Caller ID Spoofing Origins

Discussion of why telcos permit CLID faking, comparing it to BCP38 in internet routing. Historical trust-based engineering agreements between large national telcos, and how deregulation and smaller operators eroded that trust without retrofitting controls.

← Back to The Australian Government to Require SMS/MMS Sender ID Registraion

The persistence of Caller ID spoofing stems from a century-old legacy of "gentlemen’s agreements" between national telcos that prioritized trust over security long before deregulation introduced smaller, less reliable actors. This system remains largely unchanged because legitimate modern businesses, such as outsourced call centers, rely on the ability to display local numbers to maintain professional appearances for international clients. While critics argue for stricter routing controls similar to internet security standards, the sheer weight of legacy technology and complex legal frameworks makes retrofitting the global network a massive undertaking. Consequently, users are left seeking better transparency, such as the ability to see both the asserted number and the call’s true geographical origin to better manage their own security.

3 comments tagged with this topic

View on HN · Topics
I've yet to read a good explanation of why the telcos permit CLID faking and reinjection of apparently local CLID by overseas inputs. I'm assuming there's a technical and/or willpower reason or some counterfactual like VOIP depends on it. Even just flagging it would help. Or, rejecting numbers they can know lie inside their own routing architecture, or asserts within their own number plan where the CLID does not match. Morally it's like BCP38 in the customer facing internet systems: reject customer input they don't pay you to assert.
View on HN · Topics
I used to work at two (UK) telcos. There's a historic reason and a modern reason. The historic reason was, just like the Internet, the international phone network was built on gentlemen agreements by engineers who largely trusted each other. A big national telco is unlikely to attack its peers, so there was little need for safety measures. As smaller telcos came in to the mix via deregulation, that understanding changed - but it was hard to retroactively fit controls. The more modern reason is outsourced call centres. You want outbound calls from your Philippines based staff to show as if they were calling from a local number. When large and reputable entities were doing this it was fine. Just like showing a different reply-to address on an email. If you were designing a modern network, it wouldn't be like this. But international telephony is over a hundred years old and has a huge amount of legacy technology and legal agreements.
View on HN · Topics
I am sure there are reasons why this won't work, but could it really be so hard to show both the faked number, and where the call actually comes from, so I could choose which one to add to my block list.