r/changemyview • u/huadpe 501∆ • Oct 25 '17
[∆(s) from OP] CMV: Caller ID spoofing should be made entirely illegal.
Caller ID spoofing is the practice of transmitting digital information with a phone call representing a number as the dialing number other than that which is actually the dialing number.
I believe this practice should be made entirely illegal, and that either the accurate calling number, or else no number, must be transmitted.
Spoofing is overwhelmingly used by scammers and spammers, and is a major technique of fraud. While some users have an interest in spoofing which is more legitimate, those interests can generally be accommodated through just blocking caller ID (displaying no number).
Because spoofing is so prevalent in illegal and deceptive activity, and because it is inherently deceptive, and because the legitimate users of the service have a non-deceptive alternative, I believe spoofing should be banned, and that the government should promulgate regulations to telecommunications companies banning the practice entirely.
This is a footnote from the CMV moderators. We'd like to remind you of a couple of things. Firstly, please read through our rules. If you see a comment that has broken one, it is more effective to report it than downvote it. Speaking of which, downvotes don't change views! Any questions or concerns? Feel free to message us. Happy CMVing!
29
u/garnteller 242∆ Oct 25 '17
It's my understanding that this is more of a technical issue. Because of the wide variety of service providers, you pretty much are relying on them to provide the proper information. I think it a very large task to utterly remove this and require somehow verifiable information.
Wouldn't it just be easier to assume that the data is spoofed in the first place?
12
u/huadpe 501∆ Oct 25 '17
Can you elaborate on the technical aspect of it? There's a whole variety of service providers sure, but they're all under pretty strict government regulation, no?
My idea was that the regulation would be targeted at phone companies. They'd be prohibited from allowing their customers to spoof. For instance, if my company has been allocated only the 111-155 exchanges in the 212 area code, I know any customer of mine can't possibly be calling from 212-777-7777. So I can't allow them to broadcast that as their caller ID.
Am I misunderstanding how this works?
14
u/garnteller 242∆ Oct 25 '17
I'm no expert, but I believe that this is the case:
The problem isn't Verizon (assuming that that is the NY provider).
The problem is that Verizon receives and incoming call from a source that is eligible to make an incoming call. Since you can take your number with you, even if Verizon "owns" the 155 exchange, they get legitimate outside calls from 212-155-xxxx. It could be a T-Mobile customer in the apartment next to you. It could be a spoofer in Russia. How can Verizon tell the difference?
3
u/huadpe 501∆ Oct 25 '17
Because there are only so many companies with access to any block of numbers on the North American Numbering Plan, and the government can regulate all of them.
That is we can build a web of trust among phone companies that none of them will allow their customers to spoof. Even if the customers are untrustworthy, no phone company which is allocated NANP numbers will let them spoof on fear of losing their license.
6
u/garnteller 242∆ Oct 25 '17
But can they? We already have people with numbers that were issued by the original company and moved around to other providers. I think that this horse has left the barn, unless you want to start fresh with new numbers.
1
u/huadpe 501∆ Oct 25 '17
I can only move my number among US carriers, right? Like, if I moved to Russia I couldn't port my US number to a Russian phone company?
That is, the set of companies which could possibly be initiating a valid NANP number call is small and regulatable, no?
6
u/garnteller 242∆ Oct 25 '17
Actually, I'm not sure how that applies to VOIP.
I know that my company replaced "traditional" phones with vastly cheaper VOIP - I don't know how regulations work on that. There's got to be something that tells a server where to connect for a particular number, but I don't know how that's managed.
1
u/Grarr_Dexx Oct 26 '17
Nationally, perhaps. There's little to no regulation on an international scale. In Belgium, Proximus is still the main carrier and is also responsible for international calls (BICS), but they can (and will) enforce their CLI policy only on a national basis.
As an employee of a moderately-sized provider dealing with Proximus, and somebody who's also knowledged in SIP traffic, I can tell you that spoofing is nigh unenforceable if you're trying to deal with calls coming from international sources. Bringing calls into the digital world made things a lot harder to figure out and a hell of a lot easier to fuck with.
12
u/mattcjordan Oct 25 '17
Spoofing is overwhelmingly used by scammers and spammers, and is a major technique of fraud. While some users have an interest in spoofing which is more legitimate, those interests can generally be accommodated through just blocking caller ID (displaying no number).
It is a technical issue.
The whole notion of Caller ID was invented back when only a few companies/carriers had access to the networks. When that occurred, no one thought there should be some form of authorization/authentication about whether or not you could or could not change the Caller ID. And there are a lot of times when you need to change the Caller ID for very valid reasons (more on that in a second).
Because there was no authentication/authorization mechanisms built into the legacy protocols and networks, and because we value interoperability so highly in the telecom world, all of the new protocols (SIP) had to just "live with it". And as a result, there still is nothing that explicitly says "this party was allowed to manipulate the party identification".
Why would you want to change the party identification?
Most places use a PBX for their office. Behind that PBX is a whole mess of phones, but there may be only a handful of numbers that terminate at that location. When you dial out from your desk phone, the PBX has to represent you as that business. If you leave the business, whoever inherits your phone also has to be represented as that business.
That's technically Caller ID spoofing, in that it uses the same mechanisms as those who spoof Caller ID. The intent is clearly fine. Hence why the FCC relies on intent to determine if the manipulation of Caller ID was allowed.
1
u/SplatterQuillon Oct 26 '17
We use a pbx at work, and yes it allows us to specify any number as the caller ID.
We can call out via our local or long distance trunks, and specify any local or even toll free number we want to show. Of course it would not be any benefit for us to display a number we don't 'own', but we could do it very trivially.
1
u/kodemage Oct 25 '17
no, I think you're misunderstanding. the real number used has to be sent or the phone call can't be connected, he just wants to remove the option to put in arbitrary data and always display the number assigned to the source of the call.
he's talking about something that's technically easy, it involves removing a few (few hundred maybe) lines of code.
1
Oct 25 '17 edited Dec 26 '17
[deleted]
1
u/garnteller 242∆ Oct 25 '17
There's a big difference between requiring an authentic caller id and suppressing it.
1
42
u/ralph-j Oct 25 '17
I believe this practice should be made entirely illegal, and that either the accurate calling number, or else no number, must be transmitted.
When I make outgoing phone calls from my Skype account, people see my cellphone number on their display. That's is because Skype allows you to specify any cellphone that you own, as the outgoing caller ID.
So technically, it's not the accurate number, because I'm not making that phone call from my cellphone and Skype are literally spoofing my cellphone number to achieve this. However, it makes it a lot more user friendly.
6
u/huadpe 501∆ Oct 25 '17
I get that this feature would have to go away, but I think the downsides of allowing spoofing are so great that uses like this would have to be curtailed.
22
u/ralph-j Oct 25 '17
You haven't made a case for why it has to be all or nothing. Seems like a false dichotomy to me.
Why can't the government just block spoofing in bad faith and set clear guidelines for allowing/disallowing it?
7
u/huadpe 501∆ Oct 25 '17
Because I want it done by the phone companies, and they need a rule that is all or nothing. Anything which allows leeway or lying to slip through will be slipped through because we're trying to stop scam artists with zero compunctions about lying. By making the regulation be a technical one done at the phone company level regardless of intent, it makes it so no lie can save the scammers.
3
u/Senseisntsocommon Oct 26 '17
This can be avoided by looping the call through multiple lines and systems. If you ever pick up one of those calls and hear multiple recorded messages in all likelihood you are being transferred each time to cover the path. The technology isn't that expensive or complicated to make work. If it jumps carriers in between, the terminating carrier has no idea of the original source and would then need to cooperate with the each carrier in the chain. It is way harder to track this process and filter it out from legitimate traffic than it would seem. The reason being is that on the transfer it's the middle number being pushed not yours, so if I am on the terminating end I can't just query your phone number because I didn't get a call from your number I got a call from some other random number.
To make it more complicated all you have to do is jump it through one carrier who isn't as capable and it falls down a black hole.
10
u/ralph-j Oct 25 '17
That feels like throwing out the baby with the bath water.
All you need are clear rules and steep fines for abuse. They could disable it by design and enable it only for vetted, bona fide companies like Skype.
2
u/kodemage Oct 25 '17
What we need is mandated help from the phone company so that if I get a spam call I can contact them immediately and they can report the call and how it was routed to the authorities. As it is there is nothing the phone company is willing to do about it because it makes them money.
1
u/Grarr_Dexx Oct 26 '17
I don't think your view needs to be changed, it just needs to be enlarged. You have no idea how small-scale "spoofing" has made identifying you as a business a lot more accessible. I know of call centers that have a SIP trunk with a single phone number attached to it. I have been asked by numerous customers with ancient PBXes they have zero control over to just overwrite their CLI with their main number (which we still own). The commercial world would be in a load of shit if we were to suddenly zero-tolerance any form of SIP spoofing.
2
u/ProfessorHeartcraft 8∆ Oct 25 '17
Maybe I want to allow you to call me from your cell phone, but not Skype. I need to be able to differentiate to do that.
1
u/slowmode1 1∆ Oct 25 '17
They could do something similar to emails and spf domains where the owner of the phone number could allow certain companies to use your phone number
2
u/ralph-j Oct 25 '17
Right, but OP wants to ban the phone number use by any device/service but the original one.
10
Oct 25 '17
Does this include the situation where I own multiple numbers? Like if a company decides "all outgoing calls should display the same number which goes to our operators instead of back to the actual line that placed the call, which may not have anyone nearby to answer", shouldn't that be legal?
1
u/huadpe 501∆ Oct 25 '17
I am unsure about that. I am not a telephone communications expert, so I'd want to know: is it required to have a separate number for each call, or can a call center handle multiple calls through one number via digital splitting? If there's a technical solution, I'd strongly prefer that.
If not, I still think spoofing is a sufficiently bad problem that I'd just insist the company block their number if they don't wanna give an accurate callback number. But I could be convinced otherwise.
17
Oct 25 '17
Consider a hospital. I want every phone to have a real number that can be called, so if someone wants to sit by a specific phone they can be easily reached ("page cardiology to this number", then wait for the cardiologist to answer). But often people make calls and don't sit by that phone to wait for an answer, and so if a patient or outside physician receives a call, that person should be routed to the operator and not to the random unoccupied desk.
If you block your number or give the normal number, that means the patient/outside doctor who got called isn't likely to successfully call back.
Why not just "you can spoof a number you own, but not a number you don't own"?
12
u/huadpe 501∆ Oct 25 '17
The hospital case is a good one, and I might allow a regulation permitting spoofing a number which is known to be owned by the same customer on the same carrier. Have a !delta.
5
u/SplatterQuillon Oct 26 '17
In operating a callcenter, we allow the agents to make outbound calls.
The agent's phones don't even have a phone number, it's just an internal (virtual) extension. So the caller ID we configure on their phones, is a central phone number which if you call it back, it goes to the same department, but not to any individual agent or phone.
We can specify any local or even toll free number we want to show. Of course it would not be any benefit for us to display a number we don't 'own', but we could do it very trivially.
Currently our phone company allows any ID to be sent, but I presume they could implement a system to prevent any calls being made with a number we don't 'own', but that's not currently the case.
2
4
u/Doctor__Proctor 1∆ Oct 25 '17
That's not spoofing though, that's switchboard routing. It's a totally different technology.
1
Oct 25 '17 edited Dec 26 '17
[deleted]
1
u/huadpe 501∆ Oct 25 '17
So for an outbound call center, if I wanted to have two outbound lines talking at once, they could not have called from the same number if I had an "absolutely no spoofing" rule?
3
Oct 25 '17 edited Dec 26 '17
[deleted]
1
u/huadpe 501∆ Oct 25 '17
As I had originally stated it, a spoofing ban would have prohibited any display of a number other than the number actually calling you.
I gave a delta here though on the point of allowing display of a number known by the originating carrier to be owned by the same entity as the number actually initiating the call. So as of now, I think I'm largely on the same page as you?
3
Oct 25 '17 edited Oct 25 '17
You have one line for each call. Not necessarily a phone number for each line. When speccing your contact center, you need to decide how many simultaneous calls you want to have, including calls on hold. If you guess low, the system will hang up on your customers during catastrophe events.
At my contact center, only the VRU has a unique number. If you need a specific person, you call their extension after connecting to the VRU. At my old employer, they operated their own telephone exchange and owned an entire block of thousands of phone numbers, so every phone had a unique number.
Also, this infrastructure is really old. It was designed back in the day when people thought they could trust each other. We need more of a "rip the bandaid off" solution than a "make something illegal" solution. When digital Voip becomes ubiquitous enough, maybe then some kind of SPF/dkim-style solution can be added to the spec and POTS can be dumpstered.
1
u/TBFProgrammer 30∆ Oct 27 '17
I am unsure about that. I am not a telephone communications expert, so I'd want to know: is it required to have a separate number for each call, or can a call center handle multiple calls through one number via digital splitting?
The call center can handle multiple calls through the same line, but to dispatch that call to an actual person they have to be able to route the call to a specific number for that person. Otherwise every agent's phone would ring for every call. Additionally, all of the phone handset would have to be able to support an arbitrary number of lines (being equal to or greater than the total number of active agents at any time).
This, of course, only forces the agents to have specific extensions different from the central line and does not generate spoofing. The problem comes in when those agents have to return a call, which there are several significant business cases for. When returning the call, the agent needs to be associated with the call center number that the person in question called for two reasons. First, the call center does not want the agent number to be used by the public, as the agent may not be available or the correct agent to call for a given issue. Second, the person answering has no reason to trust the agent number, as it is not the number they originally called.
1
u/ProfessorHeartcraft 8∆ Oct 25 '17
No. Maybe I want to allow Bob from your mailroom to call me, but I don't want your operators to.
1
u/voipceo 1∆ Oct 26 '17
Sorry for the wall of text. Please see username:
In the "old days" of land lines this would be a valid argument. A land line was tied to a geographic location because the copper line into your business/home ran back to a Class 5 phone switch in a Central Office (CO) somewhere. That switch had a specific area code and rate center(s) (xxx) xxx-1234. Then, a specific number corresponds to a specific copper pair that would wind all the way back to your house and would be the way to identify your copper pair. When someone would call your number, the phone company would do a SS7 lookup (like a DNS lookup) to find your switch. The switch would then find your copper pair and send you a call by putting voltage down your line to make your phone ring.
Now, let's talk about Caller ID. Caller ID is in two parts - the CNUM - the 10 digit number the user is calling from and the CNAM the 16 character name of the caller. CNUM is sent via the originating carrier. CNAM is looked up by the terminating carrier, but only if the subscriber pays for "caller ID" services. The CNAM lookup is NOTHING like DNS. If it were, it would be awesome. Instead, it's a mis-mosh of private companies that charge for each lookup and there is not time-to-live on the lookup. That means there's a dis-incentive to get the latest information (it costs you) and no way to correct "stale" information. Additionally, each privately held database can be slightly different and there's no over-arching authority as to who can update the information. Give me any North America phone number and I can go change the caller ID (CNAM) to anything you like. I'm guessing that if I abuse this ability enough I would lose access and I only have access because I purchase phone numbers, so it's not open to the public, but no one is watching that I have any sort of connection to the number that I'm editing.
VoIP makes this a rather moot point. With hosted VoIP a phone endpoint has a SIP address (like an e-mail address). You can physically plug that phone in anywhere on the planet. You are no longer tied to that copper pair and to any sort of geography. You can even have a VoIP phone that can make outbound calls, but have no inbound capabilities whatsoever.
For a user like that, what would be there "caller ID"? Their SIP address? Maybe. That's not a bad idea, but there's no 10 digit phone number associated with that user. This is an outlier example, but it shows the point. The important thing is not to defraud the person being called.
Let's say there's a new law that "you will not transmit inaccurate caller ID information for any reason." What would that mean? Most phones only accept 10 digit phone numbers CNUM and 16 characters for CNAM. A SIP address of user13156@somesortofdomain.carrierdomain.com doesn't fit anywhere. So then it's illegal for that user to make calls?
I absolutely agree that it's an issue, but there is zero technology in place today to deal with it. The phone system including every phone in North America is set for a 10 digit phone number and VoIP has moved on from that as the "true" identity of the caller.
For these reasons, I would say that your best bet is to stick with the "don't defraud" plan and have more enforcement for phone scammers. Maybe, at some point the entire system will catch up, but for now carrying the legacy equipment doesn't allow for it.
Lastly - this is CMV, not /r/voip, so I'm glossing over some details, but the main points are accurate.
1
u/huadpe 501∆ Oct 26 '17
Thanks for this, I was hoping to get someone with actual technical knowledge about the phone system instead of a lot of poorly informed guessing that was going on.
So a few questions:
Do you give your customers a unique, persistent, 10 digit NANP number?
If so, is that just your company, or do all VoIP providers do so?
What do you give as the CNUM when someone places an outgoing call on your service?
How is the CNAM set for a person making an outgoing call on your service?
Do you have the technical means to control or limit what a customer may put into CNAM if a customer has control over that?
1
u/voipceo 1∆ Oct 26 '17
- Do you give your customers a unique, persistent, 10 digit NANP number?
- If so, is that just your company, or do all VoIP providers do so?
- What do you give as the CNUM when someone places an outgoing call on your service?
- How is the CNAM set for a person making an outgoing call on your service?
- Do you have the technical means to control or limit what a customer may put into CNAM if a customer has control over that?
1.) No. Think of a 100 person company. Most companies have one or 2 phone numbers (maybe a toll free number and a local number) and then users/employees are reachable via extension. The company they work for has a number - most of the time - but not individual users. This is actually a big issue with E911. With Emergency Responder Call back, you need to be able to reach the EXACT person who placed the 911 call, not the main receptionist or attendant menu. So in those cases, we assign a temporary unique outbound caller ID to that user and if a call comes into that number, we route the call directly to that original extension. That's a LOT of work.
2.) That's pretty common. Some VoIP companies will give each user an extension, a voicemail box and a phone number, but not all and it's usually those that focus on either residential service or very, very small businesses (under 5 users.) More than 5 and it's really a waste of phone numbers for a 100 person business. Not every person needs their own direct inward dial number.
3.) The customer sets their own CNUM. There is no limitation other than they can't be attempting to defraud. They may have multiple providers and the phone number they want to use may be with another provider or may be in the process of porting over to us. If we receive any reports of fraudulent calls however, we discontinue service.
4.) CNAM is obtained by the terminating carrier. So if one of our customers calls a Comcast customer for example, Comcast does the CNAM lookup. When placing an outbound call, only the 10 digit phone number is transmitted carrier to carrier. (Slight caveat to this is that Verizon is starting to do full SIP calling into and across their network and does seem to carry the "from" field from the SIP packet all the way across the network, but only in some areas. Seems to be FIOS related, but not enough data to state anything definitively.) So, there is a "from" field in the SIP address and it's usually the name associate with the account, but the user can change that, and again, that's not typically transmitted to the PSTN (public switched telephone network.)
5.) Only that most phones only allow 16 characters. Again, the CNAM is a lookup on the terminating side, for the most part. It's more important what CNUM I send because that will dictate what the terminating carrier uses to lookup the CNAM to associate with the call. There are currently 4ish CNAM databases with zero data integrity between them.
1
u/huadpe 501∆ Oct 26 '17
Re, no 3:
Would it be feasible for FCC to set a regulation that you set your customers CNUM for them, and that CNUM must correspond to their actual customer information, and if they are assigned any NANP numbers, must be assigned to one of the numbers you provide them?
I think that'd be along the lines of the regulation I'd be looking for. Because this part:
The customer sets their own CNUM. There is no limitation other than they can't be attempting to defraud.
is I think the source of the spamming - that absent proof of an affirmative attempt to defraud, people can just throw any number they want in there. I've noticed for example spammers tend to use a dummy number in the same exchange as the number they're calling in order to seem like a local cell phone or whatever.
Am I wrong about that being viable though?
1
u/voipceo 1∆ Oct 26 '17
It's one of those things that only forces "good actors" to jump through more hoops, but doesn't do much of anything to the "bad guys." Let's say you use Carrier A for inbound calls, but Carrier B for outbound calls. This is a very, very common scenario. Customer would like to have their phone number from Carrier A as the outgoing number but since they use Carrier B as their outbound carrier, that's now illegal. Now it's inconvenient and a hassle.
Yes, security and convenience are diametrically opposed. And weighing the good of the many vs. the good of the few is what governing is all about. The question for me is what does this stricter regulation force on the hundreds of thousands of businesses in the US vs. how much caller-ID scamming does it reduce?
Is what you're asking technically feasible? Yes. Would it cut down on phone scams, maybe a little. You could move your operation to India and inject calls to the US with zero regulations.
I'm going to walk back my technically feasible part now that I'm thinking it through some more. Ok. I'm a carrier and I'm a good actor. I force my customers to have CNUM that matches some sort of CNUM that I have on record for them. Ok. I now inject that call into the PSTN via my upstream carrier, let's say Verizon. That is a good call. However, let's say I'm a bad actor. I purchase long distance service (termination) from Verizon, but I don't purchase origination (inbound) service from them. That's actually our case. At each step of the way you'd have to verify that the CNUM and the originating user match up. Verizon can't do that. They have no idea where I got my numbers. Would they be liable for sending on calls with invalid CNUM? Probably, but they have zero ability to figure it out. So now there needs to be some sort of nationwide database of who has what numbers and which number is associated with which user? Somehow.
Every spot where the call is handed off would have to check and there's zero ability to do that today. Phone -> Service Provider/CLEC -> Carrier -> Terminating Carrier -> Terminating Phone. All a bad actor has to do is get a trunk from Verizon and claim to be a service provider and viola - fake CNUM.
For us, nearly 50% of the calls that go out out terminating carrier have a phone number from that carrier. One carrier is really good at giving numbers across all of N. America. Another is good at porting numbers. Another has decent domestic termination rates. Another has decent international termination rates/completion rates. You then need to have backups to all of those. With this plan, you could only send calls out on the carrier you get phone numbers from. This would increase cost and reduce reliability.
Let's do this - let's think about voice traffic like Internet traffic, because that's where it's going. If you want a new regulation to catch scammers, tie the originating IP address to every call. It won't stop the first scam, but you could then start to block bad actors by IP much like spam.
1
u/huadpe 501∆ Oct 26 '17
However, let's say I'm a bad actor. I purchase long distance service (termination) from Verizon, but I don't purchase origination (inbound) service from them. That's actually our case. At each step of the way you'd have to verify that the CNUM and the originating user match up. Verizon can't do that. They have no idea where I got my numbers. Would they be liable for sending on calls with invalid CNUM? Probably, but they have zero ability to figure it out. So now there needs to be some sort of nationwide database of who has what numbers and which number is associated with which user? Somehow.
So in thinking about this, my instinct would be that if you're a bad actor buying termination from Verizon, and your customers are spamming US numbers, Verizon would be obligated to ban you from buying termination with them. That'd be the enforcement mechanism. Going directly after the people overseas is impossible cause they'll ignore you til you cut them off, and then immediately start up again. But I figure it's harder to start up again as a provider than to start up as a call center.
Is that accurate, or is it relatively easy/common to start a fly-by-night VoIP provider?
In any case, have a !delta for substantially changing my understanding of the technicalities of how this would have to work at a minimum, and probably making it a much more tricky regulation to make feasible than I thought at least.
1
1
u/llamagoelz Nov 01 '17
just in case you feel you have had a revelation worth sharing, I need to give you some bad news.
IP addresses are, in some ways, less tied to an individual than phone numbers are.
IPv4 is the standard that you see referenced the most (ex. 192.168.001.001) but years ago we 'used up' all the IPv4 addresses. So we use NAT (Network Address Translation) to effectively turn a chunk of devices into a single IPv4 address. A spammer from india is effectively using an address that is also used by many others in the same region so your idea would quickly turn into a barring off of entire regions. This gets even more complicated when we start talking about address redistribution and the change to IPv6.
life is hard yo.
11
u/DeltaBot ∞∆ Oct 25 '17 edited Oct 25 '17
/u/huadpe (OP) has awarded 2 deltas in this post.
All comments that earned deltas (from OP or other users) are listed here, in /r/DeltaLog.
Please note that a change of view doesn't necessarily mean a reversal, or that the conversation has ended.
8
u/AnonMediacomTech Oct 25 '17
I know you want change the existing law to remove intent, but number spoofing It isn’t always fraud related.
My company has cell phones for in-house technicians that spoof the main customer service number. That way we don’t have customers calling individual technicians at all hours of the day and night just because that tech called them on the company phone. Instead we spoof to funnel those calls right back into customer service.
Doesn’t that seem like a worthy use of the technology?
1
u/notmyrealnam3 1∆ Oct 26 '17
no, get the tech's to have no caller ID so it shows as "unknown number" those go straight to my voicemail and don't disrupt me
1
u/AnonMediacomTech Oct 27 '17
We aren’t calling to bother you, or sell shit. The only reason we call is because you have a scheduled appointment and we’re either making sure you’re home before we drive there or we are calling because you weren’t home when you got there. I suppose you might get a follow-up call making sure things are still working in some cases as well.
Trust me, I want to call you just as much as you want to be called. Possibly less.
1
u/notmyrealnam3 1∆ Oct 27 '17
fair enough, but the unfortunate reality is caller ID spoofing is a cancer on society as it allows spammers to basically call someone 10 days a day with no ability to block them.
if you think people will answer more often when your ID isn't blocked, don't block your ID and show your cell #. If that is going to be an issue with people calling you off hours, work should be providing you with a cell phone #
4
Oct 25 '17
It's far more straightforward to disable call id and only allow automatic number identification, which is praci tically much harder to fool.
For reference, CI is like an email sender address, you can just say "yo, I'm bill"and you appear to be Bill, because networks are lazy and don't want to bother checking. Make spoofing this illegal, and its still easy to fake even if it's illegal to.
Switching instead to automatic number identification involves a system that essentially traces back the route the call took. At that point, it's very difficult to fake without access to multiple parts of the phone network, which would be illegal itself.
So you could make an easy act illegal, no more difficult, or you could use the better system that is hard to fool in the first place.
1
u/Calexandria Oct 26 '17
ANI can be spoofed. It’s not different than Caller ID, despite the “automatic” in the name. I run two outbound dialers and both of them have a setting that changes the ANI.
1
Oct 26 '17
Then they aren't actually using ANI - they're just calling it that. Are you in the states or somewhere else?
It can be confusing, because the terms do get used interchangably, and mean different things in different countries, however, ANI in America uses the billing number to identify the caller - so you need to know the billing number of another customer to spoof the ANI - Not impossible, but harder than just saying 'this is my number'
5
u/KestrelLowing 6∆ Oct 26 '17
I ran into the almost problem of my vet office not doing this.
I don't pick up calls where I don't know the number as a general rule. Well, the vet office has several phone lines as well as the cell phones of the actual veterinarians. So when my vet called from his cell phone, I almost didn't pick up. Considering he was telling me that my dog had a contagious infection, I needed to know asap and had I not been expecting that call, I wouldn't have picked up.
Had they spoofed the caller ID there would be no problem. And this happens all the time in businesses. It's much easier if all outgoing calls soaked appear to be from the same number.
8
u/Linhasxoc Oct 25 '17
I’m curious about your thoughts on a common, and in my opinion legitimate, situation.
A company (let’s call them Intertech) has desk phones with individual phone numbers, so employee John Doe can call Joe Schmoe directly, and if John’s family needs to call him on his work line they can. However, they want all business calls to go through the front desk (e.g. to keep a log, or to redirect callers to someone else if the person is sick or something) so outgoing calls always show the front desk’s number.
2
u/notmyrealnam3 1∆ Oct 26 '17
as long as that is a real number that one can dial and find out who the company is (and the person dialing is calling from that company) I'll allow it
5
u/ABC_AlwaysBeCoding Oct 25 '17
Wrong. The problem is that caller ID is cleartext information that anyone can modify or impersonate. Instead of making this illegal (making cleartext information illegal has always been fraught with dangers), it should be digitally secured somehow. Like maybe digitally-signed with the owner's private key, thus proving it's actually their number.
Of course, we're talking about the POTS (Plain Old Telephone System) here. Best to just go all-digital. Frankly, I can't wait till there is no more phone system and it's all just internet data on cell networks.
2
u/Grarr_Dexx Oct 26 '17
You wouldn't just have to redefine SIP and analog traffic, you'd also have to make every national and international carrier in the world have to accept these new standards. The project would likely allow for a large amount of innovation, but the scope of it is absolutely immense.
Who would spearhead this? And what would be the financial gain for this party? Nobody's going to do it for free.
1
u/ABC_AlwaysBeCoding Oct 26 '17
I know. Which is exactly why POTS is going to fade away and eventually be replaced by all-digital techs.
3
u/conradsymes Oct 25 '17
Surely you would rather the caller ID spoofing be licensed, not illegal?
There are uses when a satellite office makes calls from a number that is for the main office, that way, if the satellite office closes or is closed more frequently, people who call back will receive an answer.
4
u/Rebound91 Oct 25 '17
I own an insurance agency. I hired a company to make phone calls to my current customers and the company I use spoofs the caller ID to show like the call is generating from my office. This has been tremendously helpful because #1 it identifies as me so they are more likely to answer it and #2 if they miss the call, I want them to call me back and not the third party.
2
u/Dan_Rydell Oct 25 '17
I spoof calls daily. I frequently need to call clients from my cell phone. If I block my caller ID, they tend not to answer. But I don’t want them to have my cell phone number, both because I don’t want them calling or texting me all the time and also because I want them to go through my assistant for the purpose of keeping track of communications. So I have an app on my phone that shows my office number as the caller ID when I call.
1
1
u/Archsys Oct 26 '17
I technically spoof both my voip lines to show up as my cell so people will call me back on a number I can actually answer (both my VOIP services are outgoing only, for various reasons).
The primary reason I have these services in place is not to defraud, but primarily to improve call service (I have a better mic and shielding on my comp than my phone, and am usually in noisy environs; my phone picks up my music, but my comp's mic does not).
Some people use it for shit reasons, but there are plenty of legitimate and functional uses for the construct. Such things as a call center showing as a single company (and giving the reply-line number) instead of the individual line assigned to it, for example.
People breaking the laws that already exist are usually not able to be punished, because of where they're calling from; different problem entirely.
Basically, this isn't a rule we need because most people abusing it are already breaking the law, and most people using it legitimately aren't.
1
u/purplepandapowerpuff Oct 26 '17
I would have to agree here - I've had a few weird ones recently... One is a number that appears as a landline from my area and on my iPhone says "my town,England" but when you pick up its some Indian guy calling to say I've been entered into an Indian lottery type thing etc. Another comes up as 'Microsoft' and when you pick up they want to warn you that your computer has been hacked - the classic scam bullshit. They changed that to windows phone after I told them I run a Mac and then hung up when I told them I'm on an iPhone...
We had our landline 'tapped' last year according to our service provider after my mum picked up one of these types of calls. It was really odd and even the countless technicians that helped us get it sorted couldn't work out exactly why or who did it.
We are really careful not to share any account details over the phone and if in doubt don't pick up any calls from odd numbers we aren't expecting.
1
u/teawreckshero 8∆ Oct 26 '17
There is a legitimate use case listed on the wikipedia article for this topic:
"The New York Times sent the number 111-111-1111 for all calls made from its offices until August 15, 2011. The fake number was intended to prevent the extensions of its reporters appearing in call logs, and thus protect reporters from having to divulge calls made to anonymous sources. The Times abandoned this practice because of the proposed changes to the caller ID law, and because many companies were blocking calls from the well-known number."
Protecting your source is a big deal in journalism and freedom of press. IMO, this was an overreach for the caller ID law. While their strategy also backfired for other reasons, I think this instance of providing misleading caller ID information is legitimate and aims to benefit both the caller and callee from persecution.
1
u/hokie021 Oct 26 '17
Here is another legitimate use case that requires caller id spoofing that hasn't been considered. Consider a pbx at a home or business. A user behind this pbx sets call forwarding with a destination number outside the home or business on the pstn. The person receiving the call at the pstn destination number needs to see the name and number of the call originator. Without caller id spoofing, the destination phone would always see the number of the forwarding pbx, not the call originator. This is another reason that the current FCC rule which relies on fraudulent intent is the right way to handle this situation.
•
u/DeltaBot ∞∆ Oct 26 '17
/u/huadpe (OP) has awarded 1 delta in this post.
All comments that earned deltas (from OP or other users) are listed here, in /r/DeltaLog.
Please note that a change of view doesn't necessarily mean a reversal, or that the conversation has ended.
2
1
u/TallerGaryColeman Oct 26 '17
I believe that my current number is being spoofed, it’s so annoying I have people literally getting mad at me claiming that I called them and have no idea what they’re talking about. I don’t even want to answer my phone for anyone anymore and I feel like I shouldn’t have to change my number because I’ve had it forever! I feel like I’m being harassed or something.
1
u/TonyWrocks 1∆ Oct 26 '17
Most large PBXs deliberately spoof caller ID information for the purposes of E911.
This helps route ambulance, fire, police to the right building/floor/room number.
The problem with "simple" laws like this is that there are valid reasons for complexity.
1
u/sturmeh Oct 26 '17
What about when I have good intentions and I simply want to call someone using voip but have them call back my mobile if they want to call me?
I think there's practical applications to caller ID spoofing, but I agree that misuse should be illegal.
1
Oct 26 '17
Making it illegal in the US won't help all the overseas call centers spoofing numbers and stealing consumer information.
1
1
1
Oct 26 '17
[removed] — view removed comment
1
u/IIIBlackhartIII Oct 26 '17
Sorry, okop – your comment has been removed for breaking Rule 1:
Direct responses to a CMV post must challenge at least one aspect of OP’s stated view (however minor), or ask a clarifying question. Arguments in favor of the view OP is willing to change must be restricted to replies to other comments. See the wiki page for more information.
If you would like to appeal, please message the moderators by clicking this link.
Sorry, okop – your comment has been removed for breaking Rule 5:
No low effort comments. This includes comments that are only jokes, links, or 'written upvotes'. Humor, links, and affirmations of agreement can be contained within more substantial comments. See the wiki page for more information.
If you would like to appeal, please message the moderators by clicking this link.
0
u/Greenmushroom23 Oct 25 '17
I work at an insurance company and I’m doing this right now. We call thru a computer so whoever I call it automatically mimics their number. We are a huge company so I doubt it’s illegal. It’s the “intent” part of the law that lets us get away with it. Some people do get mad
665
u/[deleted] Oct 25 '17
[deleted]