The Not Ready For Prime Time Carriers Under FCC Threat
- Resident47Maybe it's a new Autumn tradition, like the start of football season, gathering leaf collection tools, and setting up retail Halloween sections way too early. Last October the Federal Communications Commission lined up seven phone carriers for pending bans of their outbound traffic. This month twenty more carriers face the same threat of being shut out from American telephones.
These carriers have all demonstrated a miserable lack of TRACED Act compliance, unwilling to help quarantine illegal voice calls and text messages through the the Robocall Mitigation Database, as the FCC now demands of all carriers. To be a player in the club, a carrier must certify its compliance. Simply sending a "yup, we got this" notice isn't good enough. Carriers must also submit their actual mitigation plan. They may choose to deploy the STIR/SHAKEN framework right off the shelf, or roll their own countermeasure system. The carriers under blockade threat were presumed to have done neither.
No one at the Commission said that they are actually spam harbors or have willingly passed tons of fraud sludge to the rest of the North American networks. But if they can't describe their plans for spam combat, it's better for our network security to assume they don't have any, and are therefore part of the problem rather than the solution. It's also a fair bet they won't respond to "traceback" investigations when authorities want to unmask the source of trashy calls.
One other common attribute is that they're all rinky-dink outfits with nearly unknown (and occasionally silly) names before their moments of infamy. They belong to a "small potatoes" class who were granted plenty of extended time to comply with TRACED after larger carriers had met their deadline. Possibly this was a tactical error, given it's been that same class of half-pints who have knowingly carried the most tainted water for criminals with autodialers. Like the spammers they may support, their tents can be pitched and folded to stay ahead of law enforcement, with an ease not enjoyed by Bandwidth, Level 3, Local Access, Neutral Tandem, Onvoy, et al, not excluding those big name carriers with the largest advertising budgets and the most roles for celebrities. (I'm looking at you, Seth Meyers, Zach Braff, Catherine Z. Jones, far too much.)
When last year's seven scofflaws were trotted out for just ridicule, they all reminded me of the school kids I knew who did all their homework on the morning bus ride. Here's the press release and inaugural batch of Show Cause orders:
FCC to Remove Companies from Robocall Database for Non-Compliance - FCC, 03 Oct 2022
Four of the group -- Akabis, Cloud4, Horizon, and Morse -- had declined to adopt STIR/SHAKEN. The remainder reported applying the framework to some portion of their networks. They all claimed that otherwise traffic was "subject to a robocall mitigation program" of their own. Here's what they turned in for reports:
* Cloud4 "included an attachment that requested confidential treatment of the certification".
* Sharon and Southwest Arkansas each claimed to be "seeking confidentiality for its mitigation plan, and that it will upload both a public and a redacted copy". Neither bothered to upload anything.
* Akabis and Morse "only attached a slide that appears to have been created by a third party, Inteliquent, describing the process to obtain a STIR/SHAKEN certificate".
* Global UC Inc. "only included a document that described background technical information about STIR/SHAKEN" which "was unrelated to the Company and did not include a description of the Company’s robocall mitigation plan".
* Horizon sent only a screenshot of the Company's FCC Registration Number from the Commission's website.
Horizon, I noted at the time, takes the short bus to school. The other class submissions boiled down to stalling for "confidential" time and I guess pretending to be stuck on the instructions. The Not Ready For Prime Time carriers had plainly not followed FCC Chair Jessica Rosenworcel's consistent voting record and citizen advocacy if they thought their juvenile responses would be forgiven.
Global is the only goldbrick of the first bunch freed from detention. It was yanked from the Mitigation Database eleven months ago. Its execs must have been desperate, somehow winning a second chance from the FCC a couple weeks ago. Under close oversight and reporting requirements, Global needs a real plan and its act together by January to keep the place running. Why its team is not ready now after a year off the campus, I am left to guess.
FCC Reinstates Global UC to Robocall Database - FCC order, 16 Oct 2023
This October's gang of twenty has enjoyed the same year to learn from what happened to those noncompliant peers. They all filed their Mitigation Database certs between late Summer and early Autumn 2021. Surely their mitigation plan submissions couldn't be worse than "confidential" bluffing, padding them with brochures, and generally playing dumb. During a fortuitously timed Congressional subcommittee hearing last week, probing the current state of illegal voice and text traffic, TCPA author Senator Ed Markey was eager to show one of those plans to the room.
It came from a very quick download. In fact, the office printer must have held hundreds of ready copies. It was a blank sheet. Markey erred in stating that "one of" the carriers sent a blank page. Six of the twenty did so. Well, being totally fair here, the blank from Saudi Arabia was interrupted by "an uneven horizontal line". I'm sure they'll hand in cleaner paper next time. Markey and Committee chair Ben Luján noted a few more minimalist entries, somehow missing the weirdest examples.
Eight carriers in total slightly abhorred a vacuum. Three of those merely sent an executive's signature, one from France being "illegible", another from Israel appearing politely on a "company letterhead". Montreal's Textodog, said the FCC, attached "a .PNG file that depicted a corporate icon". From Texas came a "Windows Printer Test Page", cheering "GeraldW7P" for a flawless PDF printer driver installation. Next the FCC wants to know when he's low on Magenta ink. DomainerSuite of Canada generated a conceptual art piece, a full sheet with only the word "NOTHING" in all caps. Jenny Holzer, watch your six.
Another Canadian sent "a .PNG file depicting an indiscernible object". Was it an amateur "Magic Eye" picture, I wondered, or just too rude to mention? My vote is a portion of the outside wall of a fridge, dotted with little stains. Want a guess yourself? Ars Technica did what I couldn't, and fetched this and other carrier's attachment images. The link is below, which I found by accident shortly before posting here.
A Delaware carrier forwarded a letter, "unrelated to robocall mitigation", from the local Harvard Business Services, a sort of concierge for virgin companies filing their initial paperwork. The Chinese take-out menu wouldn't fit on the flatbed scanner. Viettel Business Solutions in Vietnam spent its plan upload on unrelated bragging, a slide presentation titled Viettel Solutions: Making Smart Cities Vision a Reality, and making responsible business a fantasy.
From northwest India, Evernex SMC provided a screen cap of its own Taxpayer Profile "on a Pakistani government website". We follow the money if not the logic. From New York, My Taxi Ride Inc. dropped off a copied FCC public notice titled "FCC Facilitates Review of Restoring Internet Freedom Record" from November 2017. It's a half-pager pointing everyone to handy compilations of docketed anti-Net Neutrality comments for download, obviously several blocks off the mitigation topic. Okay, getting warmer ... it's government stuff from the correct continent.
A rare note of candor came from SIA Tet of Latvia, a letter stating "Unfortunately, we do not have such a documents." [sic] Better that then "the dog ate it". Showing the most if faintly earnest effort, Route 66 Broadband of Arizona sent "a signed declaration by the Company's CEO" and zero plan details. The Participation Trophy is in the mail.
Like last year's group, eighteen of this month's questionable carriers had declined to adopt STIR/SHAKEN and the rest claimed to apply it partially, and all otherwise certified that traffic was "subject to a robocall mitigation program". All twenty fell silent after filing, ignoring friendly prodding for correction from the FCC the next January and February. Perhaps the FCC needs to edit its certification boilerplate. Every phone call in the pipeline is "subject to" some kind of control, at every network handoff, and at the intended recipient's phone. It's not a given that control will be exercised. Overthinking, am I? Criminals and their lawyers would sooner spend a week splitting a hair than an hour at an honest job.
I said before these slackers have exhibited "miserable" noncompliance. I'm changing my adjective to "insulting". This second class isn't even trying to look confused. They've simply stuffed the virtual envelopes with whatever was lying on a desk at the moment. The only thing they didn't try was a candy wrapper from the wastebasket.
As millions of dollars and tempers alike are lost each year to the audible sewage passed along by careless carriers, these class clowns think it's a game, and that they get to rewrite the house rules. But can we blame them so quickly while proper punishment gauges somewhere between 'feeble' and 'maybe next time'? Several times at the Senate hearing the FCC Chair's oft-vented frustration was echoed as the Justice Department was chided for its poor follow-through from arduous investigations. The punishment gap is acutely vexing once regulators practically gift-wrap the perps for the enforcers.
Witness Josh Bercu put a bow on the box. He's Policy Veep at USTelecom, which manages the Industry Traceback Group responsible for keeping carriers talking to each other to locate spam sources. He had ready praise for past Indian call center raids which thinned the impostor scam volume, and also recent FCC cease orders which have nearly exterminated entire categories of junk calls, such as the fake auto warranty pushers. His wish would be to beat the criminal, not the network.Quote:... even if we stopped every single robocall, the criminals who do this, their day job is still defrauding Americans, and they'll just find a new version, so the only way to get them to stop defrauding Americans is criminal enforcement.
Not that I'm ready to exonerate the FCC itself, either. The class of twenty mouth-breathers hauled into the Principal's office have been left to their Business As Usual for two long years after turning in empty gestures. Homework was a waste of their time then, and always will be. It should not have taken four-plus months to grade their utterly inane and bratty papers as deficient. They should have been handed their nastygrams and expelled a long time ago, clearing seats for carriers who actually enjoy happy subscribers. Just maybe, now that the FCC votes won't default to splitting by party, we can see some enforcement momentum without the aid of a time-lapse camera.
Yes, I know the bad carriers tend to blend illegal and innocuous traffic, and that we've no proof that these twenty twits polluted the networks, and that sealing off their spigots is seriously drastic. We want the least harm done to the most innocent. But maybe a little more "Broken Windows" enforcement won't hurt us here in a field where the bulging aggregate of many small sources is in fact the problem.
Fellow hearing witness Margot Saunders, Senior Attorney at the National Consumer Law Center and frequent amicus curiae filer, offered perhaps the most creative spam combat plan. In a paraphrased nutshell, if Congress won't better fund a woefully understaffed FCC, then give their people greater power to act swiftly. She would like to see them slap the analog of a restraining order on incurable frauds, with no need to wait for DoJ attorneys or a judge. Because of senators' interruptions, I'm cutting together quotes from different times here ...Quote:... the incentives need to be changed, whatever way it's done. What we've proposed ... is that the FCC adopt a methodology such as is permitted under the Federal Rules of Civil Procedure .... so that once a particular voice service provider is found to be a repeat offender ... they should be suspended immediately from the Robocall Mitigation Database. That'll cost them money.
There you go, a clear view to raising the cost of doing dirty business, while better matching the pace of fraud adaptation. The sketchy bunch now on notice needed to respond to the FCC's Show Cause orders by today. Any who maintain the silent treatment get shut up for good next year. Please forgive if I decline to hold my own breath.
. . . . . . . . . .
FCC Seeks to Remove Companies from Robocall Mitigation Database - FCC press release and orders, 16 Oct 2023
The most insane “robocall mitigation plans” that telcos filed with the FCC - Ars Technica, 17 Oct 2023
Hearing on Robocalls and Illegal Texts - C-SPAN video, 24 Oct 2023 - MaryThanks for posting. Gives one hope.
- GregAtTheBeachSend this to the likes of the NY Times, Washington Post, etc.
It's that good.
I'm convinced that you could get a regular gig in a large market newspaper editorial department. - BenMichigan attorney Steve Lehto posted a recent YouTube video [10-24-23] on this exact subject: "Robocallers Continue Mocking the FCC." Let's hope his cryptic comment that the robocallers believe the FCC will not actually do something about it turns out to be a false hope for the robocallers.
- Carl WrightExcellent article!
- WrightShorter article on the same theme: https://arstechnica.com/tech-policy/2023/10/t ... it-for-2-years/
- Resident47They Told You Once, They Told You Twice
Rather quietly last Thursday, meaning without a press release, the FCC has made good on its threats against a two-thirds majority of the carriers facing blockade from the US telephone networks. Thirteen carriers, some bearing such confidence-building names as "My Taxi Ride" and "Textodog", have been thrown off the Robocall Mitigation Database (RMD). For downstream carriers, rejecting their traffic is no longer a suggestion but a demand.
Twelve of the newly blackballed carriers -- having turned in blank papers, company logos, and a promo slideshow for junk call mitigation plans -- had responded with predictable silence to the FCC's Show Cause orders.
The outlier from Edmonton, "2054235 Alberta Ltd.", made cosmetic amendments only. Their first filing claimed that all traffic was subject to mitigation without explaining how, and attached a business address. Their second try last October claimed that some traffic is mitigated and STIR/SHAKEN is partly involved. Their new attachment indicated a rebranding to their standing d/b/a Teleclub and a change of address, and quit right there.
The FCC naturally wondered, "Okay, so where's your plan, two years later?", and also noted the absence of any pleading or explaining in Teleclub's defense, which is a pretty normal thing to do with a Show Cause order. ("Give me one good reason why I shouldn't kick you from here to next Monday!" .... "uuuuhh, cuz you'll bruise your toes?")
It's unclear if the remaining seven carriers are saving face or due to get their own RMD rugs pulled. FCC press releases have been known to lag behind their actions by a half day; maybe the ones I'd expect are on hold until all the blockades are confirmed. While I'm waiting, I'll handle something that's bothered me since those twenty carriers got the FCC's Trick or Treat notices.
Not long afterward I found a column on the topic from the head cheese on CommsRisk. I'd read some of his work before, finding he holds no love for STIR/SHAKEN and little comfort with unevenly applied US telecomm policy. I disagree with aspects of his posture and arguments, but I respect his background and willingness to lift the table skirts on this story.
He pointed out that Mobily, now one of the thirteen pariahs, is Saudi Arabia's Number Two carrier with a "40 percent market share". My own poking around gives me a possible eight million subscribers. It's quarter-owned by the UAE's Etisalat, an even bigger telecomm which turns 20 years this Summer. So my prior "rinky-dink" writeoff was unfair. It's too well exposed to serve as a properly disposable spam harbor.
The column allows that Mobily's plan submission of a wobbly stray line on a blank sheet looks bad. Then it publishes the entire mitigation plan from Etisalat, all three sentences of it:
"As of now, the suspected numbers are being blocked based on the various alerts configured [line break]
Currently looking at the feasibility to test and activate STIR/SHAKEN policy for the calls, wherever possible. It is still under testing."
Really? That's no plan, that's a text message, out of context besides. The CommsRisk editor is entirely right to ask why this dash-off seemingly satisfies the homework assignment, and indeed if the FCC's standard is a hurdle or a speed bump. If any of us took random samples of RMD plans submitted in the past few years, would we find them mostly sincere and thoughtful, or that fatally defective filing is the norm and not the exception?
If the latter is true, rounding up scofflaws to shame and punish makes easy pickin's and positive news copy, helping to prove the efficacy of STIR/SHAKEN mostly by circular logic. We might argue (and some already have) that risibly lazy uploads are made, perhaps minutes after installing PDF software, on a dare that a chronically understaffed Federal agency will never discover how many are composed of blind grabs from a paper recycle bin.
The column author joins many others in related article comment forums in wishing to cut slack for foreign firms without an overt interest in US phone traffic, and/or those whose own language barrier prevents a more earnest plan submission. I'm aware of the issues around compliance traps and why certain political wings are forever lip-frothing over "burdensome regulation". Occasionally those "red tape" protests are justified. But please explain how the Etisalats and Mobilys are too big for suspicion yet too small to find someone fluent enough in English to define the telco's possible liability to US regulators.
It's been suggested many times that flimsier compliance efforts are the natural result of people not knowing what in hell to do or what is expected, and slapping random sheets into the scanner simply as placeholders. The column complains that the FCC has done little or nothing to assist compliance, both a plausible and shameful condition. I can buy the theory of faltering on a first attempt. I'm having trouble accepting the lack of follow-through across two years. I cannot accept that even a junior grade paper slinger, given this task and zero English comprehension, truly believes that pictures of a fridge wall or scans of a brochure or cryptic markings are not insulting to the process.
There's also a great deal of ranting about the meaning of "using" numbers within the North American Numbering Plan which is either hopeless claptrap or above my pay grade. I take as read from the FCC that it wants to keep trashy calls from bleeding on Americans at the seams and holes once the most prominent domestic carriers have erected their barriers. But sure, the venerably aggressive Chair Rosenworcel should explain why her team hasn't done more to make sense of RMD compliance.
The column lands perhaps its best spear when suggesting improved aim at better targets:
"The need for foreign telcos to submit to the RMD mostly stems from the American corporate obsession with cutting costs by employing people in foreign call centers whilst pretending they are making calls that originated within the USA. The FCC knows this, but instead of concentrating enforcement attention on the big call center providers they cast their net as wide as possible and hoped every telco in the world would voluntarily swim into it. This largely defeats the point of the exercise; the very many telcos who willingly submit to FCC overreach are not the few crooked businesses that the FCC most needs to scrutinize."
I remember back to circa 2006 before "Rachel from Account Services" bombed the nation via Clearwater Florida Caller ID, introducing us all to a new era in automated torture by phone. A very few smarter observers began warning that a never-ending storm was coming, mainly due to banks and major corpos outsourcing remote customer service to anyplace the labor was cheap and the entry barriers were low. Illicit monetizing of our privileged data is inevitable, almost invited, whenever upper management is not in the same room with its headset force. Time and again we've had to draw dotted lines between payday loan thugs, impostor frauds, and the most wretchedly fraudulent sales callers and the armies of phone drones raised by South Asian BPOs, where "justice is cash flow".
Possibly it's thought that control of the virtual pipeline valves is easier to manage than raiding autodialer nests ... which always looks great in the news, but it's no secret how quickly the cockroaches regroup.
I keep thinking of the bottles and cans and cartons and papers I've been dutifully segregating for recycling programs since before it was cool, and all the times I'd asked for help with categorizing materials when I lived near a "multi-stream" landfill. Repeatedly I've groaned at new video of the same trash and worse clogging up some distant shoreline which never asked for or produced the waste. I'd sleep better with a smaller carbon footprint if only I wasn't frustrated by the way the majority sabotages the system. Maybe instead of trimming the trash streams we need to prevent their very generation. There I'm asking for systemic control I simply don't have, unless I renounce all supermarkets and turn my backyard into a garden and mini-ranch like my immigrant grandparents ran.
No one has seriously suggested that STIR/SHAKEN is the great ultimate weapon, and the latest FCC Orders underline that they don't pretend to "exercise ... jurisdiction over foreign voice service providers". Just maybe, in consolation, with a fully populated Commission able to break party vote splits, we'll get more of the overdue tools for the very long job ahead.
. . . . . . . . . .
FCC Removes 12 Entities from Robocall Mitigation Database - FCC, 22 Feb 2024
FCC Removes TELECLUB from Robocall Mitigation Database - FCC, 22 Feb 2024
Why Is the USA Trying to Disconnect Saudi Arabia’s Second Mobile Operator? - CommsRisk, 23 Oct 2023 - Resident47MaxTech House, Good To the Last Dropped Call
Yesterday the FCC banished another questionable phone carrier from the Robocall Mitigation Database, showing slightly better turnaround time between the threat and execution of removal experienced by carriers in the two big roundups discussed in this thread. The matter notably features the first carrier subjected to the FCC's expedited removal procedures, effective since late last Summer. As noted by some telecomm attorneys, the rule upgrade allowed faster purging of "facially deficient" RMD submissions, which translate to "willful" violation of filing standards.
Two years ago this month, BPO Innovate turned in what by now we could call a classic example of willful deficiency. The FCC says it "certified that some of its traffic was subject to a robocall mitigation program". In support of this claim, the uploaded plan for robocall mitigation was "actually a letter from the Internal Revenue Service notifying the Company it had been assigned an Employer Identification Number". More than "deficient", it's a bird-flip, totally in bratty pattern with the other ninnies who slapped what was handy onto a flatbed scanner and went to lunch.
In January this year, the carrier received the routine Show Cause order, warning of pending RMD removal. The FCC gave reminder that "BPO Innovate received numerous traceback requests from the Industry Traceback Group (ITG)" and ignored them. The carrier was prodded once before at the end of last September about its garbage filing, and did nothing. It was given a last chance to cure all problems, and did some more nothing. Here we are this week, no change in Silent Running.
Now comes a necessary reflection. Is this tiresome exercise in regulatory cat herding doing us any good? Are we raising the cost of bad business for the actual guilty parties? ITG data yet remain a secret, which the watchdogs at EPIC and NCLC would like to see turned loose to all law enforcement and the public. We're not even sure the FCC is sure what a fully compliant RMD filing looks like, given the defective specimens sent by carriers which have yet to hear a peep of official protest.
The newly ostracized carrier won't process tracebacks or describe its junk call handling, which surely makes bad optics. We're left to speculate if it has also generated or passed illegal voice call content.
BPO Innovate is a British Columbian carrier, which it says keeps footprints in New Jersey and India. However, it's also MaxTech Data House, a/k/a Max BPO in Delhi, India. I'm skeptical about which is the real boss of the outfit. It may be a more symbiotic arrangement.
The "BPO" is the dull part of the name I've used here and there. Those are initials for "Business Process Outsourcing". It's one of those fuzzy sanitizing phrases for things we shouldn't tolerate, like "Enhanced Interrogation Techniques", and "future deniability". BPO is code for "overseas room full of cheap headset jockeys".
The BPOI website is being uncooperative just now, but I think study of MaxTech's site is more relevant anyway. They offer help with "mortgage loan processing, bookkeeping and accounting, debt collection, data entry, data mining, customer support, medical coding, freight bill audit, to name a few" categories where anonymous strangers are privy to sensitive secrets of another nation's commerce. Nestled amid the marketing claptrap and happy office stock photos are numerous examples of the detail-sweating we've come to expect from mercenary wage slaves.
A large subheader proclaims "World Class Business Outsourcing Services to Clients Globally from Different Industry". Yep, we're in trouble already. More home page pull quotes:
* "We are one of the trusted business process outsourcing companies in the world, which boasts off [sic] high-quality service."
* "We strive to achieve the highest level of accuracy, & supreme level of delivery with our experience acquired over the years."
* "... saving you an appreciable cost, time, efforts [sic] & helping you concentrate on your business goals"
"Maxtech has a team of due diligent experts [sic] who are all well aware of their specific tasks", I'm told, like that should soothe me after reading their brochure PDF. This adrift non-sentence leads its promo copy for the core activity of call centers:
"Contemporary era of increased competition & empowered customers, businesses need to work harder than ever to deliver the best user/customer experiences."
They can write your product catalog blurbs, edit your photos, and code those doctor visits in "security with HIPPA compliance" without realizing it's the wrong acronym again. My, is there no limit to what labor you can rent on a shoestring? I suppose this whole brochure is an example of their "Digital Publishing" service, replete with awkwardly hanging syllables (preserved below) at the line breaks and more of the same obsession with ampersands. But you be the judge .....
"Electronic publishing is an editorial aspect, [sic] that consists of editing books, journals, newspaper [sic] or magazines that are mostly destined to be read on [sic] tablet, e-reader, desktop & smartphone. eBooks offers [sic] instant access, interactive features and search options for a great user experience. The ePublishing Industry is flourishing [sic] and es-sential parts [sic] of today's innovative business world. Max BPO is embedded with the ex-perience of more than 2 decades [sic] to offer the cost-effective solution. We take advan-tage of our vast expertise to convert books, newspaper, [sic] magazines & journals into di-gital contents. Our customized solution helps to get the competitive advantage in the digital world."
With prose like that, I can hardly wait for the next round of AI software to put these English-flogging scribes out of work.
It's now a month since the deadline for all voice carriers to comply with the new RMD rules, no more extensions or exemptions. Everyone needs a submitted mitigation plan, now even those fully adopting STIR/SHAKEN. Everyone, not just the oft-wayward gateways, must agree to process tracebacks within twenty-four hours. Obligations are the same for all players. Next we'll see if their habits remain as consistent.
. . . . . . . . . .
FCC Seeks to Remove BPO Innovate from Robocall Mitigation Database - FCC, 09 Jan 2024
FCC to Remove Voice Service Provider from Robocall Mitigation Database - FCC, 27 Mar 2024
Reply to topic