I never understood what are the technical obstacles to building the phone network in such a way that caller numbers can not be spoofed or suppressed. Then, you could just build a system where receiving an unsolicited phone call from a commercial entity entitles you to a compensation in small claims court, to the tune of 50 EUR, unless the caller can prove that you explicitly authorised them.
The problem is not that the originator can be found. The current, existing, legacy, phone system already can find the exact originator.
The problem is that enforcement of breaking the regulation is so non-existent that the criminals just place millions of calls knowing, at most, they might get a minor slap on the wrist that can be budgeted for as a "cost of doing business".
Every single call carried across the phone network is billed, and every hop along the path knows who to bill for their part of carrying the call. The billing system is the method to trace back to the originators, and then apply a fine sufficiently large enough to no longer be a cost of doing business.
But the regulators seem to have no idea that the billing system provides the traceability to find the criminals and then go after them. Instead we get things like stir/shaken that are trying to patch "authenticity" on top of a network never designed with that in mind.
AFAIK, the problem is that the system works like international mail used to.
There are strict barriers at the borders to ensure everybody pays their dues. But once a call is accepted, there's no control at all about where it's going to.
The problem is that it's a network. The hard part of networking isn't the technology - it's the other people. And short of a government regulation or a monopoly, they'll never all agree.
STIR/SHAKEN has an exception for calls passing through TDM trunks, which don't support it. This created a small industry for passing spam calls through TDM trunks. Such calls can trivially have their caller ID spoofed.
Phone companies used to be monopolies, in Europe they were owned by the government as a public service. But when they become profitable politicians betrayed their citizens and sold them. Nowadays, phone companies are a source of scams, spam and everything wrong with big corporations. And all that profits are now private instead of helping to fund the country.
On this topic, phone lines are so ubiquitous that it is irresponsible for representative governments to continue to let private companies mess around with them. Doubly irresponsible to go from public to private after the increase in popularity.
That was in the 2000s. Phone lines are an anomaly now but cellphones are not. The phone number is more like an ICQ number than an identifier of a physical connection, but is still regulated like the latter.
Why are those non-STIR/SHAKEN TDM trunks serving as transit trunks (non-terminating), rather than terminal-only trunks? Seems a pretty obvious hole to close.
The only limitation is cold hard cash. The phone companies make big bucks from telemarketers by providing an endless list of new numbers and multiple lines. The whole racket wouldn't work without the companies' greenlight.
Exactly. The same reason the bulk of paper mail is unsolicited garbage. The spammers/scammers are paying customers, without regulation the incentive for the phone company is to keep them flowing.
Compare to how effective spam filters are on email. It's a much harder problem, but the spam costs the provider money, so they address it.
Historically, in a world of analogue phone lines, spoofed phone numbers were a legitimate feature: if my business has more than one phone line, each of those lines is going to have its own distinct number; but I'm going to want outgoing calls from any of those lines to appear to originate from the same number (the one that I put on my promotional material, invoices, etc.).
Much the same as e-mail, identity within the phone system was, historically, entirely built on trust (because only Ma Bell could make configuration changes, and they could verify that what their customer was asking them to do was legit). Those assumptions were carried through deregulation, and are very deeply entrenched in the technical design of the network. Changing them will hopefully become easier over the next few years as analogue service is turned off entirely (e.g., BT/OR in the UK are set to turn off all analogue phone service by the end of January 2027).
I've seen two reasons. 1) Backward compatibility--you would have to add an additional security layer, and some old legacy switching hardware (5% of the network?) wouldn't support this. 2) Phone companies profit from the calls, so they have no incentive to spend the money to upgrade and stop it.
Yes, but the premise here is that for national calls it becomes harder to spoof the caller id. In fact, here in Italy we're seeing an increase in telemarketing calls from Spain and France, so it's not entirely hypothetical.