7/31/2026 at 4:58:54 PM
The solution is accessible law, not better anti-fraud tooling. Introduce a spam / fraud button, using it requires your pin and costs $10, but obliges your telecom provider to record the call (preferably including a few minutes before you hit the button), email you a signed recording and if found to be spam deposit $100 onto your account. Your provider may then hand the fee +10% for himself to whatever network the call in question entered his own network from. The last cooperative network in the chain gets stuck with the fee, forcing them to either reclaim the money from the malicious customer, the next network in the chain (in court) or pony up the money themselves.Result: All routes to non-cooperating networks get dropped within days to weeks and scam-calling stops being a lucrative business basically instantly.
by DeepSeaTortoise
8/3/2026 at 9:35:01 PM
I think a much better solution is to get rid of phone numbers (and email addresses), and instead only allow incoming phone calls, texts, email, ect, from people and companies you know."Cold calling" can either come from governmental organizations (IE, call from the police), or someone or some organization in your network can grant access to call, text, email, ect on their behalf.
The result is that SPAM has a chain of traceability, so you can then block people and organizations in your network who make unwanted calls.
Furthermore, regulation is needed so that your cable company can't pull dumb nonsense like saying "telemarking is required to use our service": This is where the SPAM button that you propose really comes in handy, because it holds accountable the fools who think that selling their customers' contact information is a good idea.
by gwbas1c
7/31/2026 at 5:35:20 PM
That's pretty much the proposal I've made for some years.[1]California has introduced bonding to telemarketing firms specifically. I feel that should apply at the carrier level, where networks carry a guaranteed bond, pay regular premiums on it, and are dinged for unwanted calls, with the proceeds being split among the called party and any third-party network(s) traversed by the calls. Downstream networks could seek compensation from ANY upstream network carrying the traffic regardless of whether or not they originated it.
This would both create a penalty for providing, or transiting, unsolicited calls, AND create an incentive for carriers / network providers themselves to pursue unsolicited traffic from their peers.
<https://oag.ca.gov/consumers/general/telreg>
________________________________
Notes:
1. See for example <https://toot.cat/@dredmorbius/111099306069523624>
by dredmorbius
7/31/2026 at 11:25:51 PM
Do you really want the network to be so locked down you can't get access to it?by inigyou
8/1/2026 at 3:38:00 AM
How do you reach that conclusion based on what I've written?by dredmorbius
8/1/2026 at 8:58:33 AM
Because it happened to everything else where this idea was tried.by inigyou
8/1/2026 at 4:47:20 PM
In other words: nothing to do with what I'd written.And no specific instances or mechanisms detailed, to boot.
Thanks.
by dredmorbius
8/1/2026 at 8:07:14 PM
The financial system. And the phone system in India.by inigyou
7/31/2026 at 5:01:48 PM
I think we have to do something this extreme. We have to give the system a total makeover. Somehow we also have to keep it from being fully centralized and have the big brother problem on the other side. Unfortunately these two goals are difficult to get through at the same time, with the system that we have.by bckr
8/1/2026 at 3:09:56 PM
They are impossible.You can't make a system that can force bad actors off the system that can't also be used to force politically undesirable actors off the system.
by LorenPechtel
7/31/2026 at 6:48:48 PM
If major states like California and New York pass it, and spam basically dies in those states, it wouldn't surprise me if it spreads across the country.by giancarlostoro
7/31/2026 at 7:41:27 PM
Assuming the nature of the spam and how it makes money.by pixl97
7/31/2026 at 5:24:15 PM
Cue the crypto bros touting their decentralized spam-detection blockchainby ssalka
7/31/2026 at 7:00:39 PM
Infeasible. Fraud or spam is usually pretty hard to confirm from one recording without additional context. Many scammers have plausible deniability or are just checking whether the number is active. Moreover, this solution would involve secret non-consensual recording; what if it's not a scam?by orbital-decay
7/31/2026 at 8:43:58 PM
Plus, who is ‘confirming’ the spam? The same entity (or group: carriers) that is keeping the $10 and paying the $100 out? That just means the result will always be ‘not spam.’by ryandrake
7/31/2026 at 11:31:47 PM
This is why fees should be structured such that all carriers are on the hook, but upstream carriers inherit the obligation, possibly with an increased liability per hop, implying that downstream carriers can utilise enforcement as a profit rather than cost centre.Scenario:
- Spamford places an unsolicited call to subscriber Alice initiating from MalTelCo, transiting carrier hops BunnTel1 and BunnTel2, to Alice's telco carrier, EndTelCo.
- Carriers MalTelCo, BunnTel1, BunnTel2,[1] and EndTelCo have all placed surety bonds, held by BondCo, to practice telephony operations within the jurisdiction (regional/national). The carriers are the Principals, BondCo is the Surety, and receiving subscribers (or telcos, see below) are the Obligees.[2]
- Unbonded carriers may have their traffic refused by peers. Peering to an unbonded carrier places the bond obligation on the receiving carrier.
- Alice flags the call as spam. A per-call surety of $100 is paid to Alice, and charged to EndTelCo against its BondCo contract. As an additional option the call may be flagged as fraud through the phone system, in which case it is automatically referred to LEO by EndTelCo. Obligation of surety is independent of any fraud finding and is based SOLELY on the unsolicited nature of the call.
- EndTelCo has the option of 1) eating the charge or 2) filing a claim against its peer, BunnTel2, the 2nd hop in the chain, which EndTelCo does.
- BunnTel1 similarly files a claim on BunnTel2.
- BunnTel2 files a claim on MalTelCo.
- MalTelCo now eats the claim (it's paid out by BondCo). MalTelCo may seek further compensation from Spamford, but that's Out Of Scope of the bonding / surety schema, and would be covered by MalTelCo's own terms of use.
- BondCo assesses risks and adjusts its surety rates correspondingly based on observed behaviours (and financial risks) of EndTelCo, BunnTel1, BunnTel2, and MalTelCo. If risks are excessive and no surety can be issued, MalTelCo is unbonded, and hence, decertified. Peers may now refuse traffic without penalty.
Note that no one carrier needs to know anything more about a call's routing than its own network boundary. If EndTelCo has no idea that BunnTel2 and MalTelCo were involved, it doesn't matter, because BunnTel1 is on the hook for passing on the call. Spoofing or falsifying records doesn't save you.
There are some questions over how this might be implemented, though generally:
- If Spamford and Alice are both subscribers to EndTelCo, then EndTelCo eats the surety, which is paid to Alice. There's no upstream. Moral: Telcos, don't spam your own customers.
- One thought is that the surety is split among telcos and the subscriber. Rather than just facing a potential cost, transiting and reciving-end-point carriers could see revenue by tracking and prosecuting unsolicited calls. This could include calls received by monitoring numbers set up strictly to assess unsolicited call activity directed to the network. This would mean that calls transiting multiple carriers would be subject to compounded surety claims ... and ... I think I'm OK with that.
- There would all but certainly be classes of calls which would be exempted from claims. Those should be very limited, preferably to government and specifically qualified emergency services only. No political exemptions, no non-profit / NGO exemptions.
- How often claims are settled and risks re-assessed is open for discussion. Daily might be too often, weekly or monthly seems most likely. Longer than that gives too much free-run for malevolent actors to operate.
________________________________
Notes:
1. "BunnTel", because bunnies hop.
2. For an overview of surety bonds, see <https://www.suretybondsdirect.com/educate/what-is-surety-bon...>.
by dredmorbius
7/31/2026 at 10:58:37 PM
I'd make one significant change to the proposal in the comment.The delivery penalty applies to any unsolicited email, as determined by the recipient.
If also tagged as scam, those are further forwarded to law enforcement (state, national) for investigation.
Many US states are one-party regarding recording. Even in two-party states (CA, OR, WA, MT, IL, PA, MA, CT, NH, MD, DE, FL), disclosed recording and continuing a call will generally be construed as consent. If that's not the case, proposed state or national legislation could carve out exceptions as needed, and there'll likely need to be some legislation required anyway, so that's part of the process.
But shifting the fee element from fraud (one class of unsolicited call/text abuse) to undesired contact makes sorting when the fee applies far more evident, and eliminates a class of other objections (e.g., due process) from consideration.
by dredmorbius
7/31/2026 at 11:27:00 PM
I sign up for a newsletter from Google, then I report it as unsolicited. Boom, I just made Google pay me $10.by inigyou
8/1/2026 at 4:05:12 AM
That's a familiar complaint from the world of email, where it's usually applied to mailing lists.If I were to steelman the concern, I'd look at a few related scenarios, say, where a subscriber is running a poorly-secured VOIP system and spammers hijack that to make calls. I'll ... get to that.
First: the scenario here is phone systems, not email, so the traffic would be voice calls, possibly texts. That said, I'll consider your question as if it was calls and not newsletters.
I've given a more detailed breakdown of how I see a bonding system working here, you might want to read it before continuing with this comment: <https://news.ycombinator.com/item?id=49129679>.
Second: It's not subscribers who are on the hook for spam calls, but carriers. So Google isn't paying you, your carrier is paying you (via a Surety agent), with the option of recouping that penalty from an upstream carrier, if any. If you and Google are on the same carrier, and the call didn't transit any other networks, it's just you and your own telephony service provider (carrier).
A carrier might have its own TOU/TOS with its subscribers, and subscribers originating calls could and likely would attempt to recover abuse costs if they were incurred. That subscriber (say, Google) might also have its own TOU/TOS addressing the case of mis-reporting of authorised contacts. Those actions would be outside the bonding system itself. A party repeatedly abusing the system could be liable for other actions, including fraud or malicious damages.
Note that one of the interesting elements of bonding is that call origination becomes a risky activity for telcos. Presently, telcos are eager to enter such business, put few restrictions or obligations on their customers, and to prefer outbound traffic to inbound traffic. Under a bonding programme, this changes dramatically. Large-volume outbound traffic is a liability, where it does occur, it needs to be closely monitored and managed. Our poorly-secured VOIP system mentioned earlier would probably be subject to configuration/operation validation, pen testing, close monitoring for activity, and alerts/throttling if unexpected usage patterns emerge. All of this is now in the carrier's interest.
Third: The bonding scheme would be periodically settled among carriers. I've hand-waved how often this would occur, though somewhere between daily and monthly, with a shorter term more likely (malicious actors often shoot-and-scoot, we want to avoid that). So low-level skirmish actions such as you describe would tend to result in a net wash between carriers: claims on one would be balanced by claims on others.
Fourth: Just how Google came to communicate, what it's communicating, and the degree to which it's coercing, say, receipt of sales/marketing messages vs. strictly advisory messages tied to a service ... would probably have to be considered in a larger context, but would still be outside the bonding system itself.
Fifth: There's a model for how surety bonds and claims work in the State of California's syste. For a breakdown of that see: <https://www.jwsuretybonds.com/states/california/telemarketin...>.
A few other points:
- New relationships might be permitted through a contact request. This itself could be mediated by a known third party. Private individuals for personal contacts, commercial or governmental trusted parties in other cases. Effectively it's the social-introduction problem from before the age of mass communications brought forward. Such systems will have some friction (necessary to defeat spammers), but not so much friction that the system as a whole doesn't work.
- Bonding does not require strong KYC for small accounts. That is, the person wanting to buy a mobile phone and service anonymously could, but their device and service would be monitored for abuse. I expect a tiered system to emerge, with individuals, small, mid-sized, and large accounts, with increased controls and obligations proceeding with scale and/or capability.
- Generally, it's not individual accounts which are responsible for large volumes of outbound calls, absent an issue such as a proxy hijacking. Large outbound volumes will tend to be associated with known call- or data-centres, and can be managed as such.
- The goal is preservation of a general-availability, universally-accessible phone system. That works only if it is not systematically abused, which is presently the case. If trust in public-switched telephone networks, permitting direct-dial access to any other number, anywhere in the world, is lost, what we'll see is desertion to other options which serve specific individuals' and organisations' interest. We are already beginning to see this, though no one clear winner has emerged. Unfortunately, most of the alternatives are proprietary, though some federated networks might prove to be viable alternatives.
by dredmorbius
8/1/2026 at 8:58:13 AM
So I just sign up for $60, collect a bunch of calls and then report them all a spam, earning me a guaranteed $1000 from the phone company?by inigyou
8/1/2026 at 2:25:23 PM
Please see my second point above, particularly the 2nd 'graph.If you're acting fraudulently and at scale, there will likely be consequences.
If this happens occasionally, it's a feature of the system, and your reports effectively become a super-opt-out.
And if perhaps the problem does become sufficiently widespread, I'd be interested in seeing how you'd address it given one constraint: operating within the bonding/surety system I've suggested. And that the State of California and others have already enacted in some form.
by dredmorbius
8/1/2026 at 1:25:10 AM
> Moreover, this solution would involve secret non-consensual recordingIn Canada at least, only one party has to consent to the recording
If you record your own phone calls that's not remotely illegal. Nor is it in my opinion unethical
by bluefirebrand
8/1/2026 at 1:30:43 AM
Almost, as someone who used to work with telecom systems in Canada, while it is true that felony wiretapping requires 1 party to consent to not be illegal, it is not the only law. PIPEDA applies to only commercial endeavors, and requires two party consent.This is why a company must inform you of the recording, but you do not have to inform them.
by Maskawanian
8/1/2026 at 1:58:45 AM
I didn't know that, thanks for clarifyingStill, as an individual wanting to record scam callers, you're in the clear to record calls that you are a part of
by bluefirebrand
8/1/2026 at 3:25:25 PM
That's where I stand, also. You're a party to the conversation, it's not something that would implicitly be expected to be private (thus no bedroom recordings etc), it should be legal to record. I can see no justification for prohibiting it.by LorenPechtel
7/31/2026 at 10:27:35 PM
> Many scammers have plausible deniabilityThe scammers who call me are perfectly obvious.
First, they tell me the company they are from (almost certainly a fake one -- could be easy to verify). Then they try to convince me that two years ago I have created an account on their website, they gave me some free money that was managed by an AI, and now I have a ton of money, and they need to send it to me (a completely bullshit story). Then they tell me that in order to get that money, I need to install a software, that I know happens to be a remote control software (no legitimate financial institution would ever do that).
There is no way to make this plausibly deniable. Especially the part about the need to install the remote control software... which is the entire point of the operation.
by Viliam1234
8/2/2026 at 4:03:18 PM
Sounds like a great way to strongly incentivize a new form of fraud--fraud-reporting fraud! Imagine how much fraudsters could gain by reporting thousands or tens of thousands of "fraud" calls that they themselves both originate and report from existing SIM farm infrastructure. Any deployment weakness or hole in blocking malicious traffic in the global telecommunications network all of the sudden becomes akin to a weak smart contract that is ripe for exploitation on the order of millions of dollars of fines until it is patched, all due to this depositing requirement.by bennettnate5
8/3/2026 at 9:12:15 AM
You're assuming the telecom operator of the SIM farm doesn't know his customers. That'll change very quickly after the first few have to cover the fines themselves.After that that scam would result in the scammer paying the (e.g.) $10 upfront, the (up to; e.g.) 10% for every hop between networks and likely and transaction, processing and legal fees for the civil case (if he's not cooperating).
And he'll likely end up with criminal charges on top of that.
Also it's not like the scammer gets sued by some powerless private citizen authorities are likely to ignore. His opponent will be a telecom provider in his own jurisdiction.
by DeepSeaTortoise
7/31/2026 at 5:01:25 PM
A lot of scams unfortunately operate right on the line of legality like the car warranty moronsby verall
7/31/2026 at 5:57:11 PM
Sure, but that's okay because you don't need 100% of spam calls to be recognized as spam for the incentive to do its job. The system still sounds like it could still work even if a large percent of calls weren't flagged.by cj
7/31/2026 at 7:06:55 PM
This works both ways, if the detection rate is low then nobody would press a "lose $10" button.by orbital-decay
7/31/2026 at 8:58:25 PM
Unscrupulous operators will just run up huge liabilities and close up shop by the time they can be identified and dragged into court, meanwhile having started another similar operation under a different name. That's basically already what's happening, and the speed differential between the technology and the law will be forever in their favor.by flatline
8/1/2026 at 3:04:19 PM
Which is why bonding is applied, as with other high-risk ventures.The bonding agent (the Surety) sets the bond rate based on the perceived risk of the venture.
Unbonded ventures are not permitted to operate. In a telco context, unbonded carriers would not be peered to other carriers.
Overview of how surety bonds work: <https://www.suretybondsdirect.com/educate/what-is-surety-bon...>.
California's present regulation: <https://oag.ca.gov/consumers/general/telreg>
by dredmorbius
7/31/2026 at 9:01:45 PM
The idea is that telecoms would be on the hook for these folks' behavior; they'd be incentivized to scrutinize them more thoroughly.by pavel_lishin
7/31/2026 at 7:05:03 PM
How are they listening to a few minutes before the button? A "temporary" recording of the first 2 minutes of every call? I feel like there would be some privacy concerns.by edoceo
7/31/2026 at 7:18:04 PM
It'd suffice for them to sign the transmitted information (audio and required timing metadata for the packet stream) and make you do the temporary recording on your side, transmitting it back to the provider once you hit the button, to let them handle the backup/safekeeping aspects for you.by namibj
8/1/2026 at 3:36:02 PM
Recording into the recent past is quite common. You implement it by storing the data *to memory only* until the trigger event happens, then you write out what's currently in memory.It's a common feature in better dashcams--you get say the 30 seconds before the thump that triggered it. Likewise, many high speed cameras that record some short action. They're actually always running, but dumping the end of the data, they only "record" when the trigger happens.
by LorenPechtel
7/31/2026 at 6:57:51 PM
Simpler yet: require every call to come with a physical source address, huge (and enforced) jail times for faking it. Let the internet and the pissed callees crowdsource the restby dmitrygr
7/31/2026 at 8:18:39 PM
This would be an enormous invasion of privacy. Other countries have a lot less issues with spam calls without these measuresby hutattedonmyarm
7/31/2026 at 11:27:54 PM
Other countries have this rule, actually. At least most of Europe records your passport and address.by inigyou
7/31/2026 at 6:24:17 PM
I don’t understand how this works. Suppose someone calls you about some political poll and you hit the button, would it count or not? What about a cold email (there was another such thread about cold emails being praised, i said fundamentally is spam but was downvoted lol).by amazingamazing
7/31/2026 at 5:59:50 PM
I spent a little time unsuccessfully looking for a reference, but in some ancient Greek and early Roman governments, newly elected officials who were in charge of money were required to personally indemnify (become responsible for the professional liabilities of) their predecessor.If your predecessor committed fraud, you were 100% personally responsible for it. You would then gather the evidence and sue your predecessor for your losses.
by pessimizer
7/31/2026 at 7:21:22 PM
That sounds like a great way to attract scammers and dissuade honest people, so if it's ever been tried it must have failed spectacularly (I also searched for variations of this idea but didn't turn up anything).by Luc
7/31/2026 at 8:00:34 PM
It probably worked for Romans because the taxes you were allowed to collect was so much more than you had to send back to Rome that you could get rich 'honestly'. That and you had options to prove the fraud that meant the other was unlikely to try.by bluGill
7/31/2026 at 6:50:36 PM
How does your predecessor today have those funds? The problem is politicians get to "play" with wealth beyond their own reaches (typically).by giancarlostoro
8/1/2026 at 12:16:45 AM
Oddly specific with the dollar ounts, but I like the general idea.by RobRivera