Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have a VOIP business account, and I can set any caller ID I want (including on SMS). And this is validated at the carrier level.

The main use case for this is redirection, when I get a call from A to my office O, it will also call my mobile phone M, but it is my PBX at O that start the call, so normally I would have O as caller on my phone, but I want A, so my PBX must be able to set the caller ID to A. I cannot use redirection at the carrier level, because a number might redirect to multiple mobile phone at the same time or recording the call or any feature that are provided by a PBX.

I guess this is a very common use case and it make it trivial to spoof caller ID.



"I have a VOIP business account, and I can set any caller ID I want (including on SMS). And this is validated at the carrier level."

There is an easy fix to this and I believe Twilio does this ...

You allow senders to announce CID for any number they have validated with your service (in this case, Twilio) ... so you prove to Twilio that you control that number and they they let you set that number as CID.

Seems like a very simple and elegant solution ... and allows for the use-cases that you are alluding to.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: