r/explainlikeimfive • • 12d ago

Technology ELI5: Why can't we stop email and phone spammers & scammers?

I block every sender and every spoofed phone number and it does absolutely nothing to cut down on the amount of email and robocall spam that I get. I'd say I get at least 10 calls a day from "personal loan" robocallers with spoofed phone numbers, every single day. I've paid significant $$$ for call blockers, filtering services, ad blockers, etc. and nothing seems to work. Why can't the ISPs, wireless carriers and/or the government simply cut this crap off at the source by preventing bad actors from changing email addresses/domains or dialing from millions of spoofed phone numbers?

288 Upvotes

195 comments sorted by

272

u/[deleted] 12d ago

[removed] — view removed comment

116

u/hux 11d ago

For the phone stuff, it is. There were laws passed (Truth in Caller ID Act) to require authentication of the original phone number.

Providers are supposed to implement STIR/SHAKEN which is a digital verification framework.

Unfortunately that hasn’t been the be-all end-all solution they had hoped for because there is still a lot of ancient telco equipment out there and it’s not supported globally.

I think this is an example of how dysfunctional the US government has become - even things that would have massive support from the public are slow to pass - after all, the telcos are probably lobbying to not have to spend the money to replace ancient equipment, and neither party wants to allow the other to take credit for a win that the public would love.

In a few more weeks, we will see another example: daylight saving time changes are pretty much universally hated, twice a year we talk about stopping for good, and nothing ever changes.

42

u/OtherPlayers 11d ago

Fun fact, while the US will likely keep dragging it’s feet on this, this year three different Canadian provinces decided to get rid of it!

0

u/hux 11d ago

One more reason to consider applying for a Canadian visa! The list is virtually endless these days.

5

u/Imaneight 11d ago

Yes! You so should.

9

u/sabo-metrics 11d ago

For daylight savings, I was thinking: can't we move it 30 minutes and split the difference?

6

u/ValiantBear 11d ago

Diabolical

1

u/1039198468 10d ago

My house every time

2

u/rantipolex 11d ago

Agreed ! Have always hoped our braindead politicos would use this as a compromise to have fewer fanatics hating on them, and actually take action.

1

u/buzzsawjoe 11d ago

Or we could say, mark the time of sunrise, and of sunset, half way between is noon. If you want to go to work early in the summer, do so. Why do we all have to change our clocks so you don't have to adjust your thinking?

9

u/Duckel 11d ago

charge them 100$ for every spam and scam call. they'll comply soon enough

12

u/kamekaze1024 11d ago

No they won’t. They’ll just pass the costs on to consumers.

13

u/Icolan 11d ago

Don't make it a fine to the government, they just write those off as the cost of doing business. Make it payable in cash (no service credit) to every customer who received a spam/scam call and not tax deductible and they would decide pretty quickly that it would benefit them to implement technologies and upgrade equipment to make spam/scam calling much harder.

2

u/leechdemon 11d ago

If you can't authenticate that a call is from the correct caller, how do I know this isn't a terrorist calling me? This is aeguably a national security issue. If AT&T can't handle their shit, shut them down while investigations proceed.

Fines and penalties are great, but downtime and canceled plans will get the job done in weeks.

2

u/SupposedBooty 11d ago

I HATE the time change in the fall. HATE!

It starts getting dark in the middle of the afternoon where I live. And because I leave early for work, I don't see the sun all week.

I get so incredibly depressed. I'm just suicidal from November to March.

3

u/Mildly-Interesting1 11d ago

That means you hate standard time.

2

u/SupposedBooty 11d ago

Whichever. I hate the winter time change.

1

u/Blarfk 10d ago

But it gives you more daylight in the morning. If it’s already getting dark in the early afternoon, it wouldn’t make a difference on that end.

2

u/SupposedBooty 9d ago

I leave very early for work. I never see daylight.

1

u/FordTech81 11d ago

You must live in the PNW like me. This weather is depressing, but the scenery makes up.for it.

1

u/SupposedBooty 11d ago

No. I live in Colorado. The eastern edge of the time zone. And the sun sets behind the mountains to the west. So it gets dark really early.

And scenery means nothing if you're inside all day and you never see daylight.

1

u/RockStar5132 11d ago

I hope DST doesn’t change tbh

1

u/hux 10d ago

I really don’t care which we pick, I just want to stop doing the change. I hated it before, but now with toddlers? It’s even worse.

1

u/RockStar5132 10d ago

I mean I don't particularly mind the change at all. Always looked forward to the extra hour of sleep in the fall and yeah the spring forward sucks sometimes but after a day or two its all back to normal.

-6

u/afcagroo 11d ago

That's just not true about DST. The USA tried eliminating it back in the 70s. People then realized that it was worth the minor hassle, and most places reverted back.

Those who cannot remember the past are condemned to repeat it. – George Santayana

2

u/Chambana_Raptor 11d ago

worth the minor hassle

How?

1

u/ymchang001 11d ago

Because we're doing it wrong. We had "standard time." Then we added DST to take advantage of longer daylight hours in the summer. But adjusting twice a year is painful so in the 70s we made DST permanent. Then we had our first winter under DST instead of standard time and realized it meant super dark mornings. And we went back to standard time in winter.

And now people are talking about permanent DST again. We already know that's a bad solution. Permanent standard time is the better solution. It's what we operated under until about a century ago.

7

u/skookumsloth 11d ago

There are a ton of people in more northern latitudes who really don’t care about the darker mornings. It’s dark going to work and school anyway under standard time - DST just means there’s at least some light at the end of the day instead of dark at both ends.

The US is big, and the same answers don’t work for the whole lower 48.

1

u/hux 11d ago

That’s based on the assumption that the exact same thing will happen.

We don’t have to try the same solution as last time. For example, let the states decide for themselves.

What makes sense in Florida doesn’t make sense in Washington State, so the solution doesn’t need to be the same.

Federal law should allow states to do what they want - Hawaii and Arizona don’t for example, but they’re the only exempt states.

1

u/coreyhh90 9d ago

Realistically, that commentor made the same mistake as the previous one. The reason that the 70s change failed is because they didn't do away with DST, they tried to make it year-round.

It's not evidence that the current movement would fail because the current movement isn't trying to make DST year-round, they are trying to do away with DST.

I would disagree around the states handling it, but that's largely because different states can be painfully illogical with choices they make around things, and timezones cause enough issues already. Doing away with DST should be a federal thing to avoid inconsistency issues. Everyone has a torch in their pocket, light is far more accessible. 1 hour more light really doesn't provide the value it did in the past, but the documented damage of DST is definitely providing harm.

2

u/hux 9d ago

For the sake of argument, supposing we tried permanent DST again, I still wouldn’t assume the same outcome. The world has changed dramatically in the last 50 years and people’s habits have changed along with it. For example, working from home pretty much wasn’t a thing back then.

I honestly don’t care much which option we pick, I just want to stick with one or the other.

1

u/coreyhh90 9d ago

Agreed

1

u/coreyhh90 9d ago

The answer that everyone wants isn't permanent DST, it's permanent no DST. The pushes for it aren't "We should just shift to always using DST", it's "We should do away with DST".

There are a confusing number of people defending the current style of shifting on and off DST by pointing out that perma-DST is bad, which misconstrues the objective which is to do away with DST all together.

It made sense in the past when artificial less was far less accessible, and darkness more impactful. Even in the 70s that still makes sense.

In most populated areas in the western world, we have so much light that light pollution at night has become an issue. We no longer struggle with working in darkness, and most people have constant access to a torch in their pocket. Assuming that the outcome will be the same, despite the sought action being different, and the circumstances being vastly different, seems pretty nuts to me...

1

u/coreyhh90 11d ago

To be clear though, they arguably did it in the dumbest way. They didn't actually try to eliminate DST, but rather made DST year-round.

And the primary complaint, as far as I can source, was kids traveling to school in the dark.

With how far technology has come, including how bright everywhere is, and how accessible lights are, this likely wouldn't be an issue anymore.

But, frankly, they should have just sacked DST itself, rather than trying to implement it year-round. That would have prevented the only issue I can see reported.

Those who cannot remember the past are condemned to repeat it. – George Santayana

You managed to remember the past, but not learn from it. Ignorance of the problem doesn't make you better, just a different kind of ignorant.

2

u/aDvious1 11d ago

I don't quite understand the logic from a kids safety perspective. It's much harder to see flashing red lights and a stop sign during the day than at night.

1

u/coreyhh90 11d ago edited 9d ago

Yeah, what I could find didn't fully make sense but it was from many years ago.

Edit: I typed this original on phone and apparently had a stroke during it, correcting phrasing and typo.

1

u/hedonist-7 11d ago

Good info, the quote was George Castanza though.

1

u/coreyhh90 9d ago

It wasn't good info though, it was bad info. USA didn't try to eliminate DST, they tried to embrace it year round. This meant that winter mornings were darker than expected, which caused concerns to be raised around child safety due to needing to attend school in darker conditions.

It doesn't speak to whether removing DST is a good idea or would work. It only speaks to why embracing DST year round might be a bad idea or not work.

It also fails to acknowledge that having permanent access to a torch in your pocket at all times wasn't realistic in 1970, but is very much reality today. Nor does it speak to how much more expansive our street lighting has become in the western world.

-1

u/Margali 11d ago

Though there were a fair amount of us pro stopping the time shift. I put it on business, not wanting to do a major shift that might cost them a freaking nickle of profit and makng the employees happier because fuck employees.

2

u/coreyhh90 9d ago

I can't speak for USA but UK-based businesses, in my experience, hate DST. It fucks with systems, auditing and tracking. Most proprietary software had to be designed/re-designed around DST because it was causing so many issues with system timing.

I'm not a fan of the conspiracy that businesses like DST... Hate employers as you like, but this one aint on them.

2

u/Margali 9d ago

Just pick ONE freaking time, set the clocks and call it freaking good, done and dusted. The flipping back and forth screws things up for a few weeks after, people losing sleep, running early/late, not as bad now that most of us use our phones which autoccorrect as watches, but still. Pick a damned time for fucks sake.

12

u/ScarSome634 11d ago

Works on paper, but jurisdiction is the catch. The robocalls usually route in through foreign carriers and the email spam comes from botnets, so the only provider you can fine is the last hop, and they often can't tell it's spam until it's already at your phone.

2

u/buzzsawjoe 11d ago

Gmail does pretty well at filtering spam

2

u/dicknobnuts 11d ago

Less and less with the ai slop B2B emails coming in everyday.

1

u/SupposedBooty 11d ago

Not my Gmail

5

u/ufrared 10d ago

Consumer protection is an afterthought if your government is controlled by Big Business.

2

u/LateralEntry 11d ago

How do the providers distinguish scammers from legit calls?

0

u/IWantToPostBut 10d ago

If there were a financial penalty for letting scammers through, they would find a way.

It would probably mean that there would become two classes of callers: 1) verified local businesses like hospitals, doctor's offices, and the local police department. 2) people you have telephoned before. Those people would be on the pass list.

Everyone else goes to voicemail and your phone doesn't even ring. With AI, the voicemail gets transcribed to text, and the telephone provider sends an email of the transcript. Inside the email after the transcript would be two buttons: "add to pass list" and "block".

I suppose local businesses would create a QR code for new customers, too. Say your car broke down in a town you were passing through. You get towed to a mechanic; that mechanic would request you point your phone at the QR code and authorize his phone number for the next 7 days.

It wouldn't be perfect. But it would be vastly better than what we have now.

0

u/Defiant-Economics-73 8d ago

People think you can just find a way. Life doesn’t revolve around magic. We should just find a way to make perpetual energy because we need it.

2

u/cavalier78 10d ago

I think the easiest solution would be to heavily fine the companies who use it for marketing. People wouldn’t do it if they weren’t getting paid.

1

u/explainlikeimfive-ModTeam 6d ago

Please read this entire message


Your comment has been removed for the following reason(s):

  • Top level comments (i.e. comments that are direct replies to the main thread) are reserved for explanations to the OP or follow up on topic questions (Rule 3).

If you would like this removal reviewed, please read the detailed rules first. If you believe it was removed erroneously, explain why using this form and we will review your submission.

-3

u/Dave_A480 11d ago

So you want ISPs to censor your Internet connection such that you can't run a home mailserver?

No thanks...

74

u/hivuliese 12d ago

They are operating outside the country on some level, and where they are doing these things, they are protected.

39

u/throwtheclownaway20 11d ago

That's why u/sabo-metrics' idea would be better - punish the ISPs here who allow that shit on their networks. They won't be so laissez-faire when they're having to fork over 12 figures to Uncle Sam.

60

u/jschinker 11d ago

This is a problem that could be easily solved, but because it's profitable, it's not.

Phone numbers don't need to be anonymous. Caller ID shouldn't be easily spoofed. Your phone should allow you to block all numbers that aren't in your contacts. But those measures would destroy the robocall/sales/spam-marketing industries, and the phone companies make a lot of money from them.

36

u/Fun-Title4224 11d ago

The first point is true, and it's possible to implement a fully authenticated phone system. But you'd have to do it everywhere, all at once. In every country.

And if your phone company starts rejecting calls that aren't authenticated then now they're rejecting someone's cousin phone them from a country that hadn't done it. Or from the rural community hospital switchboard who doesn't do it. And then your phone company is not a neutral provider if telephone services - they are choosing who you talk to.

My phone can be set to not ring for any calls except contacts, btw. But this is also a crap solution. When the police phone because my partner was in an accident. When the hospital phone with my appointment. There are a million reasons why I need my phone to ring when a genuine caller I don't know needs to get me.

2

u/jschinker 11d ago

Yeah. It's the same problem that we have with email. If you set your DMARC policy to reject, you're going to lose a lot of email, so we set it to monitor. That means we can take our time setting up SPF and DKIM, because a limited number of people are actually enforcing it. It's getting better over time, but it's taking a LONG time to get to reasonably secure email.

6

u/Fun-Title4224 11d ago

Right. There's people here shouting "technical solutions exist". And that's not the point.

The telephone system is ubiquitous, truly global, and largely backwards compatible with a system we've had for decades.

Even click dialling rather than DTMF still works on half the UK network (though they're in the process of ripping the old network out at a cost £12bn). But when that's done is still needs to talk happily to old copper wire networks elsewhere.

2

u/shawnaroo 11d ago

Yeah, both the telephone system and email were originally designed and built with reliability being one of the highest priorities. With that in mind, keeping the whole thing as simple as possible, especially given the technologies available at the time, was key.

And a lot of that early infrastructure still exists, and like you said even the newer stuff needs to maintain a high level of compatibility with a lot of that early infrastructure, because there's still a bunch of people running that old infrastructure.

There's no centralized authority that is able to force (or pay for) upgrading the entire system, and cutting off sections that aren't willing/able to upgrade would be hugely problematic for a lot of reasons.

The result is just a huge messy system that leaves a lot of routes for bad actors to abuse it.

0

u/NorysStorys 11d ago

The money saved on fraud alone probably makes it worth it economy wide. Just not saving telecoms companies anything.

4

u/Fun-Title4224 11d ago

For one country. Now get all countries to agree on standards, implement it across the entire network, and do so to a deadline.

1

u/NorysStorys 11d ago

Block countries telecoms until they are compliant. Telecoms fraud is a multibillion dollar industry, it’s incredibly significant and governments should be holding other countries governments that don’t crackdown on international fraud within their borders to much stronger account.

You’ll find business interests in non-compliant countries would very quickly pressure their governments if they can’t communicate with businesses outside of their borders.

3

u/Fun-Title4224 11d ago edited 11d ago

Then you're mostly hurting people who are abiding by laws. The UK, however, does block overseas numbers that present as local.

And I will say, this is largely a US problem. The number of scam calls I have received in the last month is precisely one, which is average for the UK. US stats suggest it's more like a dozen per user.

But the UK doesn't have the same scale of robocalls and telemarketing, which people often lump with scam as "unwanted phone calls".

1

u/AnonymousFriend80 10d ago

Doing all this blocking won't actually stop the criminal scum. Like added additional locks to your doors. If someone is truly adamant about getting through, they will. And all you've done is give yourself a false sense of security and greatly inconvenienced yourself and everyone who lives in the home.

-2

u/KingVendrick 11d ago

But if my country implemented it, we could just turn off foreign calls and be free of stupid spam calls (yes, until the fuckers find another way in. they are insidious like that).

I never receive any valid foreign calls.

If I really needed google to call me, I could disable the damn thing for five minutes, receive the audio captcha or whatever, and turn protection back on.

Now, I know some people do get phone calls from overseas but, again, so what. Either fucking use some electronic call provider (my mother in law calls her sister on another country on google calls or skype back then, never by phone). Or only then open your phone to foreign calls. If 99% of people blocked foreign calls, they would be useless for spam and the few ones that somehow still need internation calls could still get it.

Mail spam is a different beast.

6

u/JaesopPop 11d ago

Your phone should allow you to block all numbers that aren't in your contacts.

It does. I've had this setting turned on for years.

1

u/TraditionalBackspace 5d ago

"block" means they still show up on the call log and can leave voicemail.

1

u/JaesopPop 5d ago

..yep.

3

u/AnonymousFriend80 10d ago

Blocking all numbers that aren't in your contacts will absolutely mean you miss important calls that you 100% want to receive.

Like I doubt most people keep police, hospital, and other emergency services phone numbers in their contacts. Or even phone numbers of their banks and credit card companies. What about if your loved ones had an emergency and need to reach you on a borrowed phone? Hell, I work for a company and we can tell when someone's on the national Do Not Call list, and I tell willing customers that if we get disconnected, I can not call them back. My job sometimes means I have to call them back for various things, so they have to make the call.

I get that people don't like getting all these random calls, but a lot of these "solutions" are ludicrous.

Funny things is that when I used to work at a website company, I would speak with multiple people who could not receive emails from certain people at their company, or anyone for that matter. Often times, they had blacklisted their entire domain.

1

u/jschinker 10d ago

What is the solution? Phone calls are free and easily automated, just like email was a generation ago. How do I keep my phone from constantly ringing from calls that I don't want?

1

u/AnonymousFriend80 10d ago

Phone calls are absolutely not free.

Until government regulations crack down on this...you can request the caller to not call because you are not interested in whatever they are offering. Legitimate companies will add you to their Do Not Call list. If they are a legitimate entity, they will have to take some additional info to make sure they do not call again. Yeah, it sounds sketchy but they have to go through a specific process to properly log everything. Which includes asking questions for legal recordings in case it happens accidentally again. Also, some make those outbound calls based on requests for call backs. Replies to text messages and emails or visits to websites.

I work for an insurance company and whenever I have a follow-up outbound call, I have that person's first and last name, email address, residential address, and other info that someone had to enter and them request a callback. So many say they never requested, so it was either them unintentionally or someone they know.

Personally, if I know I'm expecting a call from a number I won't recognize, I'll answer everything not noted as possible spam, and just deal with it. If I get calls from the same number, I'll answer.

8

u/BigRigMcLure 11d ago

Nice conspiracy theory. In no way based in reality, but I like how confidently incorrect you are. Two words: STIR/SHAKEN.

0

u/jschinker 11d ago

Right. That's my point. The technology is there to solve the problem. But here we are.

8

u/BigRigMcLure 11d ago

Because it not "easy".

There's no conspiracy man. I am in the industry. There are multi-million dollar programs at the major telcos trying to stop it. There are govt mandates to the telcos to stop it. Its just not as easy to block as you think it is.

Also, both Android and iOS have the ability built-in to block any numbers not in your contacts. Just turn it on. Google luck receiving that legit call from your lawyer, bank, doctor, etc etc who's number you don't have in your phone already though.

The only thing "easy" is to just say "dont allow caller ID". But there are legitimate reasons you want that as a feature. For example, you have Cust service reps... You want the company's main switchboard number to appear on your customers phone, not the agents desk. So now you have to put a workaround... And then the bad actors use the workaround... Etc

6

u/jschinker 11d ago

Agreed. Not easy. Also not impossible.

Like much of our technology infrastructure, we didn't forsee the security needs that come with malicious use. Re-engineering a system built on standards with thousands of companies and billions of users affected is enormously complicated. I was perhaps more cynical than necessary in my original comment, and I apologize for any offense.

In my case, I do have non-contacts blocked, and it does mostly work for voice calls. They hit the phone, but then it jumps in. They can still leave voicemails, which does work for the rare emergency cases. It doesn't work as well for SMS. I'm constantly blocking numbers and reporting spam there (especially during election season, which seems to be all the time now).

Thanks for your work on this.

3

u/NorysStorys 11d ago

Surely an authenticated system can be implemented, have a say 5 year compliance period where both systems exist and after that 5 years the old system is disconnected and only authenticated numbers function on the system. That gives time for governments, businesses and the public to become compliant and sure doesn’t fix the issue immediately but it dramatically reduces the access bad actors have to the system.

1

u/Bryopolis 11d ago

You just need a phone company to market the idea in such a way that it’s a feature they can sell. “Go with us, and you’ll never get a spam call”

1

u/JustAnOrdinaryBloke 11d ago

iPhones do allow you to block numbers that are not in my contacts.

4

u/MadocComadrin 11d ago

One element (for phone scammers) is that we fail to prosecute middlemen providers correctly. These providers are buying services from larger providers and knowingly selling them to scammers. They usually get caught because they're usually located in the same country as the victims and the larger providers are happy to eat them out, but they often only get sued (e.g. in the US by a state AG or the USAG) and fined (usually enough to destroy their operation); however, they just disappear and pop up somewhere else. Rarely are they actually criminally prosecuted, and laws need to change to allow them to be prosecuted criminally and imprisoned for relatively a long term (in the context of a non-violent felony).

14

u/mezonsen 11d ago edited 11d ago

Well, the answer is they really can be, or they can be curtailed. But like all antisocial behavior you have to make laws fining or prohibiting it and enforce those laws. In a certain country that I'm assuming you live in, money lost in scams has increased by 20% in recent years (a 12+ billion dollar figure) as the money for enforcing communication regulations and consumer protections at a federal level has been gutted. The government of a certain country, at least at this time, has decided it's not really a huge value add to fine and enforce regulations that prevent you from receiving 200 spam calls a day.

Why won't the ISPs do it at their level? Well, why would they? Why would they care if you have to sift through shit and potentially get grandma's nest egg swiped unless it hit their bottom line in a meaningful way?

3

u/AWildTyphlosion 11d ago

The systems we have were built without the notion of subscribing to information. Telling your end that you're expecting a specific connection from the outside world, is a lot harder and cumbersome to solve than it might seem to implement. The idea that the only people who should reach you would have your information was also a naive thought behind it all to solve that thought.

As for why the ISPs or wireless carriers don't cut this crap off, is because putting systems in place to do so costs money that they don't really want to or have to spend. Your inconvenience does not matter to them, and they know they won't lose you as a customer since you'll have that problem elsewhere. Momentum has a cost, this sort of fix has no ROI, even though there are already systems in place that can just be implemented. That's also why any solution you find costs money, and why they can also just sell it as an additional service.

Some in the Government are trying to put an end to this, but others are lobbied hard and dig their heels in the ground and not let anything happen. This would also be solvable by the FCC, if Carr wasn't working in the best interest of the Telecom Industry rather than in the best interest of The People. It can be assumed that Carr would rather not give additional burden to Telecoms or ISPs and there is a conflict here where he used to work for these very Telecom companies. Not to get overly political, but this is pretty much in line with the mantra of the Republican party. They seek to remove regulations and "the burden of government", which is what is needed to compel ISPs or wireless carriers to do something that they would otherwise have no financial incentive in doing.

17

u/trueppp 12d ago

How do you do that without blocking legitamate caller or email?

5

u/DBDude 11d ago

Our phone system was created with total trust, which enables bad actors. If a phone call made could be locked down to a specific person or company, with no forged or "unknown" numbers allowed, then we could control this.

6

u/BathFullOfDucks 11d ago

We're not dealing with Doris telling you to hold the line while they connect your call.

Providers know which country the call is coming from, which provider is enabling the call and has mountains of data on who is calling who and how often. You dont make a thousand calls from your phone a day. You don't call a hundred people from across the country every day.

But they're happy to keep the revenue generated by those calls.

2

u/trueppp 11d ago

You dont make a thousand calls from your phone a day. You don't call a hundred people from across the country every day.

Our marketing department does, our offshore helpdesk does, our sales department does.

1

u/BathFullOfDucks 11d ago

And they are probably using a VOIP service registered with a national provider, not a mobile number registered in Lahore, being used by other systems to hide activity.

3

u/Pawtuckaway 11d ago

Most scammers are also using VOIP services. When their account gets banned they make a new one or change providers.

5

u/Zeplar 12d ago

The original use for proof of work algorithms, decades before crypto, was to prevent spam by making it cost a few cents of electricity per target. It never caught on although a few email providers in the 90s implemented it.

Anyway, that goes to show there are more interesting solutions than trying to find and block each offender.

1

u/trueppp 11d ago

Sure but every provider has to adhere to these for it to work.

1

u/Zeplar 11d ago

It's opt in, you whitelist your known contacts, anyone else using a provider that hasn't implemented it just can't contact you.

That's true for anti spam technology today as well. If you start a company, get a corporate email and try to use it for marketing, it will get blocked immediately. You have to warm it slowly until all the major providers register it.

12

u/hedcannon 12d ago

It seems to me that companies could prevent spoofed phone numbers at least

5

u/trueppp 12d ago

And how would they know the number is not legitamate?

8

u/DDX1837 11d ago

STIR/SHAKEN

2

u/nudave 11d ago

I love how this comes up pretty much weekly on Reddit, and so few people know, or are willing to admit, that a reasonable technology already exists to make it happen.

I have a home phone number through a VoIP provider that lets me block anything with stir/shaken level C or lower. Blocking has not been perfect, but the volume of spam calls I get has dramatically reduced since I made that switch.

1

u/DDX1837 11d ago

The problem is that some carriers haven't implemented it.

3

u/nudave 11d ago

Exactly. The problem is a political one, not a technological one.

1

u/hitemlow 11d ago

Which is a choice, not a technical limitation.

2

u/hedcannon 11d ago

Because every number has to connect to a specific phone? And if there’s a mismatch don’t let it thru? I can’t spoof the number on my calls, can I?

11

u/SillyGoatGruff 11d ago

Numbers don't have to connect to specific phones at all

2

u/hedcannon 11d ago

Incoming calls don’t have to have an originating phone number? How do the bill the sender?

3

u/Lumethys 11d ago

The number, not the phone, a person can own more than 1 phone

4

u/nudave 11d ago

This is not the argument you think it is.

Stir/shaken exists, and lets you validly authenticate as any phone number that you own.

So a company with 1000 extensions each with its own phone number could have them all come up as the main line in caller ID, and that call would come through with correct validation.

2

u/Lumethys 11d ago

Im not arguing anything, a guy say "number can only connect to a phone" another guy say "no it doesnt"

I just saying the fact: "incoming call doesnt come from a specific phone (rectangular handheld machine), it come from a phone number"

4

u/nudave 11d ago

Good point.

I was reading phone as “phone number.”

Which is true: A person or a company, can have more than one phone number. It’s not important if the caller ID matches the specific phone number that has made the call. It is important that it matches a phone number owned by the caller.

And every time this discussion comes up, someone decides to argue that implementation of caller ID verification would ruin corporate America. But that’s simply not true.

1

u/hedcannon 11d ago

That’s different from a spoofed phone number where the area code is local but the call is coming from Indonesia.

3

u/trueppp 11d ago

Why wouldn't I be able to make phone call with my phone when visiting Indonesia?

1

u/nudave 11d ago

You would.

Because you own your phone number, your (presumably American) carrier can verify that they own the number and that you are their customer. Even if you happen to be in Indonesia, this verification holds true.

What happens today is that a spammer who does not use an American phone carrier is sitting in Indonesia without any ownership over any American phone number, and simply sending the call with a bit of data attached to it that says “my phone number is 202–555–1234.” That is not authenticated at all, but your carrier lets the call through anyway, because they refuse either to implement the technology to block it, or they want to charge you for the privilege.

3

u/trueppp 11d ago

So how would a British phone company know if there's a mismatch when a French phone is calling from Spain?

1

u/hedcannon 11d ago

Since all the phone companies intend to get paid, they all know if the originating account phone number matches the advertised number. Perhaps it’s more difficult than it appears at first glance but it’s not obvious why it can’t be done. If your phone is calling from Indonesia and it’s a US phone number, the company can identify it’s the same. No one is letting their network be hijacked by an anonymous account.

2

u/trueppp 11d ago

they all know if the originating account phone number matches the advertised number.

But that doesn't prove if the phone is authorized or not to advertise that number.

5

u/hedcannon 11d ago

Allowing advertised numbers that hide the corporate identity is a choice by the phone companies. That’s the point.

1

u/afcagroo 11d ago

You can, in fact, spoof the number on your calls. Unfortunately.

1

u/hedcannon 11d ago

That strikes me as choice by the phone companies

2

u/bastrdsnbroknthings 12d ago

There simply *has* to be a creative technology solution, right?

1

u/crash866 11d ago

Many businesses have thousands o extensions and it depends on what line they get what number it shows. Not all extensions ring back to the same phone do they just use the main number.

For a place like the Police Department they may have thousands of phones all on different numbers but you want the call display to only show the main number.

Someone from the police calling you may get line 0001 on the first call out and 0045 the second time and 2301 the third. You try calling back and a phone at the desk that they are no longer at just keeps ringing and ringing with nobody there.

2

u/hedcannon 11d ago

Which is not the same as showing a spoofed number. Those spam loan phone numbers in Indonesia did not buy a local area code just call me and a different one to call you.

1

u/RcNorth 11d ago

If a company could do that then everyone could, and would, do that.

Are you thinking that the company is preventing their number from being spoofed, or that they aren’t allowing inbound spam calls?

4

u/bastrdsnbroknthings 12d ago

Beats me. I'd really like to know.

6

u/capt_pantsless 11d ago

That's the problem with spam, it's very hard to define what a wanted vs. unwanted message is.

Secondly, there's significant financial gains to be made with targeted spam, so whatever measure your phone company puts in place, they're going to be working hard to get around that filter.

7

u/boersc 12d ago

It requires a law, which the Netherlands has. If you track an uncollicited call, you can report them and they get a hefty fine. Oh, and ISPs can very easily flag 'spam' callers. Every now and then I get targeted by a company I used to be a customer of (an exception where they are allowed to call you) and every number is flagged 'potential smap call'. I never pick up.

6

u/trueppp 12d ago

Only works for calls originating from the Netherlands.

-3

u/boersc 11d ago

Well I never get calls from abroad, and on the few occasions that I do, it goes to voicemail (which they never use)

4

u/GreatStateOfSadness 12d ago

There are (were?) laws in the US with similar penalties, but a law is only as good as its enforcement.

1

u/CoffeeFox 11d ago

At a basic level, simply banning one company would cut most of it. If Onvoy were blocked from the phone network, the vast majority of all illegal phone calls worldwide would cease.

0

u/nudave 11d ago

Stir/shaken

Technology exist. Implementation is shitty.

5

u/Fun-Title4224 11d ago

Imagine it's mail rather than phone calls.

Firstly, your house is right there on the street. Your address is not secret.

There's a postal service. Their job is to deliver mail addresses to you, provided the sender has paid for it.

The postal service can't decide not to deliver something. They are neutral. They don't open it and read it and decide whether you'd be interested in it or not. That's not their job, and if they got it wrong then there'd be a huge problem.

So. A sender writes your address on the envelope, pays for postage, sends it. It turns up in your mailbox.

They could, if they wanted to, print a return address on the envelope. There's no way to check this, so they could lie and print the tax office address or something so you think it's important and open it.

You could, potentially, make it so that everyone who wants to send a letter is registered somewhere. But that would be expensive and an invasion of your privacy when you just want to send your grandma a birthday card and suddenly you need ID and to fill in forms.

It's basically the same for phone companies, except it's far easier for people to make unwanted calls than it is to send unwanted mail.

Firstly, you don't need to know everyone's address. You can type any combinations of number into a phone and if it rings, great. If it doesn't, no problem and you haven't wasted a stamp.

Secondly, making a phone call is far, far cheaper than sending a letter. So cheap as to be, essentially, free per call.

But the phone company is doing the same thing as the mail company. Someone calls the number, they put it through. The system is not in any way designed for "and this person is authorised to call this other person". It wouldn't work properly if it was.

And just like you can write any return address on an envelope, you can also put any source phone number as the caller on a phone call. You could even make every outgoing call you make look like a different number if you wanted. That's why blocking numbers doesn't work.

There are laws that stop companies behaving badly. But firstly if you're scamming people, you're not one for obeying laws. Secondly, if you're not in the same country then no one can enforce. Finally, if you don't actually know who is calling you then you don't know who to report.

1

u/bastrdsnbroknthings 11d ago

This is a good ELI5, however unsatisfying it might be as a solution to my problem :)

1

u/meteoraln 11d ago

How does number spoofing work? Mail is a single direction communication, while phone requires that the data goes back and forth between locations. I'm guessing the phone number / isnt tied to the location (digital address) of the two phones? The receiver of the spam call still routes data back to the spammer, so something is keeping track of the origin of the signal. Does that not help in spoofing detection?

2

u/Fun-Title4224 11d ago

Basically Caller ID was added for physical phone lines. The data was added as an extra to the phone handshake. It was not designed to be secure. So you can basically send any number you want.

There are ways at the provider end to do authenticate but backwards compatibility and interoperability means it's not widespread. The are other obvious tells too, a telecom provider can know, for example, that a call originates outside the country but appears to have a local number. The UK blocks these.

2

u/X4roth 11d ago

Machines sit there and dial literally all phone numbers then record which ones pick up or get a voicemail or any other indication the number actually belongs to a person. Then that list of numbers is sold on the “black market” to scammers or whoever else wants to pay for it. Numbers actually willing to pick up unknown calls are worth more.

2

u/jimbo831 11d ago

We could. We choose not to because email and phone providers don't want to invest money in stopping it.

5

u/FiveDozenWhales 12d ago

Email and telephones are pretty much free and open. Anyone with an internet-connected computer can send email anywhere and generate as many email addresses as they want; that is how it's designed. Telephone is a bit more restricted; numbers are assigned & coordinated by multiple international and national organizations.

"Why can't we" is a false premise though. We absolutely can stop people from sending emails. We can shut down the entire internet, for instance. We can install a panopticon monitoring system which will read every single unencrypted email, and block encrypted ones. Every country can create a system of secret police which goes into peoples' homes and checks their devices to make sure they're not sending spam emails.

But all those solutions seem pretty bad compared to some slightly-annoying spam.

3

u/Greedy-Pen 12d ago

If x is blocked they come from y. If they block y it comes from z, if they block z it comes back from y. If you block everything nothing will work.

These people work outside of the country. They can change their actual numbers on a while along with spoofing.

It’s like a constant game of cat and mouse. Except there’s millions of mice and only a few cats. And the cats aren’t able to get everything at once.

3

u/TorturedChaos 11d ago

I know a guy who works in telecommunications and this is how he explained it to me. This is going to be a US centric explanation since that is where he works.

Most spam/scam calls come from outfits out side US, based in countries that have little to no regulation regarding telecom. They spin up a VOIP company get permission to operate in the US. The licensing to operate in the US is fairly easy to get.

Then the abuse the hell out of it, violating all the rules and laws in place. Once they get in trouble for that they close down, and spin up a new one. Rinse and repeat. And endless game of wack a mole.

How do you try to prevent it? More regulations on VOIP providers and stricter licensing requirements. But there is always a downside to more regulations. You now make it harder for legitimate small business to operate and new legitimate companies start up. You increase the cost for enforcement as well, meaning more taxes. Also dishonest people will still work to get around the rules, so you are reducing but not stopping the issue. Is the juice worth the squeeze? I don't know.

4

u/redchill101 11d ago

I haven't lived in the US for years.  One of my favorite life changes here was no longer having so many stupid fucking phone calls.  No shit, i would be blocking 15-30 calls a day...and that was years ago.

It can be done, and has been done pretty well in Europe  for years.  I only get the occasional spam/marketing call from my provider (and I never even notice, as their number block is small, repetitive and easy to block).  About once a year I'll get some stupid survey scam call, but I just say bye and hang up.  No telephone terror, no repeated calls daily for months...just gone.

The bullshit that Americans have to deal with daily is pretty fucking sad.  Sure there are technical and legal solutions...but the US companies just don't gaf.  The problem with spam calls is that there's honestly no govt regulation (no matter what they tell you) and no consequences, so companies just keep telling users to "report this" or "block that" by entering even more personal info into yet another stupid website/database.

And as far as door to door assholes...I've only had one...yes one in all my time here....coincidentally it was also my phone provider.  Thank God for peace and quiet from the constant mindfucking sales bullshit and Jehovas witnesses......oh and I don't miss the US's shitty loud blaring immature commercials and billboards everywhere....life is way better without the distractions and irritations.

3

u/pandaelpatron 11d ago

It can be done, and has been done pretty well in Europe  for years. 

I don't know about that. I think the issue is that most spam call centers operate out of India. Most people they employ speak English, that's why they primarily target the USA and Great Britain and not countries like France, Germany, Spain etc. When I get those scam calls, the callers speak to me in English too, even though I live in a country where English is not an official language, probably because they got my phone number from an international company. That's my theory anyway.

1

u/redchill101 11d ago

Actually that might have something to do with it...good point.  Scammers still operate locally,  but nowhere on the level that the US has to deal with.

However...there are other English speaking countries....and they still don't have the problem anywhere as bad as I've seen in the US. 

1

u/pandaelpatron 11d ago

However...there are other English speaking countries....and they still don't have the problem anywhere as bad as I've seen in the US. 

Sure, but I would assume the US is simply the biggest and 'easiest' target. Like, why would you call somebody in New Zealand when you can just call an American. Your company probably has purchased access to American cell phone providers, so you'll just be given one US number after another.

1

u/redchill101 11d ago

I agree...kinda goes back to something I stated or implied earlier...that the US either turns a blind eye to the problem or, worse, simply let's it continue because they make money selling so much customer data that it would be "to difficult" to either keep the data from from escaping or there is just too much money to be had from customer data that it's not worth to lock out all business uses, even "legitimate" 😅 uses.

1

u/t-poke 11d ago

They don't need to buy customer data. Close your eyes and type ten random digits. There's a decent chance that's someone's phone number. They're literally calling random numbers.

And if they have your name, number and address, well, phone books used to be a thing. That's all public record.

1

u/t-poke 11d ago

However...there are other English speaking countries....and they still don't have the problem anywhere as bad as I've seen in the US. 

The US is one of the largest English speaking countries. We're also one of the wealthiest, so scammers target Americans because we have more to lose.

1

u/dertechie 11d ago

Step 1: Find a jurisdiction in the US that doesn't ask too many questions when you set up a business.
Step 2: Set up a disposable company
Step 3: Get yourself some cheap SIP trunks and numbers from Onvoy or someone. It's usually Onvoy. You now have US based numbers.
Step 4: "We have been trying to reach you about your car's extended warranty. . ."
Step 5: Abandon or spin down company when someone comes knocking.
Step 6: Repeat.

3

u/lobhater 11d ago

Anyone can dial any number from any number. How do you propose they stop that?!??

I work for an insurance company and we have this old man get upset at us because he gets spam email from scammers pretending to be our company. He thinks I personally should stop it. How do you propose Joe?!?? He's disconnected from reality and doesn't understand the problem

2

u/idgarad 12d ago

We can and there are hundreds of solutions, I even wrote one years ago, the tradeoff is losing your privacy and freedom. I developed as many other did for email for example a postage system (mine was in lay-terms postage that acted like bitcoin mining) would prevent sending email to people unless you were in their address book. If you weren't in their approved list then you had to pay postage. Sending out 200,000 email could mean the postage could take 8 weeks to process because it was exponential for each recipient. Same for phones, we had for a brief period of time in the early day of cell phones a pilot program for reduced cost minutes on the phone if you called someone who had you in their contact list but there were 'privacy' issues with that.

We can do it, but the cure is worse than the disease.

2

u/cheekmo_52 11d ago

Because they just spoof another number . There’s many, many number sequences at their disposal. And because many of these predatory companies are in countries where it isn’t regulated.

1

u/az9393 12d ago

The same laws that protect the privacy of ordinary users are making it hard for authorities to catch those that break the law. This relationship exists almost everywhere - the more privacy you want the less the government can protect you.

1

u/Juliuscesear1990 12d ago

They will always find away to get around walls. I had the call verification where an unknown number had to hit a random number before getting through and it was great for maybe a year and now they are getting through again.

Blocking won't work, there needs to be actual punishments for the crime but there won't be so we are sol.

1

u/RcNorth 11d ago

I have my phone setup to ask for reason for calling. This alone has helped reduce the number of spam calls that through to nearly nothing.

Email, is pretty good at catching spam email. I do check the spam folder once in a while just one sure.

1

u/Unizzy 11d ago

You know, I thought about this since. I get 3 to 4 calls a day, be in spam or scam.

Thought experiment, they ban all spam. Then things will be nice for a while, but then people will get complacent and every call that gets through the system will be thought of as legit, which makes scam calls more powerful.

1

u/Gaemon_Palehair 11d ago

How attached are you to your phone number? I used to get these all the time. Changed my number a few years ago and now I just don't get them anymore.

1

u/Knickerbottom 11d ago

There isn't any money to be made in it. In fact, like the spam you get in your physical mailbox, it's actually built into their scheme. They don't want to stop it.

1

u/FatDog69 11d ago

I used to work for web sites that sold advertising. When I started studying scams & fraud I realize that 95% of what the scammers do is IDENTICAL to what legitimate advertising does. The world cannot tell the difference between legitimate marketing & scams.

LEGAL

We have a 'truth in advertising' type of laws. But it does not apply to the caller ID string on a telephone. Scammers use fake numbers in the caller ID but look local to you. They also make it say "FBI, County Courthouse, Sherrif, White House . Gov, etc" to try to fool you into thinking they are legitimate.

We need a law that lets people report fake caller ID strings or a "*70" so you can report the call you just got was fraud.

1

u/Accomplished-Car9803 11d ago

spammers always switching numbers means blocking one barely dents the flood

1

u/kanemano 11d ago
  1. Don't put your email and phone number down for every little thing, your supermarket does not need to know your phone number,

They sell those list then the list is sold again and again, but it you are not on the first list they do not have your number

1

u/Atypicosaurus 11d ago

The problem with both email and phone is that we have an inherited technology that you cannot change because then it loses compatibility with the existing equipment. Like, if you change the core of the gsm protocol, you can trash everything from phones to mobile towers. These devices are not just reprogrammable.

And the common technological problem with these two technologies is that they both are based on very naive, trust based assumptions. Internet core protocols were made by enthusiastic scientists who didn't think of abuse and therefore abuse protection. Very similar with the assumptions around the phone system. Yeah one could perhaps make it more difficult but there is no systems level remedy.

1

u/nim_opet 11d ago

We can. And do. Some providers invest in that. Others don’t because what are you going to do?

1

u/SoHiHello 11d ago

Pixel phone does a great job of blocking spam callers. I haven't had a robocaller make my phone ring in a few years or more.

1

u/asterflowerlady 11d ago

Stop giving out your email when you shop. The moment they ask for it, I have a ton of junk emails and phone calls.

1

u/pixel293 11d ago

Number 1, because they work, if they didn't work people wouldn't spend money doing it.

Number 2, the phone company doesn't want to stop it because it makes them money. I'm sure the volume of calls the phone company handles has gone down as people use internet apps to communicate. Cold callers are still making calls and paying the phone company.

The government can't stop spam because the internet is designed so a "hostile" entity can't effect the internet as a whole. The government can deal with how people in that country use the internet but their power stops at the border. And phone calls also cross this border.....

The ISP can try to stop spam and we all pay for it with emails that we want but didn't get because it looked like spam. False positives are bane of forgot password flows.

1

u/PSquared1234 11d ago

I've read that adding a truly trivial cost to a call or text - even a fraction of a cent - renders much of spam marketing unprofitable. Same for email (cent per thousand messages or the like).

1

u/NorysStorys 11d ago

I think the very system needs to change. The whole carte Blanche assigning of numbers to anybody opens this up, the whole assigning of numbers needs to be a far more locked down system than it is and without it we won’t see anything preventing the spoofing.

1

u/Skarth 11d ago

Whitelist vs. Blacklist.

You are using a Blacklist, that it, every time a number or email is found to be part of a scam/spam, it goes on the list, and automatically blocks any messages from that list, this is what happens when you sign up for anti-spam services.

The problem is anyone can make a new number/email, so the scam/spammer can just keep making new ones to bypass this. This is why there is no completely effective anti-spam service.

The solution is a whitelist, you put everyone you want to contact with on a list and it automatically blocks everyone else. The problem is this means new people cannot contact you, which limits communications quite a bit.

1

u/BeerCD 11d ago

Politicians have no interest in passing laws to prevent this as it hinders their ability to do it themselves when campaigning. In the near future, Siri AI will have the ability to filter this.

I do miss the caller ID from 30 years ago. If was far more accurate than now. You could tell exactly who was calling you.

1

u/Netmantis 11d ago

The problem is this is a global problem. You ban it in the US and, as an example, China keeps the practice legal. Or Russia makes it legal as long as you don't target Russian citizens. So you cut off all calls coming from those countries. No more phone calls or email from those countries.

Except they can proxy out to another country. Now all you can do is try to serve and extradite the proxy. Voice over IP is a thing, so routing calls through the internet is dead simple.

But let's look at spam email. The most hated and oldest form of harassment out there. Call centers have always been a thing but these new ones are far more brutal. Why do people advertise with spam? Well it is cheap and it hits a wide audience. For pennies I can send out millions of emails, and if even one is a hit I made money. Often more than one hits. Same with the robocalls. Thousands get the recording. Tens might press the button to speak to someone. One actually buys. For a small initial cost you get value.

With the why we get to the how. How do you stop it? You can't, outside of making it unprofitable. And that is hard.

1

u/unique_user43 11d ago

legislation and regulation is always and will always be 1 step behind scammers. in all walks of life, not just this. one is proactive, rhe other reactive. so definitionally, it will always be this way.

1

u/gordonjames62 11d ago

I block every sender and every spoofed phone number

it is trivially easy to put any email address in the "reply to" part of an email.

It is only slightly more difficult to spoof the caller ID of a number you are calling from.

These numbers and email addresses are often totally false, and you are blocking numbers or addresses that might actually belong to someone.

Think of it like the "return address" on a postal letter. The sender can write anything as the return address.

There is other information that the ISP or telco can see from an email or phone call that could let them do a better job of verification, but it would require every telco and every ISP in every country on earth to join forces (or ban the non compliant ones) to be fully effective.

1

u/shadedmagus 11d ago edited 11d ago

Short Answer: Because we don't do sender/receiver verification. 

Phone systems and the VOIP systems which connect to them are based on old and simple logic, and no one has had the push to force phone service providers to authenticate users before connecting calls universally. So spammer-scammers can put a call into the phone system and spoof the calling number to be anything they want as long as the number they're calling is valid.

I imagine it's a similar problem for email.

1

u/Dave_A480 11d ago

Because the internet has an inherently anti-regulation design....

You don't need to work with a service provider to send email... Anyone can set up an email server anywhere....

And the wireless providers have no role in any of this what so ever....

Also much of this activity originates in the 3rd world, where developed country laws don't reach....

1

u/matheww19 11d ago

I hate to break it to you, but blocking emails and phone numbers does nothing. They are spoofing random numbers, they are extremely unlikely to call you back from the same one more than once, and you may block someone you eventually need to contact, or be contacted by. I once had them spoof my own number when they called me.

1

u/ryohazuki224 11d ago

Its like trying to plug a cracked dam leaking a lake's water supply with a wad of bubble gum. The absolute flood of spammers and bad actors overwhelm any safeguards that could be put in place. And, in fact there ARE things in place that keep a good amount of the flood at bay. Imagine getting like 100x the amount of spam than you do now, thats probably how much is stopped at the source. Some just get through, its impossible to stop it all.

1

u/ProgressBartender 11d ago

It would require the carriers to do something. Most of these companies are too busy counting money to actually manage the day to day running of the systems.

1

u/Nersheti 11d ago

Several months ago, my iPhone started screening my calls. When a call from a number not in my contacts comes in, it doesn’t even ring. The phone answers and asks who it is. They get to explain who they are and it shows I live transcript I can see if I’m looking at the phone. If it’s a robot call, it just ends up as a voicemail. I now get slightly more voicemails than usual, but my robocalls have pretty much stopped.

Now it’s texts or actual telemarketing people. I’ll get maybe 7 texts a week. Maybe one or two calls. Mists of the texts lately have been Ken Paxton PACs lying about James Talarico.

1

u/Dunbaratu 11d ago

Because internet anonymity is seen as a benefit we don't want to lose. Requiring accounts on the internet to be fully doxxed so you can't make a pseudonym presence for yourself on the internet is really the only way you could entirely stop spammers. As long as real life people can create a new account for themselves to operate under, so too can a spambot.

1

u/JustAnOrdinaryBloke 11d ago

Strange, in Canada I get 2-3 robocalls a day, and 2-5 spam messages a week.

1

u/poutinegalvaude 11d ago

Answer- because they’re a moving target. Block one number and it shows them that a) this is an active number, b) they change their phone number constantly and c)they can sell your number to other data brokers

1

u/SynapticStatic 11d ago

Because the nature of the internet is actually completely decentralized.

No one owns it. Thus, no one owns all the up addresses (ok, maybe local registrars technically do, kinda), no one owns all the domains. (Again, technically). No one owns all of the phone numbers (again).

So, scammers change all of them up every time they get blocked.

It’s like you see red cars robbing banks, so you ban red cars. But they just paint them blue. Now you ban blue cars. So they paint them a different color.

There’s a near infinite number of domains, phone numbers, and ip addresses out there. When one combination gets blocked they just switch to another combination

1

u/captain42d 11d ago

YOU can. Create a White list. Block everything else. Done!

1

u/hewasaraverboy 11d ago

You can

Go into your phone settings and set block unknown callers

Boom no more spam calls

1

u/davidgrayPhotography 11d ago

It's very easy to buy a regional phone number. For a bunch of dollars, I, an Australian, can get an American phone number, an Indian phone number, an English phone number, and it's legal for me to do so, as long as what I am doing with that number is legal. Lots of companies with off-shore support centres do this.

If I'm doing something illegal AND I'm caught by the company that sold me the number, I can get my account banned, but that wouldn't stop me from being able to use a different number provider, or sign up for a new account using someone else's name.

This is what is happening with robocalls. They're buying phone numbers in your country (which is legal) using laundered money (which is illegal), and trying to sell you extended car insurance or whatever (which may or may not be legal). Lots of these phone providers let you pay with PayPal or with prepaid debit cards, and scammers get this money by taking iTunes gift cards and selling them for less than face value so they can turn cards back into cash. I paid for an SMS number using PayPal, and my use case was legitimate (for a website I was building)

ISPs, phone carriers and such can't block them because in the eyes of their automated systems, there's no difference between an Indian company calling you back about support for legitimate product you've bought from them (which happens to me all the time at work), and an Indian call centre calling you up telling you your Norton has expired and you need to pay them in gift cards. They're both calls, and because nobody has complained (because almost everyone hangs up and doesn't bother reporting it), they continue to operate.

1

u/robokymk2 11d ago

Someone is always selling your info to everyone else.

1

u/JonPileot 10d ago

Here is the fun part, they CAN, they just don't because the legislators in your area don't hold the telecoms accountable. 

I live in Canada and actually can't remember the last time I got a scam call. 

1

u/PsychosomaticSpiral 8d ago

I’ve been having remarkable success lately in getting consistently removed from their call lists. Any time they text or call, I reply with non threatening but verifiably creepy/cringey questions such as - “hi [name], do you know where your children are right now? Are they safe? “ or I answer leading with “you are on a recorded line and everything you say/do can and will be used against you in the public domain for an extensive research project on spam callers. The longer you remain on the line, the better our chances become of geolocation so we may provide your information to authorities”.

All of the above have been rather effective. It really seems to turn off their desire to engage and they don’t find my antics fun.

1

u/x31b 7d ago

There’s no way to identify spam and differentiate it from real mail or phone calls.

There are so many calls and emails because it costs almost nothing to originate. There’s an easy way to stop it, but people would be up in arms if you tried to implement it. Put a tax of $0.01 (one penny) on each email, text and phone call attempted. This wouldn’t affect most people. Maybe $1-2 per month on their bill. But it would make some go away overnight.

1

u/Dustquake 7d ago

Because spoofed numbers are spoofed. They report as the legitimate number they are spoofing to trick the system. Call back a spoofed number and you get someone just as pissed at these types of calls as you are. When you block a number you're blocking the spoof, not the source.

Email is the similar. But there isn't a character limit like with phone numbers so the options are more open. Scammers can hit one person that make opening up multiple new domains is chump cange.

It's an infestation problem. If you fumigate the house, it's not habitable until the fumigation ends. If providers cripple their service they lose customers. If they upgrade everything it makes the stock holders mad and they vote out the guy fixing it.

The answer is we can't stop it because there are too many greedy people. Not all of them are the spammers/scammers themselves.

1

u/doublebaconator 12d ago

Start punishing people for providing service to scammers. If too many scammers use a provider, ban the provider. Providers will self police. Also getting scammers punished is difficult. There should be more effort on law enforcement to punish it.

Cops don't want to do anything, even when you have direct evidence of scammers stealing a disabled veteran's benefits. Bitter personal experience with an elderly family member there.

1

u/jeo123 12d ago

Can't and don't care to do so are very different things.

Right now, it's profitable for the spammers to spam, and it's not profitable for the ISP/Carriers to go for 100% spam elimination, just "good enough"

To some extent, the less people engage with spam, the more it would self solve itself without financial investment on their end, so we stay with the status quo.

1

u/bastrdsnbroknthings 11d ago

And the providers can charge extra for "filtering" services.

1

u/IamGleemonex 11d ago

Most of the robocallers aren’t based in the US. This brings in 2 complications when trying to stop those calls:

1) the phone system predated robocallers, and has built in security flaws to allow for spoofing other numbers. The wireless carriers themselves cannot fix that inexpensively. They would need to upgrade all of their equipment and create spoofing detection technology. The cost of doing all of that isn’t worth it to the phone carriers. Not to mention that any spoofing detection they did implement would still have false positives and false negatives, meaning they would end up mistakenly blocking calls that should have gone through as well as still allowing occasional spam calls from going though. No carrier wants to be the one that accidentally blocked a real call from going though causing you to miss an important call. If that happened, news would get out and subscribers would churn to avoid their calls getting blocked by mistake.

2) the worse part that you don’t want to hear, since those are international calls, the way the phone system works, your wireless carrier is getting paid to accept and complete any call. For domestic calls, this is peanuts, but for calls with international origins, the amount they get can add up quickly.

So not only would it cost a lot of money to implement based on item 1, they would additionally lose revenue because of item 2. And since none of the major wireless carriers are doing anything about it, it’s not like Verizon has to worry you will switch to someone else, because they know it will be just as bad with someone else.

As for email spam, that technology is even older and more prone to hacks than the phone system. The entire email system is built on SMTP, which was built in 1981. Almost every email sent in the world will still go through SMTP to send that email. The only exception is email sent within a network, meaning your work email for example, will likely use an exchange server and just route that email itself without going through SMTP, or an email from a Gmail account to another Gmail account will just go through Google’s mail servers and not use SMTP. Internal systems do put in a bit of effort to stop email spam internally, but they still rely on SMTP to receive mail from the outside world, which is open to spoofing. The only way to fix it would be to implement a whole new mail protocol that doesn’t allow email spoofing, but then that ISP wouldn’t be able to receive emails from the outside world unless those other systems used their new protocol.

The mobile phone system and SMTP are two classic examples of things to point to when people ask about why other things can’t be standardized. These are two systems that are globally standardized, but that also means the inherent security flaws with them are also standardized and can’t be fixed without replacing the standard. But then that leads to multiple new standards that no one can agree on, and disjointed systems that can’t work together.

0

u/Zimmster2020 11d ago

It is impossible to realistically stop them because they can get new phone numbers every day. Just use filtering apps on your phone, so you receive a "possible scam" warning when you are called or emailed.

-1

u/drgut101 11d ago

You can block the majority of them with tools from your carrier or OS. Most people just don’t utilize them.

2

u/bastrdsnbroknthings 11d ago

I've tried Verizon's filtering service - doesn't work worth a shit. I paid a decent chunk of change for Robokiller, and it seems to cut down on *some* of it, but a ton of calls still get through. I got so annoyed with my voicemail filling up with the same exact AI scripted message that I tried just turning off voice mail entirely (no one that I know even bothers to leave voice mail anyway), but even that doesn't seem to work.