Fred's Blog

Kamailio, VoIP, Rants, and More

STIR, SHAKEN, KYC... It's all just BS

Posted . ~5min read.

Disclaimer: The views expressed in this post are solely my personal views and opinions. These do not necessarily represent the views and opinions of any company or project that I am (or have been) associated with.

Numerous reports document the costs of scam centers, many of them based in India, and their cost to US victims. Conservative estimates say Americans lose 150 million yearly to such call centers (posing as tech support, government impersonations, etc.).

To combat scams (and robocalling), the FCC implemented STIR (Secure Telephone Identity Revisited), SHAKEN (Signature-based handling using tokens), and KYC (Know Your Customer). These rules were supposed to help combat spam, “illegal” robocalls (because political ones are still legal, of course), and scammers.

The whole idea, based on some crime prevention/crime deterrent principles, hoped that limiting the opportunity of such crime and strict enforcement would significantly reduce the problem.

Spoiler alert… it has not.

Since I love putting my criminology degree to work (which is a rare occurrence)…

The crime prevention triangle tells us that for every crime to occur, three elements must exist:

  1. Desire
  2. Opportunity
  3. Ability

In the prevention world, the only factor you (as a potential victim) can control is opportunity. This isn’t victim blaming per se, but it also kind of is saying the victim can help limit the opportunity to be a victim.

Things like locking your doors, not keeping valuables in sight, being mindful of pickpockets, are all common ways we encouraged our loved ones to limit the opportunity of crime.

Now, there also exist Three Core Pillars of criminal deterrence (aka the ability to deter crime). These are:

  1. Certainty (likelihood of getting in trouble)
  2. Swiftness (speed of punishment/apprehension to the time of crime)
  3. Severity (harshness of punishment)

The American system of justice is not, by any means, a deterrent.

The certainty of getting in trouble is extremely low. Historically, more than 75% of property crimes (theft, etc.) never result in an arrest.

The swiftness of our system is notoriously slow. This, of course, is by design. Our system, famously, is to protect the accused, not deter. And, the severity when the small percentage of those arrested actually get punished is why we have phrases like “slap on the wrist” commonly used.

Deterrence can be effective at home (parent/child), at school, at work, but definitely is not a factor to prevent crime in the United States.

I digress…

In theory, STIR/SHAKEN and KYC (Know Your Customer) were supposed to help prevent fraudulent telephone activity through prevention (limiting opportunity as well as ability) and deterring activity with consequences against providers.

By any measurable account… total failure.

Your carrier, and you for that matter, are supposed to be able to limit opportunity by only accepting calls that have been verified and attested with STIR/SHAKEN. You can, for example, choose to only accept calls with the highest, A level, attestation.

An A level attestation would mean (in theory) that the carrier sending the call owns the number and knows who made the call.

Back in 2022, to help with an NPR report on “Those fake active shooter calls to schools? A similar thing happened before,” I looked at criminal calls made from VoIP carriers that had given numbers to people (often times for free), without verifying who they were, where they were, or any basic information about the user.

The carriers, in many cases TextNow, then sent these calls through the PSTN signed as level “A” (aka trusted/known) even though they had no idea of who the customer was or where the customer was located.

To illustrate this for a reporter, I used a VPN with a foreign IP to make a Google account with the name of “George Criminal.” With this fresh account and newly created Gmail address, I created a new TextNow account, received a number, and made a call with A level attestation. The process took less than 10 minutes. It cost me $0. I didn’t even need a credit card.

No verification. No checking. All fake info that is easily shown to be false, and yet I was given full access to make and receive calls with my foreign IP. Any call I made was signed with “A” level attestation.

Repercussions for TextNow from all these swatting calls, bomb threats, and so forth? Nothing.

In 2025, I wrote about Telnyx receiving a 4.5 million fine (proposal) for allowing government imposter robocalls on its network. I detail in that post all of the many, many reasons why Telnyx clearly did not do anything a reasonable person could consider as verifying the customer.

Telnyx is still fighting the fine (remember what I said about swiftness and certainty?). Many providers are fighting the KYC rules. The CommLaw Group talked about such comments they recently filed with the FCC.

I continue to say that until there are true consequences for carriers for allowing these scammers to easily get numbers and make calls, the problem will continue.

Americans will continue to lose money yearly to scammers… who will be paying the carriers pennies for each call.

All of this ends up being pure BS.

Additional Reading

Tagged in...

Next up...

CT21 Plus Backpack APIBAN Now Has IPset (again)

Latest Posts