反诈工具赶不上机器人骚扰电话的诈骗速度
Anti-fraud tools can't keep pace with robocall scammers

原始链接: https://broadbandbreakfast.com/how-to-fight-back-against-fraudulent-robocalls/

在最近一次“宽带早餐”(Broadband Breakfast)专题讨论会上,行业专家探讨了打击网络钓鱼、骚扰电话和垃圾信息这一持久挑战。与会专家强调,虽然 STIR/SHAKEN 身份验证等工具很有用,但它们并非“灵丹妙药”。从传统有线网络向互联网语音通话的转变使通信更加普及,这让犯罪分子能够以低廉的成本轻松利用系统,他们往往利用人工智能,甚至通过获取合法电话号码来绕过安全防线。 由于电信运营商无法获知通话内容,且行业生态系统高度碎片化,专家们认为没有任何单一技术能解决这一问题。相反,他们主张采取多层次的防御措施:对企业进行更严格的“了解你的客户”(KYC)审查、加强跨行业协作,并提高消费者的警惕性。尽管针对有组织犯罪的执法工作已取得进展,但专家们告诫不应让电信运营商对诈骗损失承担法律责任,并警告称此类措施可能引发有害的过度屏蔽。归根结底,专家强调消费者仍是最后一道防线;他们呼吁公众举报可疑活动,并在有疑问时,在回复前先暂停并核实来电者的身份。

Hacker News 最近的一场讨论凸显了人们对骚扰电话骗局日益增长的挫败感,许多用户认为这种现象已经到了无法控制的地步。参与者认为,现有的防欺诈工具和监管机制(如 SHAKEN/STIR)之所以无效,是因为电信公司缺乏拦截这些流量的动力——它们往往既能从诈骗者的通话量中获利,又能向深受其扰的客户出售“高级”拦截服务。 评论者提出了一些结构性的解决方案,包括: * **财务问责制:** 对运营商实施保证金制度,若其网络助长垃圾信息,将受到经济处罚,从而激励其主动监管自身网络流量。 * **网络层过滤:** 从依赖终端设备上的应用程序,转向由运营商层面进行复杂的、基于风险的过滤,类似于某些 VOIP 提供商使用的系统。 * **白名单机制:** 许多用户主张设置“仅允许联系人呼入”,即将未知号码自动转入语音信箱,从而彻底消除垃圾电话的骚扰价值。 讨论的共识是,面对系统性问题,个人的努力已不足够。如果缺乏法律授权将运营商的利润与抑制骚扰电话挂钩,消费者仍将深陷于日益复杂、且常由人工智能驱动的电话垃圾“地狱”之中。
相关文章

原文

WASHINGTON, July 29, 2026 — The tools to fight phishing, robocalls and spam have multiplied over the past decade, but the criminals behind them keep adapting faster than any single defense can keep up, industry experts said Wednesday during a Broadband Breakfast Live Online panel.

Panelists said that there were no simple answers to the knot of problems. Authentication frameworks, traceback efforts, call blocking and enforcement all help, but only together, and only if consumers stay vigilant as scammers exploit cheap Internet-based calling and now artificial intelligence.

The rise of internet calling is what created both problems in the first place, according to Josh Bercu, executive director of the Industry Traceback Group at the trade association USTelecom. "It's become cheap and easy for you and me to call anyone around the country and around the world," he said. "Well, guess what? It's also cheap and easy for the bad guys to blow up our phones, call us from anywhere in the world."

That shift eliminated the old physical trust of wired networks. "If I'm providing service to the bank, I know they're the bank. I'm literally laying wire to the bank," Bercu said. "That all changed with the advent of internet calling platforms where I can say I'm a bank, and I might not be a bank."

The limits of STIR/SHAKEN

Much of the conversation centered on STIR/SHAKEN (Secure Telephone Identity Revisited and Signature-based Handling of Asserted Information Using toKENs), the call authentication protocol that both experts said was oversold. "Starshaken was never meant to be a silver bullet," said Joel Bernstein, vice president and head of U.S. public policy and government affairs at Somos. "This is a way we get to some level of understanding, and it's only in conjunction with other things."

Bernstein argued the industry needs to move toward a system he called right-to-use, which attaches cryptographic tokens to individual callers. "When I call, I have a cryptographic token that says, this is Joel Bernstein. Joel's been vetted," he said, describing a bank recognizing both the caller and itself as legitimate.

Even so, authentication has not solved the problem, Bercu said, because bad actors now obtain legitimate numbers. "Some bad callers now get access to numbers. So they can get the authentication. They have the right to use the number. They're still making bad calls."

Part of the challenge stems from a philosophical reversal in how carriers operate, Bernstein noted, recalling the Tom Wheeler-era FCC. "Competition, competition, competition. We want everybody in," he said. "Well, that opened the door to the bad guys. Now we're realizing, maybe it wasn't. [It] all started off great, but now it's been poisoned."

Calls, texts and emails

Moderator Drew Clark, CEO of Broadband Breakfast, offered a contrast between how well spam has been contained in email and how much harder it is to tackle spam phone calls over the telephone network. Private algorithms sucked up much of the email problem, but that model translates imperfectly, Bercu said, because visibility is fragmented across the ecosystem.

"Whether you're using the old [Short] Message Service, SMS or RCS [Rich Communication Services], who has visibility to that can be different, whether it's the operating system or the carrier," he said. "That adds to the complexity of the ecosystem, which frankly is why we all need to be partnering together across the different industries."

Carriers can read network signals but not the substance of a call, said John Nelson, counsel at the telecom law firm Davis Wright Tremaine. "A network provider can be great at looking through their call analytics, seeing how quickly someone is calling from a number," he said. "But you can't necessarily get into the actual content of the call."

That gap, Nelson argued, is why vetting matters. "Know your customer. I think that's extremely important on the back end, doing vetting of those individuals to understand the purpose of their calls," he said.

Reporting helps too, Bernstein said, urging consumers to flag every message. "That creates that group intelligence that we need," he said. "It is groupthink. You have to do this together. Otherwise it won't be taken care of."

What consumers should do

The economics keep the incentives strong. Loss to scams is rising roughly 25% a year, Bercu said, pointing to overseas operations. "Southeast Asian scam compounds. You have human traffic labor there. You have organized crime," he said. "Their whole market is the entire globe and every dollar that everyone has."

There has been meaningful enforcement progress, he added, crediting a federal executive order targeting transnational criminal organizations. "The local field agents are more likely to take the scam case and build a case now because they think the prosecutors will pick it up."

Panelists were critical of a Broadband Breakfast Member’s online proposal to hold carriers liable for phishing losses. Such rules encourage overblocking, Nelson warned. "You risk swinging the pendulum far too far in the other direction," he said, adding that fault is diffuse. "It's more than just the carrier at the end of the day."

For consumers, panelists suggested reporting spam and slowing down before responding to scammy calls or messages. 

"Take a breath, take a pause," Bercu said. "If something feels off, say you'll call back."

Bernstein agreed, citing his father's experience as a scam victim. "You have to be vigilant about this  step of the way," he said. "If it seems a little off, take a breath."

联系我们 contact @ memedata.com