Hacker News new | past | comments | ask | show | jobs | submit login

Depending on your new provider, they might just see that they have a contract with you and sign the call on your behalf with B level attestation - indicating that they "know" the end user, but not that they have the right to use the number.

As long as they managed to attach the identity header to the sip invite correctly, and are not considered to be a shady actor - downstream providers such as carriers probably have no reason to label it as spam. Spam labeling is typically done via analytics, outsourced to third parties like First Orion.

Attest levels are not in themselves proper tools for spam detection. The real meat of stir shaken is the origid in the identity JWT claim which is an opaque identifier that can be traced back to a particular user/customer/network equipment.

STIR/SHAKEN being sold as the one and only solution for spam calls was a mistake as it is only one iteration in the right direction. You have a handful of RFCs and ATIS specs that the FCC told operators to implement in a phased approach, and ultimately some gaps were uncovered in practice that reduced its effectiveness.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: