Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

CLID is trivially spoofed; indeed there are CRM vendors that will do that for your sales force.

Telco should fix CLID.



The problem is that "Telco" hasn't existed (at least in the USA) since divestiture of Bell System. Tariffed services include access to the PSTN as in terms of trunk lines (esp. PRIs), which allow end users to control call appearance including specification of the originating Directory Number (DN) that is passed in the SS7 call setup message (ISUP). It is even easier with SIP trunks.

This is a problem similar to DNS spoofing. Often a large organisation will have an 8xx number (toll-free) which they wish to appear for CLID on all outgoing calls from every line, every office.

How do you validate whether the toll-free (or whatever) CLID number passed is correspondent with the actual number of the OUTWATS trunk (or SIP trunk) used by a given caller? Trunk lines need not necessarily have a DN assigned to them if they are purely for outgoing service.

You would need to setup facilities to "sign" each originating call with a cryptographic certificate assigned to the owner of the number passed and then equipment on each terminating set to validate this.

This is an extremely non-trivial proposition.


Telco (FSVO "telco") may well not be able to fix CLID, broken as it may be - they can replace it for all the good it does. But it's always aggravated me that they can provide ANI to 8xx customers. Way different service I'll grant.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: