6 ms·
Yes, I think that is it. Thank you for finding it! AT&T took some bad press around that time, and in July 2016, the FCC, facing political pressure, and now sen
by kjellsbells 2mo ago
Yes, I think that is it. Thank you for finding it!
AT&T took some bad press around that time, and in July 2016, the FCC, facing political pressure, and now sensing that the PR gods were now on their side, leaned on the major carriers to set up a 'task force' to get things moving. I remember sitting in the little room at the FCC while various telco industry grandees bloviated. We all agreed that ATIS and IETF should define technical standards since they'd already made a start (Jim M did ATIS, for example) and so everyone agreed that STIR/SHAKEN was going to be The Path.
The original STIR/SHAKEN assumptions were that the attestation would be carried throughout the network in a SIP header and that every SIP processing element would deal with it. Reality soon intruded in the form of ancient telco equipment that didn't have the headroom to process another bunch of bytes in every call setup message. Another idea was to have signing and verification done by SIP application servers, but that didn't pan out for the same reasons. (Forgive me, I'm going to toot my own horn here for a second:) I invented a scheme with my colleagues where the signing or verification was an HTTPS operation triggered by the SIP device at the network perimeter (a 'session border controller' in telco-speak) which made the problem more tractable. AT&T took my PowerPoint and submitted a stunningly close copy as their own to the FCC. I still have the slides somewhere. I was salty at the time but ah well, what can you do: my employer still made money off the product with other customers.
- dredmorbius 2mo agoThanks! I'm going through the articles with interest. I've heard the "but we can't filter traffic at the network level" line from AT&T much more recently than that date. If there's any corporate learning that's occurred, it's not filtered through the ranks. It seems as if sorting out the STIR/SHAKEN situation with smaller telcos is going to have to happen. How that happens is something I don't have much clarity on, though I suspect some degree of national regulation and assistance will be required in the US. Your work could be an element of that? I've been ... unhappy ... with telecoms options for well over a decade now, and predicting the #DeathOfTelephony (one of my Fediverse topics/tags) for much of that time. It's coming about more slowly than I'd expected/hoped, but I'm seeing lots of strain. Enterprise/organisational frustration has been increasingly apparent over the past five years or so. Millennials and onward (as well as many Gen Xers) actively avoid voice calls. It's simply getting hard to connect to people. Then there's the privacy / surveillance / propaganda / manipulation elements. I think what I'd like is a SIP trunk to the house, and manage remote calls over WiFi (possibly with a SIP phone, I've got an old GSM 2G I'm thinking of doing some hardware-hacking on, or I could buy something ready-made). Carry a standard mobile for emergencies, but avoid it if at all possible, and route most comms through the VOIP system with a bunch of bespoke rules. If I were running a business there'd be other considerations. I'm ... glad I'm not, for the moment. The extent to which something vaguely resembling that might be more widely used ... I'm not sure. I'm thinking through elements I'd like to incorporate, might post that later (probably to the Fediverse or elsewhere for now).