← Back to context

Comment by vel0city

4 months ago

"foreign device" based on IP geolocation is pretty tricky and annoying.

My home in Texas had an IP address which a lot of databases had as supposedly being in Montreal. It was like that for years. Gotta love so many sites trying to default to French.

As a network admin I have found that whitelisting only US address space for my companies IPs drastically reduces how many attacks we get.

  • As a person who had to deal with clients, I have found whitelisting to only "US address space" lead to lots of clients being unable to access the services until they were whitelisted.

    As a person who had to deal with other associates, I also found whitelisting only US address space led to a number of people being unable to connect from their homes.

    As a person who had this happen to them, I had quite a lot of frustrations with services insisting they couldn't provide me service because Texas is in Canada apparently.

    • of course before implementing this I log all IPs and verify that we don't have any legitimate traffic coming from non-US IPs. and whitelisting a few IPs isn't a big deal. Of course a medium sized manufacturing company in the Midwest isn't going to have much need for people connecting to use outside the US.

      I'm actually working to get rid of any public IPs that isn't a VPN access point.

      5 replies →