CallSign
Two-factor authentication, pointed the other way. You are asked to prove yourself to callers constantly; callers are never asked to prove themselves to you. Every impersonation scam ever run lives inside that one asymmetry. CallSign closes it — and closing it is not a matter of detecting anything, it is a matter of arithmetic they cannot do.
The whole idea in four lines
- Once, in person or signed in to their real site, you and the organisation agree a secret. It never travels again.
- They phone you. You read them four random words.
- They run the words through the secret and read six digits back.
- Your device does the same sum. The numbers match, or they do not.
The direction never reverses. The words go out from you, the number comes back from them. An organisation that phones and asks you to read them a code is running the oldest live phishing pattern there is, and this is not the exception to it.
Watch it work
This is not a mock-up. It is the real implementation, running on your device, doing HMAC-SHA-256 in your browser. Play the honest caller first, then make them an impostor and watch the same maths refuse them. Nothing here is stored or sent.
generating… (in memory only)The fence is a list of relationships, not a ring on a map
A geofence keeps things out by where they are. That does not translate to a phone call, and it is worth being blunt about why: the network cannot tell you where a caller is. A number is rented, not inhabited. A local area code costs a few dollars a month from anywhere on earth, and STIR/SHAKEN — which is genuine and useful — signs the number, not a location and not a claim. Any product that puts a flag or a city beside an incoming call is showing you where the number was issued, and that is not the same fact.
So the perimeter that actually holds is drawn around who you have a relationship with. Inside the fence: organisations you already deal with, where a secret exists and can be tested. Outside: everyone else — which is every cold call, by definition. Nothing outside the fence gets money, credentials, or remote access, no matter how urgent it sounds or how local it looks. That rule needs no technology and never gives a false reading.
Where the operations physically are is a separate, answerable question — from prosecutions and enforcement records rather than from caller ID. That map is kept next door in Fraudbase, which plots where floors were raided, never where a call “came from”.
How an organisation would join — with no registry to capture
There is no central list of “approved” call centres here, deliberately. A registry becomes the single thing worth attacking, and the moment it can be bought into it stops meaning anything. The trust anchor is the certificate on the organisation’s own domain — the one you already type into your browser. A company publishes a file at /.well-known/callsign.json and that is the entire onboarding:
{
"callsign": "v1",
"org": "Example Bank",
"enrolment": "https://www.examplebank.example/settings/callsign",
"callback": "+1-800-555-0100",
"direction": "caller-answers",
"never": [
"We will never ask you to read a CallSign response to us. You ask; we answer.",
"We will never ask you to move money to a 'safe account'."
]
}If you can reach their real website you can find their real enrolment page. If you cannot, no directory entry would have saved you either.
What is actually running
- Response = RFC 4226 dynamic truncation over HMAC-SHA-256, six digits.
- Signed message =
callsign/v1 ⏎ example-bank ⏎ anchor bridge copper dragon - Secret: 32 bytes from the system generator. Never transmitted by this page.
- Challenge: 4 words from a 128-word list — 28 bits, rejection-sampled so every word is equally likely. No two words share their first three letters, so a bad line cannot turn one into another.
- Single use, and valid for 5 minutes. An overheard answer is worth nothing afterwards.
- Comparison is length-independent, so the answer cannot be walked out one digit at a time.
- The clock is deliberately not part of the signed message — the caller would otherwise have to read a timestamp back down the phone for no gain.
What this cannot do
Read this part twice. A security tool that hides its limits is worse than no tool, because it spends trust it has not earned.
- Nobody is enrolled.
Not one organisation on earth supports this today. What is running here is a complete, working implementation and a specification anyone can adopt — not a service with members. Treat the demonstration below as a demonstration. - It does nothing on first contact.
CallSign only works with an organisation you have already enrolled with, in person or signed in to their real site. A company you have never dealt with cannot be checked this way, and that is most cold calls. - A pass is about the secret, not the person.
It proves the caller has the secret. A dishonest employee of a real bank passes. So does anyone who has obtained the secret. Identity is not permission. - A breach at their end kills it silently.
If the organisation's copy of your secret leaks, an attacker passes and you get no signal at all. This is the standing weakness of every shared-secret scheme, and naming it is the price of using one. - A live relay is the residual attack.
In principle an impersonator could phone the real organisation while you are on the line and try to get an employee to compute the response. It requires the organisation to hand a CallSign answer to an inbound caller, which the specification forbids — but a specification is not a control, and staff training is where this would fail. - It is not a lie detector, and it never becomes one.
There is no voice analysis here, no deepfake detection, no scoring of how someone sounds. Those do not work reliably and we will not ship one dressed as this.
If a call cannot be settled this way — and today none can, because nobody is enrolled — the move that has always worked still works: hang up and dial a number you already hold.