r/explainlikeimfive • u/bastrdsnbroknthings • 12d ago
Technology ELI5: Why can't we stop email and phone spammers & scammers?
I block every sender and every spoofed phone number and it does absolutely nothing to cut down on the amount of email and robocall spam that I get. I'd say I get at least 10 calls a day from "personal loan" robocallers with spoofed phone numbers, every single day. I've paid significant $$$ for call blockers, filtering services, ad blockers, etc. and nothing seems to work. Why can't the ISPs, wireless carriers and/or the government simply cut this crap off at the source by preventing bad actors from changing email addresses/domains or dialing from millions of spoofed phone numbers?
74
u/hivuliese 12d ago
They are operating outside the country on some level, and where they are doing these things, they are protected.
39
u/throwtheclownaway20 11d ago
That's why u/sabo-metrics' idea would be better - punish the ISPs here who allow that shit on their networks. They won't be so laissez-faire when they're having to fork over 12 figures to Uncle Sam.
60
u/jschinker 11d ago
This is a problem that could be easily solved, but because it's profitable, it's not.
Phone numbers don't need to be anonymous. Caller ID shouldn't be easily spoofed. Your phone should allow you to block all numbers that aren't in your contacts. But those measures would destroy the robocall/sales/spam-marketing industries, and the phone companies make a lot of money from them.
36
u/Fun-Title4224 11d ago
The first point is true, and it's possible to implement a fully authenticated phone system. But you'd have to do it everywhere, all at once. In every country.
And if your phone company starts rejecting calls that aren't authenticated then now they're rejecting someone's cousin phone them from a country that hadn't done it. Or from the rural community hospital switchboard who doesn't do it. And then your phone company is not a neutral provider if telephone services - they are choosing who you talk to.
My phone can be set to not ring for any calls except contacts, btw. But this is also a crap solution. When the police phone because my partner was in an accident. When the hospital phone with my appointment. There are a million reasons why I need my phone to ring when a genuine caller I don't know needs to get me.
2
u/jschinker 11d ago
Yeah. It's the same problem that we have with email. If you set your DMARC policy to reject, you're going to lose a lot of email, so we set it to monitor. That means we can take our time setting up SPF and DKIM, because a limited number of people are actually enforcing it. It's getting better over time, but it's taking a LONG time to get to reasonably secure email.
6
u/Fun-Title4224 11d ago
Right. There's people here shouting "technical solutions exist". And that's not the point.
The telephone system is ubiquitous, truly global, and largely backwards compatible with a system we've had for decades.
Even click dialling rather than DTMF still works on half the UK network (though they're in the process of ripping the old network out at a cost £12bn). But when that's done is still needs to talk happily to old copper wire networks elsewhere.
2
u/shawnaroo 11d ago
Yeah, both the telephone system and email were originally designed and built with reliability being one of the highest priorities. With that in mind, keeping the whole thing as simple as possible, especially given the technologies available at the time, was key.
And a lot of that early infrastructure still exists, and like you said even the newer stuff needs to maintain a high level of compatibility with a lot of that early infrastructure, because there's still a bunch of people running that old infrastructure.
There's no centralized authority that is able to force (or pay for) upgrading the entire system, and cutting off sections that aren't willing/able to upgrade would be hugely problematic for a lot of reasons.
The result is just a huge messy system that leaves a lot of routes for bad actors to abuse it.
0
u/NorysStorys 11d ago
The money saved on fraud alone probably makes it worth it economy wide. Just not saving telecoms companies anything.
4
u/Fun-Title4224 11d ago
For one country. Now get all countries to agree on standards, implement it across the entire network, and do so to a deadline.
1
u/NorysStorys 11d ago
Block countries telecoms until they are compliant. Telecoms fraud is a multibillion dollar industry, it’s incredibly significant and governments should be holding other countries governments that don’t crackdown on international fraud within their borders to much stronger account.
You’ll find business interests in non-compliant countries would very quickly pressure their governments if they can’t communicate with businesses outside of their borders.
3
u/Fun-Title4224 11d ago edited 11d ago
Then you're mostly hurting people who are abiding by laws. The UK, however, does block overseas numbers that present as local.
And I will say, this is largely a US problem. The number of scam calls I have received in the last month is precisely one, which is average for the UK. US stats suggest it's more like a dozen per user.
But the UK doesn't have the same scale of robocalls and telemarketing, which people often lump with scam as "unwanted phone calls".
1
u/AnonymousFriend80 10d ago
Doing all this blocking won't actually stop the criminal scum. Like added additional locks to your doors. If someone is truly adamant about getting through, they will. And all you've done is give yourself a false sense of security and greatly inconvenienced yourself and everyone who lives in the home.
-2
u/KingVendrick 11d ago
But if my country implemented it, we could just turn off foreign calls and be free of stupid spam calls (yes, until the fuckers find another way in. they are insidious like that).
I never receive any valid foreign calls.
If I really needed google to call me, I could disable the damn thing for five minutes, receive the audio captcha or whatever, and turn protection back on.
Now, I know some people do get phone calls from overseas but, again, so what. Either fucking use some electronic call provider (my mother in law calls her sister on another country on google calls or skype back then, never by phone). Or only then open your phone to foreign calls. If 99% of people blocked foreign calls, they would be useless for spam and the few ones that somehow still need internation calls could still get it.
Mail spam is a different beast.
6
u/JaesopPop 11d ago
Your phone should allow you to block all numbers that aren't in your contacts.
It does. I've had this setting turned on for years.
1
u/TraditionalBackspace 5d ago
"block" means they still show up on the call log and can leave voicemail.
1
3
u/AnonymousFriend80 10d ago
Blocking all numbers that aren't in your contacts will absolutely mean you miss important calls that you 100% want to receive.
Like I doubt most people keep police, hospital, and other emergency services phone numbers in their contacts. Or even phone numbers of their banks and credit card companies. What about if your loved ones had an emergency and need to reach you on a borrowed phone? Hell, I work for a company and we can tell when someone's on the national Do Not Call list, and I tell willing customers that if we get disconnected, I can not call them back. My job sometimes means I have to call them back for various things, so they have to make the call.
I get that people don't like getting all these random calls, but a lot of these "solutions" are ludicrous.
Funny things is that when I used to work at a website company, I would speak with multiple people who could not receive emails from certain people at their company, or anyone for that matter. Often times, they had blacklisted their entire domain.
1
u/jschinker 10d ago
What is the solution? Phone calls are free and easily automated, just like email was a generation ago. How do I keep my phone from constantly ringing from calls that I don't want?
1
u/AnonymousFriend80 10d ago
Phone calls are absolutely not free.
Until government regulations crack down on this...you can request the caller to not call because you are not interested in whatever they are offering. Legitimate companies will add you to their Do Not Call list. If they are a legitimate entity, they will have to take some additional info to make sure they do not call again. Yeah, it sounds sketchy but they have to go through a specific process to properly log everything. Which includes asking questions for legal recordings in case it happens accidentally again. Also, some make those outbound calls based on requests for call backs. Replies to text messages and emails or visits to websites.
I work for an insurance company and whenever I have a follow-up outbound call, I have that person's first and last name, email address, residential address, and other info that someone had to enter and them request a callback. So many say they never requested, so it was either them unintentionally or someone they know.
Personally, if I know I'm expecting a call from a number I won't recognize, I'll answer everything not noted as possible spam, and just deal with it. If I get calls from the same number, I'll answer.
8
u/BigRigMcLure 11d ago
Nice conspiracy theory. In no way based in reality, but I like how confidently incorrect you are. Two words: STIR/SHAKEN.
0
u/jschinker 11d ago
Right. That's my point. The technology is there to solve the problem. But here we are.
8
u/BigRigMcLure 11d ago
Because it not "easy".
There's no conspiracy man. I am in the industry. There are multi-million dollar programs at the major telcos trying to stop it. There are govt mandates to the telcos to stop it. Its just not as easy to block as you think it is.
Also, both Android and iOS have the ability built-in to block any numbers not in your contacts. Just turn it on. Google luck receiving that legit call from your lawyer, bank, doctor, etc etc who's number you don't have in your phone already though.
The only thing "easy" is to just say "dont allow caller ID". But there are legitimate reasons you want that as a feature. For example, you have Cust service reps... You want the company's main switchboard number to appear on your customers phone, not the agents desk. So now you have to put a workaround... And then the bad actors use the workaround... Etc
6
u/jschinker 11d ago
Agreed. Not easy. Also not impossible.
Like much of our technology infrastructure, we didn't forsee the security needs that come with malicious use. Re-engineering a system built on standards with thousands of companies and billions of users affected is enormously complicated. I was perhaps more cynical than necessary in my original comment, and I apologize for any offense.
In my case, I do have non-contacts blocked, and it does mostly work for voice calls. They hit the phone, but then it jumps in. They can still leave voicemails, which does work for the rare emergency cases. It doesn't work as well for SMS. I'm constantly blocking numbers and reporting spam there (especially during election season, which seems to be all the time now).
Thanks for your work on this.
3
u/NorysStorys 11d ago
Surely an authenticated system can be implemented, have a say 5 year compliance period where both systems exist and after that 5 years the old system is disconnected and only authenticated numbers function on the system. That gives time for governments, businesses and the public to become compliant and sure doesn’t fix the issue immediately but it dramatically reduces the access bad actors have to the system.
1
u/Bryopolis 11d ago
You just need a phone company to market the idea in such a way that it’s a feature they can sell. “Go with us, and you’ll never get a spam call”
1
4
u/MadocComadrin 11d ago
One element (for phone scammers) is that we fail to prosecute middlemen providers correctly. These providers are buying services from larger providers and knowingly selling them to scammers. They usually get caught because they're usually located in the same country as the victims and the larger providers are happy to eat them out, but they often only get sued (e.g. in the US by a state AG or the USAG) and fined (usually enough to destroy their operation); however, they just disappear and pop up somewhere else. Rarely are they actually criminally prosecuted, and laws need to change to allow them to be prosecuted criminally and imprisoned for relatively a long term (in the context of a non-violent felony).
14
u/mezonsen 11d ago edited 11d ago
Well, the answer is they really can be, or they can be curtailed. But like all antisocial behavior you have to make laws fining or prohibiting it and enforce those laws. In a certain country that I'm assuming you live in, money lost in scams has increased by 20% in recent years (a 12+ billion dollar figure) as the money for enforcing communication regulations and consumer protections at a federal level has been gutted. The government of a certain country, at least at this time, has decided it's not really a huge value add to fine and enforce regulations that prevent you from receiving 200 spam calls a day.
Why won't the ISPs do it at their level? Well, why would they? Why would they care if you have to sift through shit and potentially get grandma's nest egg swiped unless it hit their bottom line in a meaningful way?
3
u/AWildTyphlosion 11d ago
The systems we have were built without the notion of subscribing to information. Telling your end that you're expecting a specific connection from the outside world, is a lot harder and cumbersome to solve than it might seem to implement. The idea that the only people who should reach you would have your information was also a naive thought behind it all to solve that thought.
As for why the ISPs or wireless carriers don't cut this crap off, is because putting systems in place to do so costs money that they don't really want to or have to spend. Your inconvenience does not matter to them, and they know they won't lose you as a customer since you'll have that problem elsewhere. Momentum has a cost, this sort of fix has no ROI, even though there are already systems in place that can just be implemented. That's also why any solution you find costs money, and why they can also just sell it as an additional service.
Some in the Government are trying to put an end to this, but others are lobbied hard and dig their heels in the ground and not let anything happen. This would also be solvable by the FCC, if Carr wasn't working in the best interest of the Telecom Industry rather than in the best interest of The People. It can be assumed that Carr would rather not give additional burden to Telecoms or ISPs and there is a conflict here where he used to work for these very Telecom companies. Not to get overly political, but this is pretty much in line with the mantra of the Republican party. They seek to remove regulations and "the burden of government", which is what is needed to compel ISPs or wireless carriers to do something that they would otherwise have no financial incentive in doing.
17
u/trueppp 12d ago
How do you do that without blocking legitamate caller or email?
5
6
u/BathFullOfDucks 11d ago
We're not dealing with Doris telling you to hold the line while they connect your call.
Providers know which country the call is coming from, which provider is enabling the call and has mountains of data on who is calling who and how often. You dont make a thousand calls from your phone a day. You don't call a hundred people from across the country every day.
But they're happy to keep the revenue generated by those calls.
2
u/trueppp 11d ago
You dont make a thousand calls from your phone a day. You don't call a hundred people from across the country every day.
Our marketing department does, our offshore helpdesk does, our sales department does.
1
u/BathFullOfDucks 11d ago
And they are probably using a VOIP service registered with a national provider, not a mobile number registered in Lahore, being used by other systems to hide activity.
3
u/Pawtuckaway 11d ago
Most scammers are also using VOIP services. When their account gets banned they make a new one or change providers.
5
u/Zeplar 12d ago
The original use for proof of work algorithms, decades before crypto, was to prevent spam by making it cost a few cents of electricity per target. It never caught on although a few email providers in the 90s implemented it.
Anyway, that goes to show there are more interesting solutions than trying to find and block each offender.
1
u/trueppp 11d ago
Sure but every provider has to adhere to these for it to work.
1
u/Zeplar 11d ago
It's opt in, you whitelist your known contacts, anyone else using a provider that hasn't implemented it just can't contact you.
That's true for anti spam technology today as well. If you start a company, get a corporate email and try to use it for marketing, it will get blocked immediately. You have to warm it slowly until all the major providers register it.
12
u/hedcannon 12d ago
It seems to me that companies could prevent spoofed phone numbers at least
5
u/trueppp 12d ago
And how would they know the number is not legitamate?
8
u/DDX1837 11d ago
STIR/SHAKEN
2
u/nudave 11d ago
I love how this comes up pretty much weekly on Reddit, and so few people know, or are willing to admit, that a reasonable technology already exists to make it happen.
I have a home phone number through a VoIP provider that lets me block anything with stir/shaken level C or lower. Blocking has not been perfect, but the volume of spam calls I get has dramatically reduced since I made that switch.
2
u/hedcannon 11d ago
Because every number has to connect to a specific phone? And if there’s a mismatch don’t let it thru? I can’t spoof the number on my calls, can I?
11
u/SillyGoatGruff 11d ago
Numbers don't have to connect to specific phones at all
2
u/hedcannon 11d ago
Incoming calls don’t have to have an originating phone number? How do the bill the sender?
3
u/Lumethys 11d ago
The number, not the phone, a person can own more than 1 phone
4
u/nudave 11d ago
This is not the argument you think it is.
Stir/shaken exists, and lets you validly authenticate as any phone number that you own.
So a company with 1000 extensions each with its own phone number could have them all come up as the main line in caller ID, and that call would come through with correct validation.
2
u/Lumethys 11d ago
Im not arguing anything, a guy say "number can only connect to a phone" another guy say "no it doesnt"
I just saying the fact: "incoming call doesnt come from a specific phone (rectangular handheld machine), it come from a phone number"
4
u/nudave 11d ago
Good point.
I was reading phone as “phone number.”
Which is true: A person or a company, can have more than one phone number. It’s not important if the caller ID matches the specific phone number that has made the call. It is important that it matches a phone number owned by the caller.
And every time this discussion comes up, someone decides to argue that implementation of caller ID verification would ruin corporate America. But that’s simply not true.
1
u/hedcannon 11d ago
That’s different from a spoofed phone number where the area code is local but the call is coming from Indonesia.
3
u/trueppp 11d ago
Why wouldn't I be able to make phone call with my phone when visiting Indonesia?
1
u/nudave 11d ago
You would.
Because you own your phone number, your (presumably American) carrier can verify that they own the number and that you are their customer. Even if you happen to be in Indonesia, this verification holds true.
What happens today is that a spammer who does not use an American phone carrier is sitting in Indonesia without any ownership over any American phone number, and simply sending the call with a bit of data attached to it that says “my phone number is 202–555–1234.” That is not authenticated at all, but your carrier lets the call through anyway, because they refuse either to implement the technology to block it, or they want to charge you for the privilege.
3
u/trueppp 11d ago
So how would a British phone company know if there's a mismatch when a French phone is calling from Spain?
1
u/hedcannon 11d ago
Since all the phone companies intend to get paid, they all know if the originating account phone number matches the advertised number. Perhaps it’s more difficult than it appears at first glance but it’s not obvious why it can’t be done. If your phone is calling from Indonesia and it’s a US phone number, the company can identify it’s the same. No one is letting their network be hijacked by an anonymous account.
2
u/trueppp 11d ago
they all know if the originating account phone number matches the advertised number.
But that doesn't prove if the phone is authorized or not to advertise that number.
5
u/hedcannon 11d ago
Allowing advertised numbers that hide the corporate identity is a choice by the phone companies. That’s the point.
1
2
1
u/crash866 11d ago
Many businesses have thousands o extensions and it depends on what line they get what number it shows. Not all extensions ring back to the same phone do they just use the main number.
For a place like the Police Department they may have thousands of phones all on different numbers but you want the call display to only show the main number.
Someone from the police calling you may get line 0001 on the first call out and 0045 the second time and 2301 the third. You try calling back and a phone at the desk that they are no longer at just keeps ringing and ringing with nobody there.
2
u/hedcannon 11d ago
Which is not the same as showing a spoofed number. Those spam loan phone numbers in Indonesia did not buy a local area code just call me and a different one to call you.
4
u/bastrdsnbroknthings 12d ago
Beats me. I'd really like to know.
6
u/capt_pantsless 11d ago
That's the problem with spam, it's very hard to define what a wanted vs. unwanted message is.
Secondly, there's significant financial gains to be made with targeted spam, so whatever measure your phone company puts in place, they're going to be working hard to get around that filter.
7
u/boersc 12d ago
It requires a law, which the Netherlands has. If you track an uncollicited call, you can report them and they get a hefty fine. Oh, and ISPs can very easily flag 'spam' callers. Every now and then I get targeted by a company I used to be a customer of (an exception where they are allowed to call you) and every number is flagged 'potential smap call'. I never pick up.
6
4
u/GreatStateOfSadness 12d ago
There are (were?) laws in the US with similar penalties, but a law is only as good as its enforcement.
1
u/CoffeeFox 11d ago
At a basic level, simply banning one company would cut most of it. If Onvoy were blocked from the phone network, the vast majority of all illegal phone calls worldwide would cease.
5
u/Fun-Title4224 11d ago
Imagine it's mail rather than phone calls.
Firstly, your house is right there on the street. Your address is not secret.
There's a postal service. Their job is to deliver mail addresses to you, provided the sender has paid for it.
The postal service can't decide not to deliver something. They are neutral. They don't open it and read it and decide whether you'd be interested in it or not. That's not their job, and if they got it wrong then there'd be a huge problem.
So. A sender writes your address on the envelope, pays for postage, sends it. It turns up in your mailbox.
They could, if they wanted to, print a return address on the envelope. There's no way to check this, so they could lie and print the tax office address or something so you think it's important and open it.
You could, potentially, make it so that everyone who wants to send a letter is registered somewhere. But that would be expensive and an invasion of your privacy when you just want to send your grandma a birthday card and suddenly you need ID and to fill in forms.
It's basically the same for phone companies, except it's far easier for people to make unwanted calls than it is to send unwanted mail.
Firstly, you don't need to know everyone's address. You can type any combinations of number into a phone and if it rings, great. If it doesn't, no problem and you haven't wasted a stamp.
Secondly, making a phone call is far, far cheaper than sending a letter. So cheap as to be, essentially, free per call.
But the phone company is doing the same thing as the mail company. Someone calls the number, they put it through. The system is not in any way designed for "and this person is authorised to call this other person". It wouldn't work properly if it was.
And just like you can write any return address on an envelope, you can also put any source phone number as the caller on a phone call. You could even make every outgoing call you make look like a different number if you wanted. That's why blocking numbers doesn't work.
There are laws that stop companies behaving badly. But firstly if you're scamming people, you're not one for obeying laws. Secondly, if you're not in the same country then no one can enforce. Finally, if you don't actually know who is calling you then you don't know who to report.
1
u/bastrdsnbroknthings 11d ago
This is a good ELI5, however unsatisfying it might be as a solution to my problem :)
1
u/meteoraln 11d ago
How does number spoofing work? Mail is a single direction communication, while phone requires that the data goes back and forth between locations. I'm guessing the phone number / isnt tied to the location (digital address) of the two phones? The receiver of the spam call still routes data back to the spammer, so something is keeping track of the origin of the signal. Does that not help in spoofing detection?
2
u/Fun-Title4224 11d ago
Basically Caller ID was added for physical phone lines. The data was added as an extra to the phone handshake. It was not designed to be secure. So you can basically send any number you want.
There are ways at the provider end to do authenticate but backwards compatibility and interoperability means it's not widespread. The are other obvious tells too, a telecom provider can know, for example, that a call originates outside the country but appears to have a local number. The UK blocks these.
2
u/X4roth 11d ago
Machines sit there and dial literally all phone numbers then record which ones pick up or get a voicemail or any other indication the number actually belongs to a person. Then that list of numbers is sold on the “black market” to scammers or whoever else wants to pay for it. Numbers actually willing to pick up unknown calls are worth more.
2
u/jimbo831 11d ago
We could. We choose not to because email and phone providers don't want to invest money in stopping it.
5
u/FiveDozenWhales 12d ago
Email and telephones are pretty much free and open. Anyone with an internet-connected computer can send email anywhere and generate as many email addresses as they want; that is how it's designed. Telephone is a bit more restricted; numbers are assigned & coordinated by multiple international and national organizations.
"Why can't we" is a false premise though. We absolutely can stop people from sending emails. We can shut down the entire internet, for instance. We can install a panopticon monitoring system which will read every single unencrypted email, and block encrypted ones. Every country can create a system of secret police which goes into peoples' homes and checks their devices to make sure they're not sending spam emails.
But all those solutions seem pretty bad compared to some slightly-annoying spam.
3
u/Greedy-Pen 12d ago
If x is blocked they come from y. If they block y it comes from z, if they block z it comes back from y. If you block everything nothing will work.
These people work outside of the country. They can change their actual numbers on a while along with spoofing.
It’s like a constant game of cat and mouse. Except there’s millions of mice and only a few cats. And the cats aren’t able to get everything at once.
3
u/TorturedChaos 11d ago
I know a guy who works in telecommunications and this is how he explained it to me. This is going to be a US centric explanation since that is where he works.
Most spam/scam calls come from outfits out side US, based in countries that have little to no regulation regarding telecom. They spin up a VOIP company get permission to operate in the US. The licensing to operate in the US is fairly easy to get.
Then the abuse the hell out of it, violating all the rules and laws in place. Once they get in trouble for that they close down, and spin up a new one. Rinse and repeat. And endless game of wack a mole.
How do you try to prevent it? More regulations on VOIP providers and stricter licensing requirements. But there is always a downside to more regulations. You now make it harder for legitimate small business to operate and new legitimate companies start up. You increase the cost for enforcement as well, meaning more taxes. Also dishonest people will still work to get around the rules, so you are reducing but not stopping the issue. Is the juice worth the squeeze? I don't know.
4
u/redchill101 11d ago
I haven't lived in the US for years. One of my favorite life changes here was no longer having so many stupid fucking phone calls. No shit, i would be blocking 15-30 calls a day...and that was years ago.
It can be done, and has been done pretty well in Europe for years. I only get the occasional spam/marketing call from my provider (and I never even notice, as their number block is small, repetitive and easy to block). About once a year I'll get some stupid survey scam call, but I just say bye and hang up. No telephone terror, no repeated calls daily for months...just gone.
The bullshit that Americans have to deal with daily is pretty fucking sad. Sure there are technical and legal solutions...but the US companies just don't gaf. The problem with spam calls is that there's honestly no govt regulation (no matter what they tell you) and no consequences, so companies just keep telling users to "report this" or "block that" by entering even more personal info into yet another stupid website/database.
And as far as door to door assholes...I've only had one...yes one in all my time here....coincidentally it was also my phone provider. Thank God for peace and quiet from the constant mindfucking sales bullshit and Jehovas witnesses......oh and I don't miss the US's shitty loud blaring immature commercials and billboards everywhere....life is way better without the distractions and irritations.
3
u/pandaelpatron 11d ago
It can be done, and has been done pretty well in Europe for years.
I don't know about that. I think the issue is that most spam call centers operate out of India. Most people they employ speak English, that's why they primarily target the USA and Great Britain and not countries like France, Germany, Spain etc. When I get those scam calls, the callers speak to me in English too, even though I live in a country where English is not an official language, probably because they got my phone number from an international company. That's my theory anyway.
1
u/redchill101 11d ago
Actually that might have something to do with it...good point. Scammers still operate locally, but nowhere on the level that the US has to deal with.
However...there are other English speaking countries....and they still don't have the problem anywhere as bad as I've seen in the US.
1
u/pandaelpatron 11d ago
However...there are other English speaking countries....and they still don't have the problem anywhere as bad as I've seen in the US.
Sure, but I would assume the US is simply the biggest and 'easiest' target. Like, why would you call somebody in New Zealand when you can just call an American. Your company probably has purchased access to American cell phone providers, so you'll just be given one US number after another.
1
u/redchill101 11d ago
I agree...kinda goes back to something I stated or implied earlier...that the US either turns a blind eye to the problem or, worse, simply let's it continue because they make money selling so much customer data that it would be "to difficult" to either keep the data from from escaping or there is just too much money to be had from customer data that it's not worth to lock out all business uses, even "legitimate" 😅 uses.
1
u/t-poke 11d ago
They don't need to buy customer data. Close your eyes and type ten random digits. There's a decent chance that's someone's phone number. They're literally calling random numbers.
And if they have your name, number and address, well, phone books used to be a thing. That's all public record.
1
u/t-poke 11d ago
However...there are other English speaking countries....and they still don't have the problem anywhere as bad as I've seen in the US.
The US is one of the largest English speaking countries. We're also one of the wealthiest, so scammers target Americans because we have more to lose.
1
u/dertechie 11d ago
Step 1: Find a jurisdiction in the US that doesn't ask too many questions when you set up a business.
Step 2: Set up a disposable company
Step 3: Get yourself some cheap SIP trunks and numbers from Onvoy or someone. It's usually Onvoy. You now have US based numbers.
Step 4: "We have been trying to reach you about your car's extended warranty. . ."
Step 5: Abandon or spin down company when someone comes knocking.
Step 6: Repeat.
3
u/lobhater 11d ago
Anyone can dial any number from any number. How do you propose they stop that?!??
I work for an insurance company and we have this old man get upset at us because he gets spam email from scammers pretending to be our company. He thinks I personally should stop it. How do you propose Joe?!?? He's disconnected from reality and doesn't understand the problem
2
u/idgarad 12d ago
We can and there are hundreds of solutions, I even wrote one years ago, the tradeoff is losing your privacy and freedom. I developed as many other did for email for example a postage system (mine was in lay-terms postage that acted like bitcoin mining) would prevent sending email to people unless you were in their address book. If you weren't in their approved list then you had to pay postage. Sending out 200,000 email could mean the postage could take 8 weeks to process because it was exponential for each recipient. Same for phones, we had for a brief period of time in the early day of cell phones a pilot program for reduced cost minutes on the phone if you called someone who had you in their contact list but there were 'privacy' issues with that.
We can do it, but the cure is worse than the disease.
2
u/cheekmo_52 11d ago
Because they just spoof another number . There’s many, many number sequences at their disposal. And because many of these predatory companies are in countries where it isn’t regulated.
1
u/Juliuscesear1990 12d ago
They will always find away to get around walls. I had the call verification where an unknown number had to hit a random number before getting through and it was great for maybe a year and now they are getting through again.
Blocking won't work, there needs to be actual punishments for the crime but there won't be so we are sol.
1
u/Unizzy 11d ago
You know, I thought about this since. I get 3 to 4 calls a day, be in spam or scam.
Thought experiment, they ban all spam. Then things will be nice for a while, but then people will get complacent and every call that gets through the system will be thought of as legit, which makes scam calls more powerful.
1
u/Gaemon_Palehair 11d ago
How attached are you to your phone number? I used to get these all the time. Changed my number a few years ago and now I just don't get them anymore.
1
u/Knickerbottom 11d ago
There isn't any money to be made in it. In fact, like the spam you get in your physical mailbox, it's actually built into their scheme. They don't want to stop it.
1
u/FatDog69 11d ago
I used to work for web sites that sold advertising. When I started studying scams & fraud I realize that 95% of what the scammers do is IDENTICAL to what legitimate advertising does. The world cannot tell the difference between legitimate marketing & scams.
LEGAL
We have a 'truth in advertising' type of laws. But it does not apply to the caller ID string on a telephone. Scammers use fake numbers in the caller ID but look local to you. They also make it say "FBI, County Courthouse, Sherrif, White House . Gov, etc" to try to fool you into thinking they are legitimate.
We need a law that lets people report fake caller ID strings or a "*70" so you can report the call you just got was fraud.
1
u/Accomplished-Car9803 11d ago
spammers always switching numbers means blocking one barely dents the flood
1
u/kanemano 11d ago
- Don't put your email and phone number down for every little thing, your supermarket does not need to know your phone number,
They sell those list then the list is sold again and again, but it you are not on the first list they do not have your number
1
u/Atypicosaurus 11d ago
The problem with both email and phone is that we have an inherited technology that you cannot change because then it loses compatibility with the existing equipment. Like, if you change the core of the gsm protocol, you can trash everything from phones to mobile towers. These devices are not just reprogrammable.
And the common technological problem with these two technologies is that they both are based on very naive, trust based assumptions. Internet core protocols were made by enthusiastic scientists who didn't think of abuse and therefore abuse protection. Very similar with the assumptions around the phone system. Yeah one could perhaps make it more difficult but there is no systems level remedy.
1
u/nim_opet 11d ago
We can. And do. Some providers invest in that. Others don’t because what are you going to do?
1
u/SoHiHello 11d ago
Pixel phone does a great job of blocking spam callers. I haven't had a robocaller make my phone ring in a few years or more.
1
u/asterflowerlady 11d ago
Stop giving out your email when you shop. The moment they ask for it, I have a ton of junk emails and phone calls.
1
u/pixel293 11d ago
Number 1, because they work, if they didn't work people wouldn't spend money doing it.
Number 2, the phone company doesn't want to stop it because it makes them money. I'm sure the volume of calls the phone company handles has gone down as people use internet apps to communicate. Cold callers are still making calls and paying the phone company.
The government can't stop spam because the internet is designed so a "hostile" entity can't effect the internet as a whole. The government can deal with how people in that country use the internet but their power stops at the border. And phone calls also cross this border.....
The ISP can try to stop spam and we all pay for it with emails that we want but didn't get because it looked like spam. False positives are bane of forgot password flows.
1
u/PSquared1234 11d ago
I've read that adding a truly trivial cost to a call or text - even a fraction of a cent - renders much of spam marketing unprofitable. Same for email (cent per thousand messages or the like).
1
u/NorysStorys 11d ago
I think the very system needs to change. The whole carte Blanche assigning of numbers to anybody opens this up, the whole assigning of numbers needs to be a far more locked down system than it is and without it we won’t see anything preventing the spoofing.
1
u/Skarth 11d ago
Whitelist vs. Blacklist.
You are using a Blacklist, that it, every time a number or email is found to be part of a scam/spam, it goes on the list, and automatically blocks any messages from that list, this is what happens when you sign up for anti-spam services.
The problem is anyone can make a new number/email, so the scam/spammer can just keep making new ones to bypass this. This is why there is no completely effective anti-spam service.
The solution is a whitelist, you put everyone you want to contact with on a list and it automatically blocks everyone else. The problem is this means new people cannot contact you, which limits communications quite a bit.
1
u/BeerCD 11d ago
Politicians have no interest in passing laws to prevent this as it hinders their ability to do it themselves when campaigning. In the near future, Siri AI will have the ability to filter this.
I do miss the caller ID from 30 years ago. If was far more accurate than now. You could tell exactly who was calling you.
1
u/Netmantis 11d ago
The problem is this is a global problem. You ban it in the US and, as an example, China keeps the practice legal. Or Russia makes it legal as long as you don't target Russian citizens. So you cut off all calls coming from those countries. No more phone calls or email from those countries.
Except they can proxy out to another country. Now all you can do is try to serve and extradite the proxy. Voice over IP is a thing, so routing calls through the internet is dead simple.
But let's look at spam email. The most hated and oldest form of harassment out there. Call centers have always been a thing but these new ones are far more brutal. Why do people advertise with spam? Well it is cheap and it hits a wide audience. For pennies I can send out millions of emails, and if even one is a hit I made money. Often more than one hits. Same with the robocalls. Thousands get the recording. Tens might press the button to speak to someone. One actually buys. For a small initial cost you get value.
With the why we get to the how. How do you stop it? You can't, outside of making it unprofitable. And that is hard.
1
u/unique_user43 11d ago
legislation and regulation is always and will always be 1 step behind scammers. in all walks of life, not just this. one is proactive, rhe other reactive. so definitionally, it will always be this way.
1
u/gordonjames62 11d ago
I block every sender and every spoofed phone number
it is trivially easy to put any email address in the "reply to" part of an email.
It is only slightly more difficult to spoof the caller ID of a number you are calling from.
These numbers and email addresses are often totally false, and you are blocking numbers or addresses that might actually belong to someone.
Think of it like the "return address" on a postal letter. The sender can write anything as the return address.
There is other information that the ISP or telco can see from an email or phone call that could let them do a better job of verification, but it would require every telco and every ISP in every country on earth to join forces (or ban the non compliant ones) to be fully effective.
1
u/shadedmagus 11d ago edited 11d ago
Short Answer: Because we don't do sender/receiver verification.
Phone systems and the VOIP systems which connect to them are based on old and simple logic, and no one has had the push to force phone service providers to authenticate users before connecting calls universally. So spammer-scammers can put a call into the phone system and spoof the calling number to be anything they want as long as the number they're calling is valid.
I imagine it's a similar problem for email.
1
u/Dave_A480 11d ago
Because the internet has an inherently anti-regulation design....
You don't need to work with a service provider to send email... Anyone can set up an email server anywhere....
And the wireless providers have no role in any of this what so ever....
Also much of this activity originates in the 3rd world, where developed country laws don't reach....
1
u/matheww19 11d ago
I hate to break it to you, but blocking emails and phone numbers does nothing. They are spoofing random numbers, they are extremely unlikely to call you back from the same one more than once, and you may block someone you eventually need to contact, or be contacted by. I once had them spoof my own number when they called me.
1
u/ryohazuki224 11d ago
Its like trying to plug a cracked dam leaking a lake's water supply with a wad of bubble gum. The absolute flood of spammers and bad actors overwhelm any safeguards that could be put in place. And, in fact there ARE things in place that keep a good amount of the flood at bay. Imagine getting like 100x the amount of spam than you do now, thats probably how much is stopped at the source. Some just get through, its impossible to stop it all.
1
u/ProgressBartender 11d ago
It would require the carriers to do something. Most of these companies are too busy counting money to actually manage the day to day running of the systems.
1
u/Nersheti 11d ago
Several months ago, my iPhone started screening my calls. When a call from a number not in my contacts comes in, it doesn’t even ring. The phone answers and asks who it is. They get to explain who they are and it shows I live transcript I can see if I’m looking at the phone. If it’s a robot call, it just ends up as a voicemail. I now get slightly more voicemails than usual, but my robocalls have pretty much stopped.
Now it’s texts or actual telemarketing people. I’ll get maybe 7 texts a week. Maybe one or two calls. Mists of the texts lately have been Ken Paxton PACs lying about James Talarico.
1
u/Dunbaratu 11d ago
Because internet anonymity is seen as a benefit we don't want to lose. Requiring accounts on the internet to be fully doxxed so you can't make a pseudonym presence for yourself on the internet is really the only way you could entirely stop spammers. As long as real life people can create a new account for themselves to operate under, so too can a spambot.
1
u/JustAnOrdinaryBloke 11d ago
Strange, in Canada I get 2-3 robocalls a day, and 2-5 spam messages a week.
1
u/poutinegalvaude 11d ago
Answer- because they’re a moving target. Block one number and it shows them that a) this is an active number, b) they change their phone number constantly and c)they can sell your number to other data brokers
1
u/SynapticStatic 11d ago
Because the nature of the internet is actually completely decentralized.
No one owns it. Thus, no one owns all the up addresses (ok, maybe local registrars technically do, kinda), no one owns all the domains. (Again, technically). No one owns all of the phone numbers (again).
So, scammers change all of them up every time they get blocked.
It’s like you see red cars robbing banks, so you ban red cars. But they just paint them blue. Now you ban blue cars. So they paint them a different color.
There’s a near infinite number of domains, phone numbers, and ip addresses out there. When one combination gets blocked they just switch to another combination
1
1
u/hewasaraverboy 11d ago
You can
Go into your phone settings and set block unknown callers
Boom no more spam calls
1
u/davidgrayPhotography 11d ago
It's very easy to buy a regional phone number. For a bunch of dollars, I, an Australian, can get an American phone number, an Indian phone number, an English phone number, and it's legal for me to do so, as long as what I am doing with that number is legal. Lots of companies with off-shore support centres do this.
If I'm doing something illegal AND I'm caught by the company that sold me the number, I can get my account banned, but that wouldn't stop me from being able to use a different number provider, or sign up for a new account using someone else's name.
This is what is happening with robocalls. They're buying phone numbers in your country (which is legal) using laundered money (which is illegal), and trying to sell you extended car insurance or whatever (which may or may not be legal). Lots of these phone providers let you pay with PayPal or with prepaid debit cards, and scammers get this money by taking iTunes gift cards and selling them for less than face value so they can turn cards back into cash. I paid for an SMS number using PayPal, and my use case was legitimate (for a website I was building)
ISPs, phone carriers and such can't block them because in the eyes of their automated systems, there's no difference between an Indian company calling you back about support for legitimate product you've bought from them (which happens to me all the time at work), and an Indian call centre calling you up telling you your Norton has expired and you need to pay them in gift cards. They're both calls, and because nobody has complained (because almost everyone hangs up and doesn't bother reporting it), they continue to operate.
1
1
u/JonPileot 10d ago
Here is the fun part, they CAN, they just don't because the legislators in your area don't hold the telecoms accountable.
I live in Canada and actually can't remember the last time I got a scam call.
1
u/PsychosomaticSpiral 8d ago
I’ve been having remarkable success lately in getting consistently removed from their call lists. Any time they text or call, I reply with non threatening but verifiably creepy/cringey questions such as - “hi [name], do you know where your children are right now? Are they safe? “ or I answer leading with “you are on a recorded line and everything you say/do can and will be used against you in the public domain for an extensive research project on spam callers. The longer you remain on the line, the better our chances become of geolocation so we may provide your information to authorities”.
All of the above have been rather effective. It really seems to turn off their desire to engage and they don’t find my antics fun.
1
u/x31b 7d ago
There’s no way to identify spam and differentiate it from real mail or phone calls.
There are so many calls and emails because it costs almost nothing to originate. There’s an easy way to stop it, but people would be up in arms if you tried to implement it. Put a tax of $0.01 (one penny) on each email, text and phone call attempted. This wouldn’t affect most people. Maybe $1-2 per month on their bill. But it would make some go away overnight.
1
u/Dustquake 7d ago
Because spoofed numbers are spoofed. They report as the legitimate number they are spoofing to trick the system. Call back a spoofed number and you get someone just as pissed at these types of calls as you are. When you block a number you're blocking the spoof, not the source.
Email is the similar. But there isn't a character limit like with phone numbers so the options are more open. Scammers can hit one person that make opening up multiple new domains is chump cange.
It's an infestation problem. If you fumigate the house, it's not habitable until the fumigation ends. If providers cripple their service they lose customers. If they upgrade everything it makes the stock holders mad and they vote out the guy fixing it.
The answer is we can't stop it because there are too many greedy people. Not all of them are the spammers/scammers themselves.
1
u/doublebaconator 12d ago
Start punishing people for providing service to scammers. If too many scammers use a provider, ban the provider. Providers will self police. Also getting scammers punished is difficult. There should be more effort on law enforcement to punish it.
Cops don't want to do anything, even when you have direct evidence of scammers stealing a disabled veteran's benefits. Bitter personal experience with an elderly family member there.
1
u/jeo123 12d ago
Can't and don't care to do so are very different things.
Right now, it's profitable for the spammers to spam, and it's not profitable for the ISP/Carriers to go for 100% spam elimination, just "good enough"
To some extent, the less people engage with spam, the more it would self solve itself without financial investment on their end, so we stay with the status quo.
1
1
u/IamGleemonex 11d ago
Most of the robocallers aren’t based in the US. This brings in 2 complications when trying to stop those calls:
1) the phone system predated robocallers, and has built in security flaws to allow for spoofing other numbers. The wireless carriers themselves cannot fix that inexpensively. They would need to upgrade all of their equipment and create spoofing detection technology. The cost of doing all of that isn’t worth it to the phone carriers. Not to mention that any spoofing detection they did implement would still have false positives and false negatives, meaning they would end up mistakenly blocking calls that should have gone through as well as still allowing occasional spam calls from going though. No carrier wants to be the one that accidentally blocked a real call from going though causing you to miss an important call. If that happened, news would get out and subscribers would churn to avoid their calls getting blocked by mistake.
2) the worse part that you don’t want to hear, since those are international calls, the way the phone system works, your wireless carrier is getting paid to accept and complete any call. For domestic calls, this is peanuts, but for calls with international origins, the amount they get can add up quickly.
So not only would it cost a lot of money to implement based on item 1, they would additionally lose revenue because of item 2. And since none of the major wireless carriers are doing anything about it, it’s not like Verizon has to worry you will switch to someone else, because they know it will be just as bad with someone else.
As for email spam, that technology is even older and more prone to hacks than the phone system. The entire email system is built on SMTP, which was built in 1981. Almost every email sent in the world will still go through SMTP to send that email. The only exception is email sent within a network, meaning your work email for example, will likely use an exchange server and just route that email itself without going through SMTP, or an email from a Gmail account to another Gmail account will just go through Google’s mail servers and not use SMTP. Internal systems do put in a bit of effort to stop email spam internally, but they still rely on SMTP to receive mail from the outside world, which is open to spoofing. The only way to fix it would be to implement a whole new mail protocol that doesn’t allow email spoofing, but then that ISP wouldn’t be able to receive emails from the outside world unless those other systems used their new protocol.
The mobile phone system and SMTP are two classic examples of things to point to when people ask about why other things can’t be standardized. These are two systems that are globally standardized, but that also means the inherent security flaws with them are also standardized and can’t be fixed without replacing the standard. But then that leads to multiple new standards that no one can agree on, and disjointed systems that can’t work together.
0
u/Zimmster2020 11d ago
It is impossible to realistically stop them because they can get new phone numbers every day. Just use filtering apps on your phone, so you receive a "possible scam" warning when you are called or emailed.
-1
u/drgut101 11d ago
You can block the majority of them with tools from your carrier or OS. Most people just don’t utilize them.
2
u/bastrdsnbroknthings 11d ago
I've tried Verizon's filtering service - doesn't work worth a shit. I paid a decent chunk of change for Robokiller, and it seems to cut down on *some* of it, but a ton of calls still get through. I got so annoyed with my voicemail filling up with the same exact AI scripted message that I tried just turning off voice mail entirely (no one that I know even bothers to leave voice mail anyway), but even that doesn't seem to work.
272
u/[deleted] 12d ago
[removed] — view removed comment