STIR/SHAKEN Protocol

The FCC-mandated cryptographic authentication system for caller ID in the US, its slow rollout, limitations (doesn't cover SMS/MMS), and its role as a technical solution to spoofing problems.

← Back to The Australian Government to Require SMS/MMS Sender ID Registraion

While the FCC’s STIR/SHAKEN protocol aims to curb fraud through cryptographic authentication, its slow rollout and exclusion of SMS leave significant gaps in modern telecommunications security. Critics argue the system may struggle to stop common spam calls that lack registered IDs entirely, while others highlight even more dangerous vulnerabilities in the legacy SS7 network that allow foreign actors to track individuals. Despite these limitations and the technical hurdles of identifying a call's true origin, industry insiders emphasize that these tightening regulations are a necessary, albeit disruptive, step toward securing legitimate business communications.

5 comments tagged with this topic

View on HN · Topics
The mechanism is https://en.wikipedia.org/wiki/STIR/SHAKEN But it is slow to roll out.
View on HN · Topics
That's why in 2020 the FCC belatedly mandated SHAKEN/STIR to authenticate Caller ID in the US using public-key cryptography. Deployment is still work in progress, and it does not cover SMS/MMS, however. A bigger problem is Russia or Saudi Arabia using the SS7 signalling network to track their dissidents in the US because those legacy telco protocols have basically no authentication whatsoever, and won't blink if a Saudi Telco sends Verizon a MAP message saying "what is the cell location of Jamal Khashoggi's phone?"
View on HN · Topics
I don’t think this will cut down on spam so much as fraud. All spam calls I get don’t have registered IDs
View on HN · Topics
I am sure there are reasons why this won't work, but could it really be so hard to show both the faked number, and where the call actually comes from, so I could choose which one to add to my block list.
View on HN · Topics
It's not. Together with ongoing global tightening of regulations for permissible caller IDs on phone calls, it's all about fighting fraud. (I work in the telecom industry and am in the middle of all the waves this is causing for legitimate business cases.)