Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I get that this is for businesses (mostly) so every outward call seems to originate from a single number, but why in the hell can't there be a verification that the number originated from that specific business? Isn't everything digital now? Just do NATing with phone numbers.


That’s basically what STIR/SHAKEN is designed to do, what you’re talking about is going to be handled by the certificate authorities. Carriers are ramping up the way they flag or restrict unverified calls as the system is more widely implemented. Echoes of how HTTPS slowly became universal.


Yeah that's what I don't understand. It should be 100% impossible to spoof some random number no matter what, and spoofing a business number should be heavily authenticated to make sure that only the business the owns that phone number can do it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: