Showing posts with label Robocalls. Show all posts
Showing posts with label Robocalls. Show all posts

Thursday, June 20, 2013

Malicious Phone Calls - *57 results

This is an update to a previous post (http://sigma5.blogspot.com/2013/06/malicious-phone-calls.html).  Today I got yet another robocall.  I didn't even stay on the line long enough to find out who was calling.  After hanging up I decided to stop stalling around and see what happened if I did the "*57" thing.  So I tried it.  The results were less than completely satisfactory.  I got a recorded message indicating that I was being charged $1.50 and that if it was a life threatening situation I should hang up and dial "911".  Then the message started repeating.

I hung up and mulled for a while.  Then I picked up the phone (same phone) and dialed "0" ostensibly to be connected to the Operator.  This put me into an "answer tree" that was mostly set up to allow me to change my telephone service.  I did end up eventually getting to an "operator" or at least a live body.  When I explained that I was trying to get some information from my "*57" trace he transferred me to "customer service", actually could more accurately be described as sales.

The person I talked to was not familiar with the "*57" service or malicious phone calls or call traces.  He did say that "*57" was a "third party service".  Eventually he transferred me to his supervisor, a "David N in North Idaho".,  He couldn't provide me with any of the trace information either.  The best he could do was to say that "if I had caller ID", which came bundled with some kind of long distance package, and he couldn't tell me what such a package would cost, then somehow this would help.  By this time I was pretty frustrated and he accused me of being unprofessional (apparently being unable to provide any service or information on his side is not unprofessional but my being annoyed with his inability to provide any information or service is unprofessional).  Anyhow, eventually he hung up on me without providing any help.

I decided to try again and called the "operator" again.  Again after a couple of rounds with the "answer tree" system and another person I ended up back at customer service.  This person was better informed and slightly more helpful.  She suggested I call the "annoyance call bureau", which she described as an industry organization, at 800-582-0655.  I asked her if she could reverse the $1.50 charge.  She said she couldn't because it hadn't come through yet but she put a note in my file.  She also indicated that I could get it reversed when it came through on my bill.

So I called the annoyance call bureau.  The "answer tree" system I was connected to did indicate that it was part of Century Link, my "land line" phone company.  One of the first things the "answer tree" did was ask if I had done a "*57" trace.  I selected the "yes" option.  This all happened before I was connected to a person.  I asked this person if they could identify or give me contact information on the "third party service" that apparently performs the "*57" function.  She could not.  I asked her if she could give me the results of the trace.  She could not.  The information was only available to law enforcement (and the NSA).

She recommended in the future that I do a "*69".  This is effectively a one time caller ID where a voice gives you the information.  When I asked if the "*69" information could be blocked or spoofed she said that it could.  I asked her what the next step was assuming that I had done the "*69".  She indicated that my only option was to fill out an FTC complaint form.  Given that it is cheap for businesses to block or spoof caller ID this is not much help.  I have written about the "robocall challenge" (http://sigma5.blogspot.com/2012/10/fcc-robocall-challenge.html) previously.  The fact that the FCC ran the contest indicates exactly how effective filing a complaint is.

The "annoyance bureau" lady did indicate that she could get my $1.50 charge reversed.  We'll see.

In summary, the good news is that "*57" is out there and that it works at the basic level of tracing a call.  The bad news is the rest of the story.  Maybe other phone companies do a better job in this area than Century Link but I doubt it.  So the approach I recommended in the post linked to at the top of this piece looks more feasible than ever, again assuming that the trace information is real and can't be blocked or spoofed like standard caller ID can be.  And I can't say I am surprised that the NSA gets better service than I do from the phone company.  They have actual clout and I, as a member of the "99%", don't.

Saturday, June 8, 2013

Malicious Phone Calls

I have attacked this general subject before.  My first post was http://sigma5.blogspot.com/2012/02/rachel-from-cardholder-services.html dealing with my efforts to do something about the calls from "Rachel from Cardholder Services".  Later the FCC announced a contest to solicit ideas for dealing with the problem.  So I did a post about that (http://sigma5.blogspot.com/2012/10/fcc-robocall-challenge.html).  Since the "FCC" posting I have become quite discouraged.  In retrospect my proposal looks quite complicated.  Then in the last few days something apparently totally unrelated happened that gives me renewed hope.

It was reported that the secretive NSA, the organization within the Federal Government responsible for collecting and analyzing "Signals Intelligence", was receiving a record of every single phone call made from or to a telephone serviced by the Verizon telephone company for a period of three months.  It is since come out that this is a routine procedure.  The authorization for the NSA to sweep up this information from Verizon must be renewed every three months.  So the specific authorization leaked is one of a series of standard authorizations issued routinely every three months.  And it appears that similar requests are made every three months to all the other telephone companies too.  So apparently the NSA has a record of every phone call made to or from a U.S. phone number for a period of years.

This revelation is very troubling.  Yet it has been coupled with other revelations.  It appears that the intelligence community has ways (the details are still being argued about) of getting access to the text of emails, web search histories, pictures, all kinds of web postings (like private blog postings), and other "content" information.  It may also be that the actual contents of phone conversations (e.g. if they used Skype or if a leg of the conversation transited an IP phone link) may be available some or all of the time.  The official stance of the security services is that spying only takes place if there is a foreigner on one or both ends.  But much of the legal opinions, court proceedings, rules and procedures, etc. are top secret.  As an example the FBI can issue something called a "National Security Letter".  The recipient of one of these is directed to provide all kinds of personal and private information.  They are also required to keep the National Security Letter itself a secret.  So the target of one of these letters can't even find out that he is the target of the letter, let alone whether the justification for issuing the letter in the first place is valid.

So you can't find out what's going on because it is secret.  You can't find out if whoever did it acted legally or properly according to the appropriate laws and regulations because when and how the laws and regulations are applied is secret.  In fact, you can't even find out what the laws and regulations say because even that is secret.  This situation is correctly described as Kafkaesque (after actions described in a novel called "The Trial" written by Franz Kafka and first published in 1925).  The primary legal foundation for these activities lies with a law called the "USA PATRIOT Act" (originally passed in 2001 shortly after 9/11 and reauthorized and updated a couple of times since) and the "FISA Amendments Act" (one of a series of laws relating to "FISA" courts, this specific one was originally passed in 2008 and reauthorized with minor modifications in 2012).  The provisions authorized in these laws essentially eviscerate the Fourth Amendment to the U.S. Constitution ("The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized").  I think that major provisions of both acts are completely unconstitutional.  But what do I know?  As I have remarked elsewhere, (http://sigma5.blogspot.com/2013/01/second-amendment-rights.html), the Constitution means what the Supreme Court says the Constitution means.

And here I am refighting a fight that has been going on at least since the PATRIOT act was first passed.  The fact that Congress has chosen by big bipartisan margins to authorize and reauthorize these laws in spite of the many people who agree with me means that it is old news that I am on the wrong side of this argument.  In fact, these new revelations have been greeted widely with a reaction of "no big deal" by large segments of the general population, legislators, and the media.  So what I want to do instead is move on to an issue that is peripheral to the recent revelations but central to the whole issue of Malicious Phone Calls.

One of the big problems with dealing with "Rachel" and her ilk is the problem of tracing the call.  I date back a while.  I remember old movies and TV shows where the cops were trying to trace a phone call, say in a kidnapping situation.  Back in the old days it would take a couple of minutes to trace a call so if the bad guy hung up quickly enough the cops were foiled.  Things progressed to the point where in the movie "Three Days of the Condor" (1975) our hero had to wire together a bunch of pay phones in phone booths (kids:  ask your parents if you don't know what I am talking about) to avoid having his calls traced.  Theoretically, tracing a call is now a simple and instantaneous process.  You just get Caller ID and it tells you what the caller's phone number is.  But the "Rachel" people have been able to block (no caller ID shown) or "spoof" (cause a bogus number to be displayed) Caller ID so it doesn't work.  I didn't really know how to get around this.  So I came up with the complicated plan described in the "FCC" post.

But a detail in the recent NSA revelations indicates that call tracing information is available after the call is completed.  Apparently Verizon ships the call data to the NSA about a day after the calls happen.  And I am confident that the data the NSA gets includes the real originator of the call.  If the bad guys could just block or spoof Caller ID then they would and the data would do the NSA no good.  What this means is that in the hunt for "Rachel" nothing has to be done while the call is still in progress. And all the Rachel types have an "instant hangup" device so they can and will cut the call off any time they want.  But they can no longer beat the "trace" by just doing an instant hangup.  This ability to get usable trace data after the call is over makes everything much simpler.

Having gotten this far, my next thought was to use a telephone "star" code.  You know those star-this and star-that codes that do interesting things.  For instance, if you dial "*69" it will dial back the person whose call you just missed.  Or in the old dial up modem days we would add a "*70" on the front of phone numbers so that your computer session would not be disrupted by a "call waiting" announcement.  My thought was to add a new standard star code so that you could report a Rachel call after it ended.  But it turns out there is a standard list.  You can find it in Wikipedia (where else) in an article titled "Vertical service codes".   And we don't have to add a new code.  "*57" is defined as "Malicious Caller Identification".  "*57" is also sometimes referred to as "MCT - Malicious Call Trace" or, even better, "CAMCT - Caller Activated Malicious Call Trace".  This code is perfect for our purposes.

I had never heard of "*57" before so I suspect few people know about it.  That leads me to believe its implementation is spotty and inconsistent.  But I really don't know.  So, on the theory that it is spottily or inconsistently implemented, here's my plan for how it should be implemented:

Basic version

All telephone companies would be required to implement "*57".  Whenever a customer received a Malicious call that call would eventually come to an end.  After the call ended the customer would, using the same phone line, pick up the handset, get a dial tone, then dial "*57".  (On cell phones the user would enter "*57" then hit the "dial" button.)  The phone system would recognize the code.  This would cause the phone system to locate the call record for the previous call to the same line and instantly forward it to the FCC.  The record would be tagged with the phone number of the line that had entered the "*57".

Over time the FCC would accumulate a database of Malicious calls.  The call originator would be easily identified.  If an originator accumulated a sufficient number of malicious calls then the FCC would investigate and act accordingly.  The telephone business is a business.  This means that someone "owns" every phone number in the sense that some phone company bills someone for every "in use" phone number.  The Malicious call origination data should be aggregated by the person or company that owns the number the call originates from.  If I own a thousand numbers then all the Malicious calls that originate from any of those thousand numbers should be bundled together.  This would take care of the situation where a Malicious caller distributes the originating numbers over a large group so that no single number stands out. To discourage misbehavior by the phone companies the FCC should allocate Malicious calls from numbers where the owner can't easily be determined to the phone company that controls the number.

This basic version would go a long ways toward a fix to the problem.  But more could easily be done.

Advanced version

This would work like the basic version but in addition the caller would be automatically connected to the FCC.  We are all familiar with how complex automated answering systems can be so by "FCC" I really mean an automated answering system managed by the FCC.  This automated answering system could collect additional data by running the customer down an "answer tree".  Here are some ideas for what data could be collected:

  • Was the caller an individual or a company?
  • Was the call associated with a police related matter (e.g. violation of a "no contact" order)?
  • Should the information from this call be made available to law enforcement (e.g. authorization to release the information to law enforcement without requiring a search warrant)?
  • Was the call associated with a potential scam (e.g. "Rachel")?
  • Was it an annoying but probably not illegal call (e.g. survey or charitable solicitation)?
  • Did the call appear to be a prank or annoying call rather than a serious threat?
  • Does the caller wish to remain anonymous or can the reporter's billing information be forwarded to the FCC?
  • Does the caller want to leave a voice message with additional information ("This is a "Rachel" call" or "This is a call from my ex-husband Frank")?
These are just suggestions for a starting point.  All and much more is easily within the capability of standard commercially available "answer tree" automated phone answering systems.  So the whole data collection system could be implemented completely automatically and very inexpensively.  The "answer tree" could evolve based on experience and new requirements.

With the advanced version it would be possible for a person who received a threatening call from someone under a "no contact" order to "*57" at then end of the call, select the "release the data to law enforcement" option, hang up, then call 911.  The 911 operator could then query the FCC database through a "law enforcement" portal and be immediately shown the call information of the released call.  I don't know what the current procedure is for these situations but I can't imagine it operates as smoothly, efficiently, or potentially effectively as the scenario I have outlined.

In the case of "Rachel" calls the current procedure is to go to the FCC web site and fill out an online complaint form.  But "Rachel" has spoofed or blocked the caller ID, if it is available.  And when you get through to a person they do not provide you with the name or contact information of the "Rachel" people.  So you don't have the information the FCC needs most to be able to effectively deal with these people.  You have to leave key entries in the complaint form blank or enter "don't know".

My "Rachel" calls started years ago.  They kind of reached a steady state where I would get a "Rachel" call perhaps once per week.  Then the FCC filed suit against 5 "Rachel" companies and things went blissfully quiet for a few months.  Then they started back up.  Only now besides "Rachel" I get calls from people who want to clean my ducts or drapes or carpets or something else.  All these calls are completely illegal.  But the people behind these calls know it is extremely unlikely that they will ever be caught.  And if they are caught they will receive a slap on the wrist and they can open up again in a few days under a different name.  So I now get more of these kinds of calls than ever.  And I also get tons of "survey" calls, "political" calls, charitable solicitation calls, and other legal or quasi-legal but quite annoying calls.  Its worse than ever.

Sunday, October 21, 2012

FCC Robocall Challenge

The FCC is running a contest called "FCC Robocall Challenge".  Details can be found at the following location:  http://robocall.challenge.gov/.  I have blogged about robocalls before.  See:  http://sigma5.blogspot.com/2012/02/rachel-from-cardholder-services.html for details.  So this subject is near and dear to my heart.  I think the FCC is slightly misguided.  They think the winner should come up with a solution, presumably a gadget, that "should block robocalls".  I think a proper solution consists of a number of components.  Some of these components would be hardware.  But other components would be processes or procedures.  Here's my solution:
 
Telco component

All telcos (anyone providing dial tone and access to the international telephone network) must provide the following service, implemented by a code, to their customers.  Someone on the contest web site suggested using “*111”.  I will leave it to the experts to decide what actual code would be used.  But when a customer receives an inappropriate call (e.g. a robocall) the customer will enter the code on his telephone keypad while the call is in progress.  This will cause the telco to record and retain certain information about the call.  Entering the code will also cause the call to be flagged as a “logged” call.  The customer will also be able to enter the code up to five minutes after the call ends in normal circumstances.  The window will expire immediately if the customer has not logged the call before making an outgoing call.  Also, if a new call comes in within less than five minutes, the window will expire immediately if the customer does not enter the code to flag the old call as a "logged" call before connecting to receive the new call.

Telcos will maintain the information on logged calls for a minimum of a week (7 days).  Then, if the customer “registers” the call within the one week period, the information will be retained for whatever period is appropriate.  Once the information is transferred to e.g. an FCC database it can be deleted from the telco system.

The telco will collect and retain the following information when the call is logged:
- Nominal caller ID of the source.
- True source of the call.
- Nominal caller ID of the destination (customer).
- True destination of the call.
- Call start date/time.
- Call end date/time or call duration (Experts can decide which).

Note:  A telephone call is a two way process.  To work both the true source and the true destination must be known to the telephone system.  This is the information that will be collected as the “true source” and “true destination”.

Note:  Crime TV shows make reference to “LUDs”.  If “LUDs” are a standard part of telephone infrastructure and the information in a LUD is equivalent to the information listed above then collecting a LUD for the call meets my requirements and no new special record type will be needed.

Customer component

This component is optional.  But, if provided, it must operate as described.

First let’s consider a standard “land line”.  For the moment let’s also assume that the line has a customer provided answering machine.  The new component can be thought of as an “enhanced” answering machine that would replace the standard answering machine.  The enhanced answering machine would require an Internet connection (e.g. Ethernet or WiFi connection with an IP address assigned to the device).

The enhanced answering machine would process calls that “go over to the answering machine” in the usual manner.  But the enhanced answering machine would also speculatively record the first five minutes of all “live” incoming calls too.  The telephone system started going digital in the 1960s.  At that time a standard was established that converted the audio component of a conversation to a digital format.  The digital data consisted of 56,000 bits of data per second of conversation.  This is equivalent to 7,000 bytes of data.  The enhanced answering machine will record the data in a standard format specified by experts that has a fidelity equivalent to the old 56,000 bits per second standard.  Assuming no compression, a five minute recording would consume 2.1 million bytes of storage.  This is well within the capability of inexpensive computer technology available today.  Multi-Gigabyte thumb drives are readily available for about $10.  If the standard included compression or other techniques, or the call lasted less than five minutes, the file could end up being much smaller.  And the file should be encrypted using standard techniques for privacy reasons.

So the enhanced answering machine would speculatively record all incoming calls.  If the call was not logged (see the above rules) then the recording would be silently discarded.  Logged calls would be retained and a standard technique would be specified by the experts for transferring the recording to an Internet capable device (e.g. a computer).  Vendors would be required to provide a minimum capability to record and retain one logged call at a time.  The recording could be silently discarded after a week at the discretion of the device maker.  The device maker could optionally provide the capability to retain more than one recording or retain it for longer than a week.  The device maker would just have to spell out the actual capabilities over and above the minimum in the documentation for the device.

What is important here is the capability, not the specific hardware implementation.  An enhanced answering machine is certainly an easy way to understand the required capability and feasible way to implement the capability in the case of a standard land line.  But a lot of people now use smart phones.  All the required capability can be implemented in a high end smart phone using software without requiring an external box or other supplemental hardware.  Many people have an “answering machine” service provided by their telco using equipment not located on the customer premises.  The telco could enhance their ”answering machine” service offering to provide equivalent capabilities.  Or they could choose to not provide the additional capability.  The only thing I require is that they be clear with their customers as to whether their “answering machine” service provides the described enhanced capability or not.  If their offering did not provide the enhanced capability then customers would be free to decide whether they wanted to continue the telco provided service knowing that message recording would not be available to them or to instead go ahead and acquire an enhanced answering machine device to replace the telco offered service.

The registration process

We now have much more information available than before.  We will now always have the logged information for all flagged calls.  Where the additional capability exists (e.g. the customer has installed an enhanced answering machine) we also have a recording of the first five minutes of the incoming call.

A change would be made to the current process for registering a complaint with the FCC.  Currently this is done through the FCC web site.  The new process would be done through a telco web site or through a free down loadable app for smart phones or free app provided by telcos to their customers that would run on an Internet attached customer PC.

The telco would validate the identity of the customer e.g. by a log in process to their web site.  In the case of a smart phone app, validation is automatic because the app runs on the customer smart phone and would only use data available on that smart phone.  The registration/validation process should be simple in the case of a web site.  And customers could log complaints to the FCC about their telco’s process if they did not like it.

Using the telco web site, smart phone app, etc. the customer would be able to see his recent logged calls.  He would then be able to select one or more to “register” as a complaint with the FCC.  The complaint information would be passed through to the FCC from the telco web site, app, etc.  The detailed specifications I leave to experts.  But I envision an implementation where the telco web site "front ends" for the FCC web site.  The telco web site would be responsible for a "pass through" capability to pass the logged data and, if present, recording file, along to the FCC web site.  The FCC would incorporate the logged data and, where it exists, the recording into the complaint.  This is why the smart answering machine would need Internet access.  The "Internet access" for this device could be restricted to the customer’s local LAN.  The PC could pull the file from the smart answering machine and upload it into the complaint package.  In the case of a smart phone or telco provided enhanced answering machine service the appropriate procedure would be used to include the recording in the complaint package.  Timestamps would be used to match the correct recording to a logged call record.

FCC process

The FCC would now have much more information and much more reliable information for evaluating complaints.  The FCC project is designed only to address inappropriate robocalls.  So let me proceed along that path for a while.  It is probably impossible to automatically identify robocalls.  My recommendation is to not try to do it automatically.  Use volunteers instead.  The same registration process for the telco web site would be use to register volunteers with the FCC.  The volunteers would listen to the recordings and evaluate manually whether the complaint was valid.  They would not know the identity of any of the parties involved.  All they would know was the type(s) of complaint alleged by the customer.  Multiple volunteers would evaluate each recording and a super majority would be required to validate the complaint.  The FCC would act accordingly in the case of a validated complaint.

Certainly this is a good process for dealing with robocalls but it is easily extended to handle other cases.  This is done by giving the customer some options for characterizing the problem when a complaint is registered.  One would be “robocall”.  But another big problem is with live operators making illegal marketing calls (i.e. violating the “do not call” list).

I suggest that a rule be implemented that required all robocalls to include the name and a "contact" phone number for the organization making the robocall.  The information must come in the first minute of the call.  Customers could complain that the caller was not doing this or that he was providing bogus information.  (It should be a serious crime to omit the information or provide bogus information).  The same information would be required for “live operator” calls if the customer requests it.  This permits a number of complaint categories:

- Company name omitted or bogus
- Contact phone number omitted or bogus.
- Contact number does not work (not answered or calls are not returned).
- Inappropriate contact (i.e. call not permitted by “do not call” exceptions).
- Illegal Robocall (marketing call rather than a e.g. "snow closure" informational call).
- Etc.

If the call contains misleading or bogus information the caller would first be gone after on this basis.  If the contact name and phone number is correct then complaints would be aggregated by who is making them and the “use many separate numbers to originate the call from” trick would no longer work.  This system would also catch spoofed “caller ID” numbers, which should be illegal, if it is not already.

Beyond the FCC

The FCC process for dealing with robocalls has been a failure from a customer perspective.  It is possible that the FCC, even with this new capability, would not do an adequate job.  So I recommend that individuals (or a class of individuals in a class action suit) be allowed to file a lawsuit in the situation where the FCC declines to prosecute.  I believe that robocallers do not want to find themselves in a court room where they will be judged by a jury of citizens.  This implied threat should allow the FCC to be much more effective than they currently are.  Violators know that they are pretty toothless now.

This system can also be expanded to cover situations beyond robocall and “do not call” problems.  An obvious example is harassing phone calls.  Here the information would not go to the FCC but to law enforcement or the court system.  In the worst case, the basic call information would be available.  In the best case, a recording of the first five minutes of the call would also be available.

Basic threats e.g. “husband threatening to beat wife” situations could be dealt with directly.  But other problems (e.g. “heavy breathing with caller not identified”) could also be addressed.  The same third party validation system would be employed.  This would filter out reverse harassment situations where the recipient is alleging harassment when none is actually present, at least not in the first five minutes of the call.

Analysis

Every indication is that the vast majority of robocalls originate from a small number of abusers.  The above system seems slow and cumbersome but it will yield results that will actually solve the problem.  It will take some time for the telcos to implement the logging process.  It will be some time before customers have enhanced answering machine capability in large numbers.  But it will get us to where we want to be in the end.

If the FCC contest yields what they say they are looking for (e.g. an inexpensive robocall filter device) it will be some time (years) before most customers have one.  Likely the device will cost more than the enhanced answering machine device that is part of my proposal.  So the aggregate cost of the FCC approach will be the same as or higher than the cost of my proposal and will probably take the same amount of time or longer to implement.

I see only one long term problem to my proposal.  If my proposal is successful then robocalls and other similar telephone related problems will plummet.  At that point the number of volunteer listeners will probably also plummet.  But the need for listeners will plummet too.  At that point it may be necessary to pay listeners to attract and maintain a sufficient number of them.  If we get to this point perhaps some fine or fee will be needed to provide the money to pay the volunteers.

Finally, there are some areas I have not addressed.  For instance:
- How is the volunteer pool managed (e.g. weeding out bad performers)?
- A lot can be done with just the registered complaints data, e.g. statistical analysis.
- Should the complaint database be published? (Of course!)  How?
- How to deal with legitimate but unpopular callers (e.g. ethical collection agencies).