Manav.id
Definitional · 5 min read

STIR/SHAKEN attests the carrier, not the caller

STIR/SHAKEN attests the carrier, not the caller

Enterprises built verification procedures on a signal that was never designed to answer their question. Caller ID authentication tells you about a carrier's relationship to a telephone number. Voice cloning made the gap between that and who is speaking into a business problem.

What does STIR/SHAKEN actually attest?

That a carrier has a relationship with the number being used, and how confident it is about that. It signs the right to use a number, not the person using it. A cloned voice on a lawfully provisioned line receives full attestation and verifies perfectly.

Key takeaways
  • Attestation levels describe the originating service provider's knowledge of the caller's right to use a number. They are assertions about provisioning, not about people.
  • A legitimately provisioned number in an attacker's control yields full attestation, correctly.
  • Of the six questions an enterprise callback procedure is trying to answer, caller ID authentication answers none.

What the standards say, in their own terms

Carrier knows the customerand the numbertrueAttestation A signedhighest levelcorrectCall placedcloned voiceattestation still ARecipient trusts itas identitycategory error
Full attestation is a statement about provisioning, and it is correct.

Under the STIR framework and the SHAKEN governance model, an originating service provider signs a call with an attestation level. The definitions are specific and worth quoting in substance:

LevelMeaningWhat the provider is asserting
A — FullThe provider authenticated the caller and confirmed they are authorised to use the calling numberA relationship with the customer and their right to that number
B — PartialThe provider authenticated the call origination but cannot confirm the right to use the numberA relationship with the customer only
C — GatewayThe provider received the call from another provider and cannot authenticate the originNothing about the caller

Read the right-hand column. Every entry concerns a provider's knowledge of a customer and a number. The word person does not appear, and that is not an oversight — it is the scope of the standard.

The six questions a callback is trying to answer

When a treasury team calls back to verify a payment instruction, or a claims adjuster calls a policyholder, or a law firm calls a client about wire instructions, they are trying to establish six things. List them explicitly and the mismatch becomes obvious.

  1. Is this the person I believe it is?
  2. Are they acting of their own volition, not under duress or coercion?
  3. Do they have authority to give this instruction?
  4. Did they intend the specific amount and destination?
  5. Is the request current, not a replay of an earlier conversation?
  6. Can I demonstrate afterwards what they authorised?

Caller ID authentication answers none of these. It answers a seventh question nobody asked: did the originating carrier believe this caller was entitled to use this number?

Why full attestation on a fraudulent call is correct behaviour

This is the part that surprises people, and it is worth stating plainly because it is not a flaw.

An attacker who lawfully obtains a telephone number from a legitimate provider — a virtual number, a business line, a provisioned DID — is authorised to use that number. Their calls will receive full attestation, and the attestation will be accurate. The provider has correctly asserted the only thing it is in a position to assert.

The system is not being deceived. It is being asked a question it does not answer, by a party that assumed otherwise.

Caller ID authentication tells you that a carrier's paperwork is in order. It has never claimed to tell you who is speaking.

What branded calling adds, and does not

Rich call data and branded calling initiatives display a verified business name and logo on the recipient's handset. These are genuine improvements to consumer trust and to answer rates, and they raise the cost of casual spoofing.

They remain assertions about an organisation's entitlement to present a brand on a number. A call correctly branded as originating from a real bank does not establish that the person speaking works there, and an enterprise treating brand display as identity verification has made the same category error one level up.

Moving authorisation off the voice channel

The structural answer is not a better signal on the call. It is to stop using the call as the authorisation channel.

The conversation still happens — people need to discuss things. But the instruction is authorised out of band: the requesting party signs a canonical statement of the specific action, from a credential enrolled in advance, and the receiving party verifies it. The voice channel becomes what it is good at, which is communication, and stops being asked to carry a burden it cannot bear.

What to change in the procedure

  1. Write down the six questions your callback is trying to answer. Most procedures have never been articulated this way.
  2. Mark which are answered by the call itself. Honestly, it will be none.
  3. Identify the instruction types where the six questions actually matter — usually payment, beneficiary and access changes.
  4. For those, require an out-of-band signed confirmation and keep the call for discussion.
  5. Stop describing caller ID authentication as verification in your control documentation. Regulators and insurers read that documentation.

The three attestation levels, and what each claims

What the levels mean
LevelCarrier asserts
A — FullIt knows the customer and their right to use the number
B — PartialIt knows the customer but not their right to that number
C — GatewayIt is passing the call on without either claim

None of the three says anything about who is speaking. That is not a flaw; it is the scope the framework chose, and it addresses spoofing effectively. The error is downstream, where a verified caller ID is read as a verified caller.

Objections and honest limits

“So caller authentication is useless.” It is effective against the problem it targets — spoofed numbers — and that problem was large. It simply does not reach voice cloning, which arrived afterwards.

“Branded calling fixes it.” It adds a display name backed by a vetting process. That raises the cost of impersonating a brand and still says nothing about the individual on the line.

Using attestation correctly

  1. Treat attestation as anti-spoofing, not identity. It is a statement about provisioning.
  2. Never use a verified number as an authorisation factor. Especially for account recovery or payment confirmation.
  3. Assume the voice is clonable. Because it is, from seconds of public audio.
  4. Move the authorisation off the call. To a signature on the account holder's enrolled device.

Terms used here

Attestation level
The originating carrier's claim about its knowledge of the customer and their right to the number.
Spoofing
Displaying a calling number the caller has no right to use — the problem caller authentication addresses.
Voice cloning
Synthesising a specific person's voice, now achievable from short public samples.

Frequently asked questions

Is STIR/SHAKEN broken? No. It does what it was specified to do, which is to attest a provider's knowledge of a caller's entitlement to a number. The error is in what enterprises inferred from it.

Does voice biometrics close the gap? It attempts to, by detecting synthesis. That is a detection contest against generation, which is structurally the losing side, and it introduces biometric retention obligations.

What about calls where no transaction is involved? Then the six questions do not apply and caller ID authentication is doing useful work — reducing nuisance and spoofed calls. The critique is narrow and applies to authorisation.

How do we handle counterparties who will not adopt anything? Keep the callback for them and record that the control is weaker for that counterparty. Documenting a known weakness is better than describing it as verification.

Does full attestation mean the caller is verified? No. It means the carrier knows its customer and their right to the number. It says nothing about who is speaking.

Is the framework failing? No. It addresses spoofing, which was a large problem, and it does that well. Voice cloning is a different attack that arrived later.

What should a bank do with a verified number? Treat it as anti-spoofing context, never as an authorisation factor for recovery or payment.

Where this fits in Manav

Manav puts the subscriber or the authorising party back in the loop for the changes that matter, with a signature bound to the specific change and verifiable by a bank, a regulator or a counterparty without calling the carrier.

See change authorisation →

Sources and further reading