Inspiration

In United States v. Suchowolski, 838 F.3d 530 (5th Cir. 2016), the opinion opens on "almost a quarter-century's unlawful receipt of social-security benefits in the guise of a person who died in 1990". Twenty-five years.

In Tokyo in July 2010, officials broke into a house and found Sogen Kato, dead since about November 1978. His family had drawn his pension the whole time, telling callers he was resting. The audit that followed could not confirm whether 234,354 people over 100 were alive.

Both have the same cause. Nothing in either process ever required a live human to answer for themselves.

The harm running the other way is bigger and gets less attention. To keep a pension, retirees living abroad have to produce a Certificate of Life: travel to an embassy, prove who you are, get it stamped. Miss it and the money stops. The digital replacements want a smartphone, a PC, or a fingerprint. The people who most need to prove they are alive are the least able to use an app.

A phone call reaches all of them. So we call.

What a call actually proves

Not that somebody is alive. Only that a human answered a line.

Every design that forgets this fails the same way: the agent asks "is Mr Kato there?", a relative says "yes, he's resting", and he is marked alive for the thirty-second year running.

So Muster does not return a boolean. It returns a dated, evidence-linked record of what one call did and did not establish, graded, with the reason named.

How the call works

Four stages. Who answered. Whether they say they are the subject, after being told plainly what the call will cause. Then three words minted for this call, said back in order, then today's weekday, then those same three words in reverse.

The reverse recital is the part that matters. A recording can echo words forwards. Saying them backwards means you understood the instruction.

The model extracts, code decides

The CALL-E result schema captures observations only: who answered, which words came back, whether another voice was audible. There is no alive field and no grade field in it.

Whether the words were right is scored in Python, with normalisation so a transcription difference never fails a living person. The model is never asked to mark its own work.

Six grades. Exactly one of them closes without a person: CONFIRMED_LIVE, PRESUMED_LIVE_WEAK, THIRD_PARTY_CLAIM, UNPROVEN, CONTRA, NEEDS_HUMAN.

Three moments in the demo

Henry Achterberg answers, passes every challenge, and is still not closed. He is enrolled as hearing-impaired, so he goes to a person. A machine never fails him.

Sofia Kallas gives every answer correctly and is still not closed. The transcript turns show an unattributed voice supplying those words eight seconds earlier. Right answers, wrong provenance.

The register says Beatrice Nkrumah is dead. She just repeated three words invented ninety seconds ago. The correction case opens against the register, not against her, and her payment does not stop.

The two rules underneath

Muster can confirm life. It can never confirm death. No grade concludes a death, because concluding one from a phone call is how living people get cut off.

And nothing here stops a payment. stops_payment is hard-wired False and swept by a property test over thousands of generated calls. One extra month of overpayment is a cheaper mistake than removing somebody's only income.

Why a weak check beats a strong one

Case Undetected Under this cadence
United States v. Suchowolski 9,125 days 40 days 228x
Sogen Kato, Adachi ward, Tokyo 11,570 days 40 days 289x

The model assumes one weak thing: after a death, no call can return CONFIRMED_LIVE, because nobody can answer a challenge minted seconds ago on somebody's behalf and a relative vouching is never a pass. Every other grade climbs the escalation ladder, and the ladder ends with a person.

An embassy certificate is stronger evidence gathered once a year, at the cost of a journey many pensioners cannot make. A call is weaker evidence gathered twelve times a year, for nothing. Run python3 -m muster.cli exposure to see it.

What it does not catch

Shipped as a table in the console rather than buried.

Attack Caught
A relative vouches for the subject yes
A recording answers in their own voice yes
Somebody in the room supplies the answers yes
The number now belongs to a stranger yes
A relative who knows the enrolled answers no
A synthesised or replayed voice no

CALL-E returns transcripts, not audio, so speaker verification is impossible and a synthetic voice passes. A test asserts those two are still not caught, so weakening either means editing that table in the same commit.

Challenges

CALL-E refused to place the call. The original design asked an enrolled question like "what was the first place you worked". The policy layer rejects that outright as collecting security-question answers. It is a sound anti-vishing rule, and it means a phone liveness check and a vishing attack look identical from the platform's side.

The fix was better than the thing it replaced. I tested candidate wordings against the live API and found that asking for the words in reverse passes where a personal question does not. It proves attention rather than secrets, and it collects no personal data at all.

Some Countries are refused at runtime. CALL-E's own region table lists some countries and the UK as supported. Both are rejected on this account; only US was accepted. That cost the live demo a working phone number.

The README argued for a system I had not built. It claimed "frequency beats strength" while the code placed one call with no cadence and no ladder. Writing the cadence, the ladder and the backtest was making the argument true.

Two bugs that were the thesis failing in miniature. nonce_ok recorded False for a challenge that was never asked, which reads as "they got it wrong" rather than "we never asked". And the coaching check only timed adjacent turns, so an intervening whisper, the exact case it exists to catch, hid the delay.

A security review from the maintainer. Two findings: the base_url override could send the API key to any host, and provider errors and call evidence could expose phone numbers. Both fixed, with the redirect case being the sharper one, since urllib re-sends the Authorization header across hosts and one 302 hands the key over.

What I learned

The hard part was never placing the call. It was deciding what a call is allowed to conclude. Almost every defect was a place where an absent answer had quietly become a negative one.

What's next

Real enrolment instead of a demo roster, a second number per subject so the alternate-number rung does something, and a written consent record attached to each attestation.

Built With

Share this project:

Updates

Submission history