The Phone Number Has a History Problem

  • Post author:
  • Post category:
    messaging

In telecom, most of the data we rely on has dubious provenance. 

Ever wonder how the “Spam Likely” label on your phone works? Or why even your mobile carrier doesn’t always know a caller’s identity for certain? 

It’s not that the data is wrong—often it’s better than when it started—but somewhere along the way, the data has been copied, enriched, aggregated, normalized, correlated, scored, repackaged, and resold. And this is done to the point where its origin story is like gossip: It depends on who you ask. The data looks rich, but you don’t know whether the checks it’s writing are any good.

And that’s an important distinction. Provenance is not trust. Knowing exactly where a piece of information came from doesn’t make it true, just as not knowing its origin doesn’t automatically make it false. Provenance gives us the history and someone to hold responsible if the data is inaccurate. It is a necessary but not sufficient input to trust.

I’ve written before about the unbuckling of the phone number and identity. Today we’ll see one way this happens.

The Phone Number

A phone number is the oldest digital user ID. But is your phone number actually yours, or does a carrier assign a number to you and give you the Right to Use (RTU) it? When you port the number from one carrier to another, does the ownership change or just the network endpoint?

At this point, telecom experts will draw complex flow diagrams showing how a phone call gets terminated. But that’s the point: The answer to a seemingly simple question—who owns this phone number—is so convoluted that even the experts can’t definitively answer it.

Every Hop Adds Value

A phone call can touch a retail carrier, an underlying carrier, an ILEC or CLEC, and the terminating carrier. Each sees a different part of the same call, and each can have perfectly accurate data based on what it sees. So whose record is the truth?

The data becomes richer while its provenance becomes murkier.

That’s one of the shortcomings of the Caller ID Name (CNAM) ecosystem. There isn’t one authoritative CNAM database in the US. There are multiple databases and providers, each potentially seeing or maintaining a different version of the caller name associated with a number. The data can be accurate at the point where it was created, but as the number moves across networks, carriers, and databases, the context around that data doesn’t necessarily travel with it. Each participant knows something, yet none knows everything.

Unpacking Spam Likely

Your carrier isn’t looking up an authoritative fact that says a particular call is spam. Spam Likely is an inference based on calling patterns, knowledge about the phone numbers, and models that tie them together. One piece of the system may know something about the number; another about the caller. An analytics engine may observe behavior and make determinations about caller reputation. Despite all the data available, there’s very little sharing between them, making any conclusion about the call an educated guess.

Telecom has lived with such ambiguity for decades. In an open network built on open standards, there are few ways to be certain. Yes, STIR/SHAKEN helps, KYB helps, better routing and analytics help, but you still can’t be sure.

STIR/SHAKEN, for example, has three attestations: A, B, and C. With C attestation, the originating provider cannot authenticate the caller’s identity or their right to use the number. It’s not that the call is shady but that the provider can’t vouch for its origin. In fact, in many cases, AT&T defaults to attestation C for calls that originate outside its own network and its trusted mobile partners.

So, when your phone says “Spam Likely,” those two words are the result of quite a bit of work. They are a strong signal that the call may be spam and, unless it’s a number you recognize, you’re probably better off letting it go to voicemail. But they remain an inference.

Your carrier is essentially saying, “We think we’re right, but make your own decision.”

The Home Depot Problem

If you want to confirm someone will be available to take a delivery, it’s important that the call gets answered. The cost of a couch being returned and rescheduled can run into hundreds of dollars.

So, if you’re Home Depot (or any retailer), what can you do? You can put your phone number on an allowlist. Except allowlisting turns out to be nearly impossible because of the many hops across the network. So, you find an intermediary who charges a fee to manage it for you.

Then you learn that isn’t failsafe either. Analytics engines operate independently. They look at calling patterns and can still mark your calls as spam, which means a carrier may decide not to complete the call. Now you have another problem: How do you get people to answer so that short call durations and calls going to voicemail don’t unduly ding your reputation?

You are then told there are multiple ways to get your brand and company name to show up on the recipient’s phone. None is a 100% solution. Every carrier is implementing its own approach and, in the name of protecting the network, there is no single place where you can pay to make sure you have even 90% coverage.

So you pay because you have to, partly because it is the cost of doing business and partly because it is the business.

Home Depot is buying confidence and hope. Confidence that the network honors its right to use the number, confidence that the call will complete, and hope that the customer will trust the number that appears on the screen (more on this later).

Before we go hammering the industry for this messiness, know that it’s a systemic problem. The authoritative signal that this is indeed Home Depot doesn’t flow automatically end-to-end. It boils down to a heterogeneous network with fragmented implementations, differing commercial incentives, and network policies.

Think of making a phone call as making a series of handshakes across the network. A single call can involve many handshakes, and each handshake needs to be paid.

Trust

Home Depot spends all this time, money, and paperwork putting its logo on the phone call to get you to trust the call. And that’s where things get into a gray zone. You make a trust decision based on the caller ID, the logo, and whatever else is going on in your life: Answer the call or let it go to voicemail. All Home Depot can do is spend and hope.

While Home Depot is paying insurance that the provenance of its call is preserved and transmitted, it is the customer who decides if the call is indeed from Home Depot.

This is the key distinction between provenance and trust. Provenance is history; trust is a bet. 

Finally

There are simple rules to see if your phone number information provider is the right partner. What data do they have clear provenance about, and what are they aggregating? What can they say is accurate, and what is their best guess? Not because I don’t trust their data, but because I want them on the hook when it’s wrong, instead of telling me they just passed along what they got from their supplier.

And if they’re selling trust scores, they should be prepared to explain how they’re calculated. Otherwise, treat it like the weather report: a likelihood, not a certainty.

Ultimately, provenance requires a historical trace, and that’s a fundamentally hard problem. In his classic, Against the Gods, Peter L. Bernstein put it best:

The information you have is not the information you want. 

The information you want is not the information you need. 

The information you need is not the information you can obtain. 

The information you can obtain costs more than you want to pay.

In identity, provenance is power. And it is expensive.