[VoiceOps] [EXTERNAL] Identity Header Test Tool

Zilk, David David.Zilk at cdk.com
Tue Jul 5 13:01:48 EDT 2022

If that is the case, a scammer that should be either attested C, or not attested at all can game the system and upgrade their calls to any customer of Bandwidth to B. Granted, B attestation isn't much better than nothing, but still it violates both the intent and the letter of the law.

David Zilk
CDK Global/IP Networked Services

From: Mark Lindsey <lindsey at e-c-group.com>
Sent: Tuesday, July 5, 2022 9:58 AM
To: Zilk, David <David.Zilk at cdk.com>
Cc: voiceops at voiceops.org
Subject: Re: [VoiceOps] [EXTERNAL] Identity Header Test Tool

I expect Bandwidth is attesting that they know the identity of the SIP trunking provider that sent your call to Bandwidth.

CDK Global -> [term provider 1]  -> [term provider 2, Strips Identity Header] -> [term provider 3] -> [Bandwidth.com<https://urldefense.proofpoint.com/v2/url?u=http-3A__Bandwidth.com&d=DwMFAg&c=N13-TaG7c-EYAiUNohBk74oLRjUiBTwVm-KSnr4bPSc&r=VcRLyVxkyGds34uxiPM944HQvaWq-nynyZXfNpSfhOs&m=qZMqiJ48ZdgXQNJnrLDT8ChNCkk7sQ42nMiHCNHAHu2zOSre0DPgkmi2n_jtKDvD&s=R4TtBNn8t5SrkyFy1ozowPSgquZflYU50Y-F6uixyH0&e=>]

...And term provider 3 is a customer of Bandwidth.com.<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.bandwidth.com_blog_abcs-2Dof-2Dattestation-2Dand-2Danalytics_&d=DwMFAg&c=N13-TaG7c-EYAiUNohBk74oLRjUiBTwVm-KSnr4bPSc&r=VcRLyVxkyGds34uxiPM944HQvaWq-nynyZXfNpSfhOs&m=qZMqiJ48ZdgXQNJnrLDT8ChNCkk7sQ42nMiHCNHAHu2zOSre0DPgkmi2n_jtKDvD&s=G7fgN1eoXUXYZw4vwpfoD5Doij6odPvNXwS2PHlZyM0&e=>

Mark R Lindsey | SMTS | +1-229-316-0013 | mark at ecg.co<mailto:mark at ecg.co>
Schedule a meeting<https://urldefense.proofpoint.com/v2/url?u=https-3A__ecg.co_lindsey_schedule&d=DwMFAg&c=N13-TaG7c-EYAiUNohBk74oLRjUiBTwVm-KSnr4bPSc&r=VcRLyVxkyGds34uxiPM944HQvaWq-nynyZXfNpSfhOs&m=qZMqiJ48ZdgXQNJnrLDT8ChNCkk7sQ42nMiHCNHAHu2zOSre0DPgkmi2n_jtKDvD&s=CBHDNMBQRfN66ebOCNYxTHugStaeRttBIJ0aIgaIuEk&e=>

On Jul 5, 2022, at 12:19, Zilk, David <David.Zilk at cdk.com<mailto:David.Zilk at cdk.com>> wrote:

I am getting results from a test to the Bandwidth number that are confusing. It appears that our Identity header is not making it through to them, however the call does have an Identity header, certified by Bandwith, with B attestation. This is odd as we don't have any direct business relationship with Bandwidth. How can they claim B attestation?

David Zilk
CDK Global/IP Networked Services

-----Original Message-----
From: VoiceOps <voiceops-bounces at voiceops.org<mailto:voiceops-bounces at voiceops.org>> On Behalf Of David Frankel
Sent: Sunday, July 3, 2022 8:05 AM
To: voiceops at voiceops.org<mailto:voiceops at voiceops.org>
Subject: [EXTERNAL] [VoiceOps] Identity Header Test Tool

CAUTION: This email originated from outside of the CDK organization. Exercise caution when clicking links or opening attachments, especially from unknown senders.

Last week I was forwarded a note from this list regarding tools to test and debug SHAKEN Identity headers. That prompted us to stitch together some modules we already had in an attempt to help.

What we have is at http://identity.legalcallsonly.org<https://urldefense.proofpoint.com/v2/url?u=http-3A__identity.legalcallsonly.org&d=DwMFAg&c=N13-TaG7c-EYAiUNohBk74oLRjUiBTwVm-KSnr4bPSc&r=VcRLyVxkyGds34uxiPM944HQvaWq-nynyZXfNpSfhOs&m=qZMqiJ48ZdgXQNJnrLDT8ChNCkk7sQ42nMiHCNHAHu2zOSre0DPgkmi2n_jtKDvD&s=9EE8xl5gvlIOy3Ck4bTVDx8WWiobc-X72SZEUOtN0o8&e=>. You can call one of the test numbers listed on that page, and if we receive your header, we'll read you a six-digit code. Disconnect and then plug the code into the box on the web form, and we'll show you details of that Identity header.

Perhaps most importantly, you'll be able to see if the header we received is the one you sent. In addition, we parse the header and try to tell you if it is correctly formatted and valid.

Currently we have a couple of geographic DIDs and three toll-free numbers (each using different underlying providers). So far we aren't having a lot of success getting the Identity headers on the TFNs; we're working to improve that.

Suggestions welcome. We hope the tool provokes more discussion about best practices regarding making the Authentication Framework as functional and useful as possible.

Happy 4th of July!

David Frankel
St. George, UT USA

VoiceOps mailing list
VoiceOps at voiceops.org<mailto:VoiceOps at voiceops.org>
VoiceOps mailing list
VoiceOps at voiceops.org<mailto:VoiceOps at voiceops.org>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://puck.nether.net/pipermail/voiceops/attachments/20220705/bb903079/attachment-0001.htm>

More information about the VoiceOps mailing list