TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Understanding STIR/SHAKEN – New Anti-Robocalling Protocol

109 点作者 randomdrake大约 6 年前

12 条评论

th0ma5大约 6 年前
Always want to fill out the old <a href="https:&#x2F;&#x2F;craphound.com&#x2F;spamsolutions.txt" rel="nofollow">https:&#x2F;&#x2F;craphound.com&#x2F;spamsolutions.txt</a> form with these ideas. Like the open world &#x2F; closed world AI problem.
评论 #19450057 未加载
评论 #19449191 未加载
评论 #19455151 未加载
评论 #19449530 未加载
评论 #19452685 未加载
评论 #19449676 未加载
Animats大约 6 年前
This clearly wasn&#x27;t designed by telephony people. It&#x27;s very web-like. The authentication info is bigger than the call data required to set up a call.<p>Mostly this is for VOIP. Telcos with TDM or CDMA transmission have serious backwards compatibility problems. Ones who peer only with SS7 have problems but those can probably be overcome.<p>One big problem is that there are off-brand telcos who specialize in services for call centers. &quot;The Dialer Hardware is being hosted in our premises at Los Angeles - USA, where we have our own switch and termination facility with over 100 Carriers. We also have a redundant switch in New York connected to LA through a fat Fibre pipe.&quot;[1] Do those guys get to sign calls? Or what?<p>[1] <a href="http:&#x2F;&#x2F;www.callcentersindia.com&#x2F;showall-orig.php?value1=11268_Worlds_No_1_Predictive_Dialer-Concerto_Ensemble_Pro_60_on_Monthly_Subscription_basis" rel="nofollow">http:&#x2F;&#x2F;www.callcentersindia.com&#x2F;showall-orig.php?value1=1126...</a>
评论 #19452484 未加载
评论 #19450486 未加载
评论 #19450343 未加载
Barrin92大约 6 年前
Instead of all these fancy technical counter-measures I think this really ought to be a matter of the law. Why not ban cold calls, like in Germany? Is there anyone on this planet who actually enjoys constant advertisement and harassment on their phone?<p>&gt;According to Sec. 7 (2) UWG; telephone calls to consumers for sales purposes are illegal if the calling company is not in possession of an explicit and effective declaration of consent by the consumer. If the call is made to another business, it is sufficient to prove presumptive consent.
评论 #19449567 未加载
MagicPropmaker大约 6 年前
A little trick that will work for &quot;geeks&quot; but won&#x27;t scale is:<p>- My personal phone number is in a remote area code, of a sparsely populated state, from where I don&#x27;t know anybody.<p>- Any phone calls that come from this area code are blocked (well, actually, they have a silent ring tone.)<p>This gets rid of about 90% of the spam&#x2F;robocalls because these days, 90% of them spoof a local areacode&#x2F;exchange.<p>Of course, if everyone did this, they&#x27;d stop doing it. But it works for now and makes my personal cell phone useful. I did have to do some finagling to get my carrier (T-Mobile) to give me a phone with an area-code of a different state.<p>I don&#x27;t have a lot of faith that STIR&#x2F;SHAKEN will help in any real way. They&#x27;ll just have to rent numbers from people who don&#x27;t care about the law, and&#x2F;or registered with bogus information so it won&#x27;t be worth anyone&#x27;s while to find them.
评论 #19449822 未加载
评论 #19449428 未加载
评论 #19449469 未加载
alphabetter大约 6 年前
Several people have asked about the management of certificates for this solution. There is indeed a seperate certificate management body created called the Secure Telephone Identity Governance Authority (<a href="https:&#x2F;&#x2F;sites.atis.org&#x2F;insights&#x2F;secure-telephone-identity-governance-authority-launched-in-major-industry-effort-to-combat-unwanted-robocalling&#x2F;" rel="nofollow">https:&#x2F;&#x2F;sites.atis.org&#x2F;insights&#x2F;secure-telephone-identity-go...</a>).<p>The Governance Authority will define policies on how certificates are to be issued.<p>Any old certificate from a web CA won&#x27;t be accepted by the system.
评论 #19452870 未加载
stendinator大约 6 年前
I&#x27;m from Switzerland and I only ever get spam calls from the US or India - how come?
评论 #19450521 未加载
Latteland大约 6 年前
Sounds like a nice improvement. It appears to be a web of trust scenario, where you trust anyone else who is verified. Eventually I&#x27;m sure some spammer will break through into the circle. I hope that if there is some spammer penetration (so much money here it&#x27;s inevitable) every phone company should be able to track back where that last phone call came from and block them then.
评论 #19449038 未加载
patrickg_zill大约 6 年前
I read through a summary from a different source and I was not impressed.<p>Any voip phone, and of course smart phone, can be easily set up for client side certificates.<p>Landlines and anything else that can be accessed via SS7 methods are already secure in terms of identity.<p>And that&#x27;s it. Client side certs and you are done...
评论 #19453371 未加载
thosakwe大约 6 年前
I’ve noticed two main things about the many robocalls&#x2F;spamcalls I’ve received (my carrier actually has spam blocking, and I haven’t received very many since activating it)<p>1. Most calls I receive from numbers <i>not</i> in my contact list are spam. They also usually just call once, whereas if it’s a legit call that I was expecting, but neglected to pick up, they’ll call again within a few minutes. 2. I’ll get robocalls from one area code at a time. I remember getting calls from 772 one week, 727 the next, 643 a few days later, etc.<p>Obviously it won’t crush spam entirely, but I can imagine that fixing even just these two things would filter out a boatload if spam from reaching consumers.<p>Oh, and calls from “Scam Likely” should <i>never</i> reach my phone to begin with.
评论 #19450160 未加载
m0zg大约 6 年前
I do the following: I never give my real phone number to anybody other than people I directly know. Everybody else gets my Google Voice number, which is set up to directly go into voicemail without ever ringing. As far as I can tell, I receive 2-3 robocalls a day, so GV just blackholes them for me. Every now and then someone leaves a voicemail, and I read that, but it&#x27;s very rare that a robocall leaves a voicemail because Google call screener requires them to enter a number to do so.
_underfl0w_大约 6 年前
Hopefully this CA process will have a better threat model - that is, one in which they&#x27;re prepared for state-level malicious actors such as DarkMatter.
nerdbaggy大约 6 年前
Anybody know who the CA is now for these? Couldn’t find much
评论 #19449090 未加载