Email Analogy to Telecom

Comparisons between telecom spoofing and email systems—spoofed reply-to addresses, the evolution of email authentication (SPF/DKIM/DMARC), and similar trust-based origins.

← Back to The Australian Government to Require SMS/MMS Sender ID Registraion

The discussion highlights a persistent frustration with telecommunications providers for failing to curb Caller ID (CLID) spoofing, particularly the practice of allowing overseas entities to inject local numbers into the network. Drawing a parallel to internet security standards like BCP38, the perspective argues that telcos should technically and morally reject any customer input that claims an identity they do not legitimately own. While questioning whether this lack of action stems from technical dependencies like VoIP or a simple lack of willpower, the contributor suggests that even basic flagging or internal routing checks could significantly mitigate the issue. Ultimately, the viewpoint emphasizes that the current trust-based system is outdated and calls for a more rigorous authentication framework similar to the evolution seen in email security.

1 comment tagged with this topic

View on HN · Topics
I've yet to read a good explanation of why the telcos permit CLID faking and reinjection of apparently local CLID by overseas inputs. I'm assuming there's a technical and/or willpower reason or some counterfactual like VOIP depends on it. Even just flagging it would help. Or, rejecting numbers they can know lie inside their own routing architecture, or asserts within their own number plan where the CLID does not match. Morally it's like BCP38 in the customer facing internet systems: reject customer input they don't pay you to assert.