Comment by orbital-decay

5 hours ago

Infeasible. Fraud or spam is usually pretty hard to confirm from one recording without additional context. Many scammers have plausible deniability or are just checking whether the number is active. Moreover, this solution would involve secret non-consensual recording; what if it's not a scam?

I'd make one significant change to the proposal in the comment.

The delivery penalty applies to any unsolicited email, as determined by the recipient.

If also tagged as scam, those are further forwarded to law enforcement (state, national) for investigation.

Many US states are one-party regarding recording. Even in two-party states (CA, OR, WA, MT, IL, PA, MA, CT, NH, MD, DE, FL), disclosed recording and continuing a call will generally be construed as consent. If that's not the case, proposed state or national legislation could carve out exceptions as needed, and there'll likely need to be some legislation required anyway, so that's part of the process.

But shifting the fee element from fraud (one class of unsolicited call/text abuse) to undesired contact makes sorting when the fee applies far more evident, and eliminates a class of other objections (e.g., due process) from consideration.

  • I sign up for a newsletter from Google, then I report it as unsolicited. Boom, I just made Google pay me $10.

Plus, who is ‘confirming’ the spam? The same entity (or group: carriers) that is keeping the $10 and paying the $100 out? That just means the result will always be ‘not spam.’

  • This is why fees should be structured such that all carriers are on the hook, but upstream carriers inherit the obligation, possibly with an increased liability per hop, implying that downstream carriers can utilise enforcement as a profit rather than cost centre.

    Scenario:

    - Spamford places an unsolicited call to subscriber Alice initiating from MalTelCo, transiting carrier hops BunnTel1 and BunnTel2, to Alice's telco carrier, EndTelCo.

    - Carriers MalTelCo, BunnTel1, BunnTel2,[1] and EndTelCo have all placed surety bonds, held by BondCo, to practice telephony operations within the jurisdiction (regional/national). The carriers are the Principals, BondCo is the Surety, and receiving subscribers (or telcos, see below) are the Obligees.[2]

    - Unbonded carriers may have their traffic refused by peers. Peering to an unbonded carrier places the bond obligation on the receiving carrier.

    - Alice flags the call as spam. A per-call surety of $100 is paid to Alice, and charged to EndTelCo against its BondCo contract. As an additional option the call may be flagged as fraud through the phone system, in which case it is automatically referred to LEO by EndTelCo. Obligation of surety is independent of any fraud finding and is based SOLELY on the unsolicited nature of the call.

    - EndTelCo has the option of 1) eating the charge or 2) filing a claim against its peer, BunnTel2, the 2nd hop in the chain, which EndTelCo does.

    - BunnTel1 similarly files a claim on BunnTel2.

    - BunnTel2 files a claim on MalTelCo.

    - MalTelCo now eats the claim (it's paid out by BondCo). MalTelCo may seek further compensation from Spamford, but that's Out Of Scope of the bonding / surety schema, and would be covered by MalTelCo's own terms of use.

    - BondCo assesses risks and adjusts its surety rates correspondingly based on observed behaviours (and financial risks) of EndTelCo, BunnTel1, BunnTel2, and MalTelCo. If risks are excessive and no surety can be issued, MalTelCo is unbonded, and hence, decertified. Peers may now refuse traffic without penalty.

    Note that no one carrier needs to know anything more about a call's routing than its own network boundary. If EndTelCo has no idea that BunnTel2 and MalTelCo were involved, it doesn't matter, because BunnTel1 is on the hook for passing on the call. Spoofing or falsifying records doesn't save you.

    There are some questions over how this might be implemented, though generally:

    - If Spamford and Alice are both subscribers to EndTelCo, then EndTelCo eats the surety, which is paid to Alice. There's no upstream. Moral: Telcos, don't spam your own customers.

    - One thought is that the surety is split among telcos and the subscriber. Rather than just facing a potential cost, transiting and reciving-end-point carriers could see revenue by tracking and prosecuting unsolicited calls. This could include calls received by monitoring numbers set up strictly to assess unsolicited call activity directed to the network. This would mean that calls transiting multiple carriers would be subject to compounded surety claims ... and ... I think I'm OK with that.

    - There would all but certainly be classes of calls which would be exempted from claims. Those should be very limited, preferably to government and specifically qualified emergency services only. No political exemptions, no non-profit / NGO exemptions.

    - How often claims are settled and risks re-assessed is open for discussion. Daily might be too often, weekly or monthly seems most likely. Longer than that gives too much free-run for malevolent actors to operate.

    ________________________________

    Notes:

    1. "BunnTel", because bunnies hop.

    2. For an overview of surety bonds, see <https://www.suretybondsdirect.com/educate/what-is-surety-bon...>.

> Many scammers have plausible deniability

The scammers who call me are perfectly obvious.

First, they tell me the company they are from (almost certainly a fake one -- could be easy to verify). Then they try to convince me that two years ago I have created an account on their website, they gave me some free money that was managed by an AI, and now I have a ton of money, and they need to send it to me (a completely bullshit story). Then they tell me that in order to get that money, I need to install a software, that I know happens to be a remote control software (no legitimate financial institution would ever do that).

There is no way to make this plausibly deniable. Especially the part about the need to install the remote control software... which is the entire point of the operation.