DEF CON 33 - Journey to the center of PSTN - I became a phone company. You should too - Enzo Damato

DEF CON 33 - Journey to the center of PSTN - I became a phone company. You should too - Enzo Damato

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 44:20

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This video explains how to become a certified phone company and explores exploits within the Public Switched Telephone Network (PSTN) 0:00-0:40. The presenter details the technical and regulatory aspects of running a telecom carrier, including various billing loopholes and vulnerabilities that can be exploited 7:56-8:01.

Key Takeaways:
• The PSTN is any network allowing calls between standard US phone numbers, regardless of whether it uses traditional TDM or VoIP technology 1:09-1:33.
• Phone company certification types include CLECs (post-1996 competitive carriers), ILECs (incumbent local exchange carriers), wireless carriers, and IP-enabled carriers with different regulatory requirements 31:01-31:53.
• Access stimulation exploits allow carriers to generate revenue by encouraging inbound calls and collecting termination fees, using techniques like free conference calls and rural rate center arbitrage 18:03-19:01.
• The "TDM shuffle" technique allows robocallers to bypass STIR/SHAKEN caller ID verification by routing calls through legacy TDM networks that strip cryptographic headers 24:50-25:31.
• "Snowshoe" spamming distributes robocalls across multiple small VoIP providers to avoid detection, making caller ID filtering largely ineffective 27:25-28:05.

The video concludes with practical steps for obtaining telecom certification and setting up interconnection agreements, noting that while the process has been simplified since the 1990s, it still requires significant regulatory navigation 31:00-37:09.

Sources:

  • 0:00-0:40 Introduction to becoming a phone company and PSTN exploration
  • 1:09-1:33 Definition of the Public Switched Telephone Network
  • 7:56-8:01 The Telecom Act of 1996 and its impact on competition
  • 18:03-19:01 Expl

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

We have no time to waste and a lot of ground to cover. This is Journey to the Center of the PSTN. I am Enzo Damato and first a little bit about me. So I got into computing when I was very young. Got a bunch of servers, turned them into this, then got one of these, one of these and put my servers in a professional data center. Uh after doing that, I started looking for the next big challenge. I mean after getting an ASN, you got to find something new to do. And for me, the answer was telephones. I wanted to figure out how the phone network worked, how I could become a part of it, and some interesting and unique exploits that you could do from the inside of the phone network. And this talk will take you through all of that, how you can become your own Mob Bell. This talk, however, is not leg…