logoalt Hacker News

amiga386today at 12:17 PM0 repliesview on HN

> we really do need a technical solution, which is unforgeable and easily traceable access to the telephone network

We have that, but it's insufficient.

https://en.wikipedia.org/wiki/STIR/SHAKEN#Limitations

    Although STIR/SHAKEN is frequently described as a "caller ID authentication technology", it does not authenticate any caller ID per se. Instead, it authenticates the originating carrier, but that solves a different problem. [...]

    It critically relies on a set of trusted certificate authorities (CAs) to manage digital certificates. In the USA, several telecom companies were appointed by the FCC as the CAs. They serve as the root of the trust. All other telcos, must not only trust these CAs but also pay them for compliance with STIR/SHAKEN, typically based on a percentage of their annual revenue. The reliance on trusted third parties severely limits STIR/SHAKEN to work across borders.
> Plus robust enforcement of consumer laws, something wildly out of fashion in the US.

Quite.

https://en.wikipedia.org/wiki/TRACED_Act#Criticism

    The act requires FCC referrals to DOJ for willful robocall fraud. In the half-decade since enactment, with billions of scam calls and billions of dollars in consumer losses, the FCC made less than a dozen referrals.