Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I worked on STIR/SHAKEN for the two biggest US operators. The techies tried very hard to make it work, and, indeed, there was a brief time when it worked pretty well, but, the incentives from Corporate were and are fundamentally misaligned.

Type A attestation is, generally, solved. Carrier A attests that the number is one of theirs, and they know that the caller is one of theirs too and attached to their network.

However: this is a fraction of calls. Carriers also sell blocks of phone numbers without the corresponding access network. This is what allows you to pick, say, a Twilio number with a local area code. In these cases the best that can be hoped for is a lesser attestation.

But it gets worse, because the operator can also sell blocks of numbers to people with no direct connection to the US carriers and who need to spoof US numbers. That call from Capital One comes from the Philippines via two or three intermediate operators, none of whom can attest to much of anything. And into that gap ride the spammers.

Furthermore, in an Experian-like twist, some carriers also realized that businesses would pay to have their calls show up as "trusted" on the recipient's phone. So the standards were enhanced to deliver 'rich call data'. However, in order to be something worth paying for you also need a baseline of calls that do not have that premium look. A scam? You decide.

Finally, one other misaligned incentive. All of this needs VoIP. Not TDM (classic legacy telephony). However, the big US carriers make bank selling TDM circuits to the hundreds of small regional telcos, and refuse to sell them SIP trunks, because it's s such an easy money maker. So again, technology loses to incentives. These incentives, to make money from phone numbers, vastly outpace what



So we can't block shady spammers because business wants shady customer support call centers? Ugh. It figures, but ugh.

Thanks for the inside perspective.


I'm going to mangle the terms of art here, but the ur-problem is that labels of routing, like phone numbers and email addresses, get confused with labels of identity, and then with indicators of trustworthiness.

Everything is built to address that weakness - think DKIM, SPF, etc, plus STIR/SHAKEN, to say nothing of IP or ASN filtering, but they feel like bandaids on a very difficult problem. What you end up with are basically default-deny except for a personally curated trust set ("only accept calls from my contacts", "everything goes in spam unless I have previously corresponded with the sender"), etc.

One last robocall story. AT&T sat on their hands for years until consumer groups embarrassed the then-CEO enough to do something about it. There was a memorable interview in the Dallas Morning News where they called him on it instead of lobbing him softballs and I suspect that the embarrassment finally got through.


Details please on the AT&T CEO story



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: