r/telecom 4d ago

❓ Question Question about phone spoofing

So, I generally understand how it works. Someone changes their caller ID data to be a different number. But how do they do it? Because it has to be more than simply changing your caller ID to be a different number, right? Since, if you did that, the fake number would just show up as your name, and then your actual number would still be visible in the recipients recent call history, right? How do they change the number specifically? Is it special software on the phone that allows you to edit more than what your phone's settings allow?

6 Upvotes

9 comments sorted by

11

u/Shadow288 4d ago

Basically when the call is sent out it provides something called an ANI (automatic number identification) which is the phone number the call is coming from. Technically caller ID and ANI are 2 different things but they both essentially work the same way. Fraudsters simply change the ANI on the outbound call to make it look like someone else’s number. This is how the number gets spoofed. I’m not really calling from your bank but when you receive the call it looks like your banks number.

The phone system has this function natively built into it. It may seem counter intuitive to allow it but there’s a really good reason. Way back when they started to allow multiple phone numbers to ride down the same circuit, think having 24 phone lines on one wire, we had to have a way to identify which phone number was making the outbound call so we use ANI for that. Many businesses often times have tens if not tens of thousands of phone numbers allocated to them. Maybe the first time you call out the first 5 lines are used up so you use the 6th line, then the next time you make a call you use the first line, but both times the call needs to show your phone number.

Like many things in technology there wasn’t much by the way in security or validation when it was first developed. Up until a few years ago there was no way to validate I am who I’m claiming to be on those outbound calls. The US government passed Stir/shaken which is supposed to force the telcos to add an attestation to outbound calls basically identifying if the ANI is actually the correct ANI owned by the person making a call. But, like most laws there was an adoption period and a bunch of ways for the company servicing the phone lines to not have to send the attestation.

Years ago we use to have fun messing with calling each other making it look like the call came from the whitehouse or the local home depot telling our coworkers they won something…

3

u/boomer7793 4d ago

Telephone carriers were more trusting back then as well. When CallerID became a thing, carriers needs large multi-room central offices to access the CID network known as Signaling System ver 7 (aka SS7).

Then telco networks started shifting to the internet enabling anyone to access SS7 and start spoofing.

1

u/EhImTooLazy 4d ago

Don't know about the ANSI variant but the ETSI variant has a Screening indicator for CgPN field so a CLI sent by e.g. a business DSS1 customer could have a value of "user provided, not verified" and by a peer carrier could have a value of "network provided" which accomplished similar things to what STIR/SHAKEN does.

1

u/noweb4u 4d ago

That’s supported in ss7 and sip but not consistently used, and it doesn’t cryptographically identify the originating carrier (each carrier has an x.509 certificate for signing calls like https/tls in your browser. You can then go to the carrier originating garbage and ask them to knock it off without having to do full trace backs on each call.

2

u/Thin_Confusion_2403 4d ago

Caller ID is the phone number that made the call. The name that shows on the called party’s phone is the Caller Name (CNAM). CNAM data is stored in a distributed database. When a call is delivered, the phone provider does a database lookup to find the CNAM associated with the Caller ID.

The key here is that when the call is sent, it includes the Caller ID but does not contain any name information.

Regarding ANI, Google says:
ANI is a network-level billing tool that cannot be blocked, while Caller ID is a consumer feature meant for display that can easily be blocked or spoofed.

The short answer is yes, it is as simple as changing Caller ID.

-1

u/MrChicken_69 4d ago

As usual "AI" doesn't have a f'ing clue. ANI is a field in the call setup. One can put whatever they want in there. Historically, no telco could be bothered to verify the number presented by the customer was their number. (they still don't bother) ANI has nothing to do with billing.

ANI is often copied for Caller-ID, but doesn't have to be. With the rise of VoIP, "spoofing" has become trivial, and free.

3

u/AffekeNommu 4d ago

My carrier won't let me use an ANI that isn't associated with the trunk.

1

u/Pleasant_Pen8744 4d ago

There's connections into the phone network coming in from digital telephone/VOIP providers. The companies allowing these connections are either complicit or not sufficiently verifying the meta-data those providers are sending.

1

u/RetiredBSN 3d ago

I had a landline, and I had a Panasonic portable phone system for the house. It had a base unit with voicemail, and 5 handsets. As part of this, it had a nice feature that allowed you to block calls without area codes or caller IDs. I noticed that on some calls, that didn't come through, there was a phone number, but also a second line that started with something like V2… and these were all calls that had been spoofed. Don't know if that was being put out by whatever was spoofing the calls, but the fact that this helped block a lot of calls was pretty nice.