), otherwise are directed to voicemail.
(It's not clear whether or not a whitelisted number will escape any treatment, perhaps subject to conditions such as originating from the appropriate/approved network for that call.)
I haven't used that system, but in advising people still moving off landlines, or looking at VOIP solutions, it's making Comcast an attractive option.
(I don't know what other VOIP providers, say, Twillo or Asterisk, offer, but suspect at least some have similar if not more-capable systems.)
________________________________
Notes:
1. California requires a $100,000 bond by all telemarketers in the state. The state has a small fraction of the incidence of robocalls of the worst US states. Several others have some bond. My view is that bonding should apply at the carrier level and be surrenderable to both contacted individuals and downstream peering networks, to provide both a strong financial penalty to abusers, and an incentive to downstream networks to pursue abusive calls.
'Kay. So you call people and just clearly have a tone the second you hear a voice which could well be someone's answering machine
(Of course most of it would be automated, I guess)
Special place in hell for these people
Cheap messaging is as annoying now as calling. Ruining the phone experience overall. Soon Apple will have to do something.
Commerce and crime go hand-in-hand.
The Greek and Roman gods of travel and communication were also the gods of tricksters (frauds) and thieves. The etymology of "Mercury" may be related to that of "merchant". (Hermes rather less so.)
<https://en.wikipedia.org/wiki/Mercury_(mythology)>
Instant messaging solved all this shit 700 years ago!
Let each number act as an "account" on the phone network/company, just like IM accounts, each with its list of contacts, and blocked numbers.
Shove incoming calls into "Strangers" with low-annoyance notifications (ringtones) by default unless they're from a "verified" company etc.
Oh and yeah as others said, a "Report Abuse" button.
Phone numbers are a scare resource and the telecommunications networks heavily regulated with numerous central points of control.
This bullshit is scaling because the companies which gate and sell that access have no obligations, legal or otherwise, to deny scammers access to their resources.
2-5% of scams succeed but penalty should be there accounting for 95-98% that did not succeed.
IANAL but I know failed attempt at robbery or murder is also prosecuted, failed attempts at scam are not, because people just hang up and move on. Then the reality is society doesn’t have enough resources to deal with "scam attempts" - well we have to focus on murder attempts an plain robbery
And why would you impose a highly-intrusive personal-tracking system across billions of subscribers?
And you know every other country has full KYC for phone connections, right?
What activities are you engaged in which make you think you'd likely be considered a spammer? What specific harms do you see occurring? Might these be related to your present line of business / profession / employment?
What activities are you engaged in which make you think you'd likely be considered a spammer? What specific harms do you see occurring? Might these be related to your present line of business / profession / employment?
SHAKEN/STIR identifies whether or not a given number is originating from a specific network, but without knowing whether that's an approved network, rejecting unapproved-origin calls, or tracking how much unapproved traffic a given network is emitting and penalising it for this, the information isn't actionable.
"Measure it harder" doesn't solve problems. The information must direct meaningful action.
<https://news.ycombinator.com/item?id=49130932>
There's a related issue apparently of small operators who can't afford (or haven't been bothered) to implement STIR/SHAKEN. Many of these are apparently small rural phone co-ops (its own interesting bit of telecoms history). There should be both support in providing them with such capabilities, and penalties for failing to do so, including liability for transiting spam calls to their own or other carriers' subscribers.
Where there's legitimate business, and the risks are low (including the overwhelming majority of personal / residential lines, as well as most business / institutional lines), there's absolutely no problem.
The key is getting incentives right. Indexing bonding and payouts to the spam level, and having a target, is one way to approach this.
The problem with cheap comms, or cheap anything, is that it makes low-return, high-volume activities viable, including especially those which externalise costs and internalise benefits. Such as, say, fraud or spam generally.
What my proposal does is internalise those costs to spammer and telcos which facilitate them, by raising effort (most bulk calls are blocked) and shifting the financial incentives. From participating in the fight against spam for the past 30 years I've a pretty good notion that this will work. And unlike email, the phone system already has a costing and payment system built in.
With single spam operations generating hundreds of millions to billions of calls monthly and barely achieving profitability, I'm pretty sure we can knock things back a lot without inconveniencing legitimate players.
Please walk through as well, what the privacy, surveillance, data-disclosure, third-party bad-actor, and authoritarian-government risks of such a system would be.
And I think this is also a problem at the habit/behavior level for people. Most people don't want to know how to set proper boundaries with people and technology and articulate what they want. Once you do that at least you can articulate what you want to come in at you or not.
Without that you get stuck with a weird one-size-fits-all policy which definitely doesn't fit for me at least.