CDN Admins are Killing Your Business
Here is an example of using my Hong Kong data in Canada, you may think that is weird but let’s just use this and pretend that today “I’m a Hong Kong tourist” or maybe “new to Canada” and I’m using a roaming data package. When you have roaming data on a cell phone, it means all data is back-hauled through the local telecom provider (eg. Rogers/Telus) and then back to the home country’s network. So even though I’m in Vancouver, and my roaming has connected to Rogers, the rest of the world, including websites I visit, just see a Hong Kong IP.
Canada and especially the Vancouver area get tourists and people from around the world. I can’t think that my foreign data from Hong Kong is the first and only case you’d see of frequent travellers who end up having a non-Canadian IP.
But apparently the Sysadmins at most major companies have not thought of this or their “cybersecurity training” didn’t teach them much about how the situation I’m in actually works and is a real life, valid case that extends outside of certifications and text books. We often worry about foreign IPs accessing our local website, but this is a legitimate and not uncommon case, to expect the use of foreign IPs accessing their company’s website(s). In most cases they are using a CDN from Akamai, Microsoft, Cloudflare, or Amazon and have only allowed Canada or selective countries and with the click of a button they have now lost businesses from all the tourists that come here and anyone who permanently roams in Canada.
These are just a few examples, in general I think the rather default settings for most local companies have been applied which basically only allows local country IPs. And of course being an admin and in cybersecurity myself, I completely understand the value in blocking IPs that have no business accessing services as it can enhance security. But it seems most companies and admins have not thought this through or haven’t been trained in an internationally connected world.
Imagine how much money the companies are losing when tourists cannot visit most sites and services that use Amazon, Cloudflare, Akamai, Cloudflare, or Azure CDN, and likely any other click it and forget it type of CDN service? This is one reason I never advise companies to just use “any CDN” or not discuss the implications of CDN/WAF/Firewall policies with actual business stakeholders within the organization, or real humans who may better understand their users.
Of course the solution here for someone like myself is to use a VPN to access local services, but I am sure most travellers are not like myself and would not clue in that we are being geo-blocked, since most of the time we just get an access denied without proper explanation I would say most travellers will just move on to a site that does work and this is where it pays to have a company that understands the world as a whole.
Here I was being a bad foreign hacker, trying to view the movies

I thought I’d try the competition at Landmark Cinemas:

Then I thought I would order rice from the grocery store but that wasn’t going to happen too since foreign IPs should never need groceries in Canada.

I think was I trying to pay for parking with this one. To their credit, this is the only site that at least tells you that you are geo-blocked.



