https://www.reddit.com/r/funny/comments/6ofdt6/how_i_made_29...
If there's a way to get around the system, these guys will figure it out.
You can, technically, write anything in it and there’s no way to guarantee it’s authentic.
For example here are some headers from some spam I received:
From: "Jeremy Adamson" <jeremyadamson@illusion24.com>
Reply-To: "Jeremy Adamson" <jeremyadamsonr@yahoo.com>
From: is what I see in my client and Reply-To: is where a reply would go to.This one is much better, note how I'm BCCd and To: is complete bollocks:
Reply-To: dr.ahmed.faruk@outlook.com
From: Dr Faruk Ahmed <dr.faruk.ahmed1@gmail.com>
Subject: MANAGER AUDIT AND ACCOUNT DEPT
To: undisclosed-recipients:;
BCC: <gerdesj@blueloop.net>
Return-Path: dr.faruk.ahmed1@gmail.com
Given that Reply-To and Return-Path are in different domains, where would a reply go to?Basically a large registry. When I call someone I tell t-mobile who I'm calling, and they register it. Then on the receiving end Verizon checks with T-mobile or a central registry, and says yep James's number is calling this number. Then it marks it as a verified call.
There are lots of good things that telephony could be required to do but they are not and they wont.
This leads down a privacy/metadata rabbit hole, but there are probably ways to make this a lot better. In any case, the phone OS can do some out-of-band signaling and just avoid dealing with the carriers altogether.
Although if you're doing all that then why not just make a call using voip...
Just today, we (Nomorobo) see 25 different numbers pushing Windows tech support scams. It's like that every. single. day.
This is an emergency call from Windows Microsoft. Your Windows license key have been expired all services are suspended on your computer. To renew call our toll free 1-877-231-6134.
https://www.nomorobo.com/lookup/844-805-7111
https://www.nomorobo.com/lookup/855-328-4888
https://www.nomorobo.com/lookup/844-517-8655
https://www.nomorobo.com/lookup/844-904-1444
https://www.nomorobo.com/lookup/972-441-0548
...
https://www.nomorobo.com/lookup/855-895-6786
(edit: formatting)
From what I can tell, every incoming call rings simultaneously on the user's phone and Nomorobo's systems. If Nomorobo detects a blacklisted number, you pickup the call, play a 'you've been blocked' message, and hangup. Is that basically correct?
So Nomorobo ends up with a log of all my incoming calls. What happens with that data? Nomorobo is free for landlines (which I think means VOIP lines); is data collection the tradeoff?
Also, can I submit a whitelist, to prevent important numbers from being blocked? And is that list confidential?
Finally, do you work with old-fashioned POTS landlines? I'm interested in Nomorobo for an elderly couple who still have POTS.
1. Yes, pretty much. Here's a more in-depth answer to what happens when the call is answered - http://www.6083716666.com/
2. Yes, we do get a log of the incoming calls. We use that to analyze the high frequency calling patterns across millions of phone lines and build the blacklist. The more people that contribute, the better the algorithm gets.
3. We globally manage the whitelist and good robocalls (school closings, pharmacies, doctors offices, etc)
4. We don't work with POTS lines yet. The older technologies are tougher to protect than the modern ones.
Those features of CallKit are what we (Nomorobo) use to stop the robocalls.