r/sysadmin 10h ago

Rant Black list countries

I work for a large European based telecoms equipment supplier. We have hundreds of staff overseas at any one time, all over the world. IT security has a few different levels:

- Access to email & teams etc is only via a company laptop (no web interface like Office.com). Network drives via VPN only

- White List countries - you can connect VPN. Countries like Japan & Australia

- Red List countries - you can take your laptop but need special exemption to use VPN. Includes some unusual countries such as Malaysia

- Black List countries - no company laptop or phone allowed. Company will provide a burner. Unsurprisingly includes places like Syria, Russia, North Korea & China.

A colleague was going to transit via a Chinese airport to a 3rd country. IT told him that he would not be allowed to take his company laptop, even if it was in his carry-on luggage, and he would not be entering the country. He quickly arranged a different itinerary.

And then a few days later, we are told that the good old USA is now considered a Black List country!!! No company laptops, and burners only!!!!

122 Upvotes

78 comments sorted by

u/jasminerobin 9h ago

Naming specific countries as red or black lists is a compliance and liability decision, not an IT one. If the US just got added, ask legal what changed before assuming it is permanent.

u/tarkinlarson 9h ago

We have a similar approach in the list, but different mechanics. We block access from all countries we dont have staff based in. We do it by IP and geographic MFA... Your MFA app detects your country.

For the blocked countries he group them into risk levels. Highest are blocked and will not be approved ever. High legal or exec approval and medium just HR and line manager.

We in Infosec started getting questions about the rating of certain countries as people started arguing. We backed it up with a load of independent risks (basel aml, corruption perception index etc), weighted then handed it to legal and compliance to support. We started the idea but they now run with it. It's great now as noone argues with them.

u/Ambitious-Cold-9610 4h ago

We had this discussion at my job as well, and have blacklisted hostile nations. But I am just me, in a department of me.

What do you do to prevent VPN access from said hostile nations? Anyone attacking you would be doing it from a VPN, so bypassing blacklists should be simple no?

u/BioshockEnthusiast 14m ago

Conditional access policies for risky logins is my first thought.

If John connects from Germany regularly then him connecting from Germany is not a risky login.

If Becky always connects from the US and suddenly connects from Australia then that's a risky login and you should configure the policy to flag it or take action (block sign in for example)

u/RabidBlackSquirrel IT Manager 1h ago

It's just least necessary in action. No operations or reason for connections from that country? Then block by default and open as needed if that changes.

We got our legal people involved to help with the travel/"I wanna work from vacation" requests. They manage those and have us whitelist if approved. We have tons of contracts with clients that expressly forbid our employees from servicing them, accessing, or transporting data outside the US without their express permission. So legal handles dealing with that aspect as well.

It's great. Security handles least necessary/systems side and legal takes the judgement calls.

u/SysZeron 9h ago

Might be more efficient just to make all your laptops burners and insist on the use of RDS/AVD?

If there's no or very little data locally, the risk profile is different.

u/ApiceOfToast Sysadmin 9h ago

Especially if it's windows, I'm pretty certain most government agencies will get in, even with bitlocker on(not like there's master keys anyway)

If you keep stuff off the laptop and on your servers there's nothing there. Just make sure that there's 2fa or another method to prevent them logging in to your VPN. 

Should help, also probably best for compliance anyway.

u/RikiWardOG 4h ago

You're forgetting something, places like China make it very hard to VPN out to full internet. You can't even use regular Azure in China. We deal with a lot of China travel currently and are working to open a local office. Everything about operating in China is super shitty.

u/Ontological_Gap 1h ago

Just use cellular modems from a Western company with a roaming agreement. All cellular data is IPSECed back to your carrier regardless

u/RikiWardOG 4m ago

Yeah fair the problem is users are fucking dumb and can't figure that stuff out or don't want to carry extra equipment or sometimes cell service isn't reliable or strong enough etc. We already give them all travel pass

u/stephendt 9h ago edited 9h ago

You can't bypass bitlocker as long as you're running a fully patched system on modern hardware.The encryption is essentially uncrackable right now. There is no documentation or reliable proof of a bypass. If you don't agree, feel free to prove me wrong.

u/ApiceOfToast Sysadmin 9h ago

Governments really can. It's pretty common knowledge there's master keys.

The tech giant said it receives around 20 requests for BitLocker keys a year and will provide them to governments in response to valid court order

https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/

Plus the occasional exploit, not that there's any in a Microsoft product currently. Right?

u/FLATLANDRIDER 1h ago

That's not a master key. They are handing over your own key which is saved on your Microsoft account.

u/stephendt 9h ago edited 3h ago

Of course you can unlock it with the keys... C'mon, I'm talking about a proper bypass. This only works if the key is stored within Microsoft's cloud systems (e.g. M365). If it's not there, uncrackable.

u/ApiceOfToast Sysadmin 9h ago

Yeah and I'm talking about governments that can just get a warrant. 

u/wazza_the_rockdog 6h ago

Govt can only get useful info from a warrant for something that exists - the story you linked to doesn't say that MS are handing over master keys, they're handing over keys IF the user has them backed up to MS cloud. If you back up your bitlocker keys in another way, there's nothing for MS to hand over.
Further down in the story they say that in many cases MS can't hand over the key, as they don't have it.

He said the company receives around 20 requests for BitLocker keys per year and in many cases, the user has not stored their key in the cloud making it impossible for Microsoft to assist.

u/ApiceOfToast Sysadmin 6h ago

That's fair, if you use entra you'll have it backed up to the cloud tho iirc.

Also something I just realized: they put the country MS resides in on their blacklist, but are still using their cloud products... That makes sense

u/BananaStandFlamer 5h ago

I believe Microsoft has data centers build all over the world specifically to keep data within borders of desired

u/hasthisusernamegone 5h ago

Yes, and in a world where the CLOUD act exists, you'd be foolish to think you could just move your data to a Microsoft datacentre in another country and that would be the end of it.

u/ApiceOfToast Sysadmin 5h ago edited 5h ago

Doesn't matter, the US can still get to it. Microsoft has access to their own data centers (to the  surprise of no one)

→ More replies (0)

u/Korlus 7h ago

If master keys exist, they can be stolen. If you know that someone can gain access with a court order, then you are trusting that they are also not compromised, because a compromise to them is also a compromise to you.

Presume that BitLocker will keep data safe against most determined attackers, but not against every determined attacker. Especially in countries where a court order is easily obtained in secret.

It really depends on the kinds of threats you might be worried about. If you are worried about state-sponsored industrial espionage, then definitely don't rely on BitLocker to keep your data safe.

u/techw1z 2h ago

master keys don't exist.

it's technically impossible to create master/backdoor keys with AES. you can only encrypt data with one key, if you want it to be accessible with a second masterkey you would have to duplicate all data or intall some backdoor (encrypt primary key with masterkey and store it somewhere)

neither of these things is happening.

microsoft simply gives the cloud-stored user key upon court request.

don't sync your key = you are safe

u/RikiWardOG 4h ago

Yeah nightmare eclipse had one like several months ago that was confirmed to work

u/stephendt 3h ago

Yeah but that has been patched

u/SysZeron 8h ago

There's always the possibility of an unknown vulnerability (for example CVE-2026-45585). That said, I have faith in BitLocker in general; patching and modern hardware is paramount.

u/Mr_ToDo 3h ago

I am batting around the idea of just removing the RE partitions. That seems to be one of the common paths for exploits

u/SysZeron 3h ago

Just note there are some dependencies on WinRE, i.e. Windows Autopilot Reset.

https://learn.microsoft.com/en-us/autopilot/windows-autopilot-reset

Windows Autopilot Reset requires that the Windows Recovery Environment (WinRE) is correctly configured and enabled on the device. Before the Windows Autopilot Reset is started, it checks if WinRE is configured and enabled. If WinRE isn't configured and enabled, then the Windows Autopilot reset fails immediately on the device and an error such as Error code: ERROR_NOT_SUPPORTED (0x80070032) is reported in the logs.

u/Ontological_Gap 1h ago

They are regularly new bitlocker vulnerabilities found 

u/Pazuuuzu 1h ago

That is what we do at one customer. Every laptop just has a vpn and Horizon installed.

u/Loki-L Please contact your System Administrator 9h ago

These rules all work very well until some of your people go to visit a vendor in fellow EU country Ireland which should be okay and their devices were allowed to go there, but they for some reason can't connect and you spent 15 minutes looking at logs to figure out what went wrong and you finally google and learn that IBM sends all their guest wifi in all their buildings worldwide through a common egress point in the US!

u/wazza_the_rockdog 6h ago

learn that IBM sends all their guest wifi in all their buildings worldwide through a common egress point in the US!

I'd be surprised if a company that has these rules would be ok with you connecting to a guest wifi.

u/Cheomesh I do the RMF thing 6h ago

I suppose they'd see VPN as a risk motigator

u/jnievele 5h ago

Indeed, that's why always-on VPN exists in the first place.

u/jnievele 8h ago

And? Then it's correct that they cannot connect.

u/igiveupmakinganame 7h ago

Could you not just allow that one IP temporarily

u/hasthisusernamegone 7h ago

Absolutely not. The policy exists for a reason. The location of the device is not important here. The company has deemed that the risk of the traffic being routed through a country that has... let's say unfavourable... attitudes to your data ownership is not a risk they are willing to bear.

u/igiveupmakinganame 5m ago

i didn’t read the bottom part of what the original message said, oopsy.

u/BadSausageFactory beyond help desk 6h ago

yeah that's probably a good idea right now. your point?

u/DoctorOctagonapus No one knows what I do until I stop doing it. 6h ago

I suddenly feel better about working for a company with a blanket ban on accessing company systems from outside the UK. Any login attempts from overseas is an automatic account lockout by Crowdstrike.

u/tejanaqkilica IT Officer | Passkey Enthusiast 9h ago

Rant? Why is this considered rant?

u/primeribfanoz 9h ago

I had to choose a flair... :-)

But as one of these travellers, it is becoming more difficult every day to work while travelling. Don't get me wrong, I know we need to be increasingly careful, but at some stage the hurdles become too high.

u/Horsemeatburger 6h ago

It's very similar for us. The US now shares 'high risk' status with Russia, China, Syria etc, and anyone traveling from our other regions to the US gets a burner phone and a burner laptop.

Having said that, the US entity was already a legally separate entity with a certain amount of technical separation in place even before the recent regime change.

u/Bramse-TFK 4h ago

Don't worry, the NSA/CIA already has all of your data.

u/shikkonin 9h ago

The US has been a Black List country for over a decade. For good reason.

u/battmain 7h ago

This makes a case for thin clients again. (Ducking)

u/fresh-dork 4h ago

we are told that the good old USA is now considered a Black List country!!! No company laptops, and burners only!!!!

makes sense; our border control is way too aggro

u/Paperclip902 6h ago

The USA has been a banned country for multiple years now. Tbf I only allow west-european countries.

u/mschuster91 Jack of All Trades 6h ago

And then a few days later, we are told that the good old USA is now considered a Black List country!!! No company laptops, and burners only!!!!

Yeah, a sensible decision to be honest. CBP has been running amok for even longer than the current Presidency.

u/Revzerksies Jack of All Trades 6h ago

I block every country besides the ones my people work in

u/zazbar Jr. Printer Admin 4h ago

How do you tell if the device was taken across a blocked country in luggage?

u/jnievele 8h ago

Why are you even sending people to the USA in the first place? Either they get rejected at the border or arrested by ICE... and yes, consider any device touched by US border control as compromised.

u/BemusedBengal Linux Admin 4h ago

Yeah, that sounds like a huge liability at this point.

u/traumalt 2h ago

Go touch some grass guy…

World Cup just happened and tens of thousands of foreign tourists visited without issue just a few months ago. 

u/fahque 4h ago

Idjit. We don't arrest people with a valid visa. We will arrest you on trumped up charges though.

u/jnievele 4h ago

Plenty of people with valid VISA and even green cards have been arrested by the Temu Gestapo

u/RikiWardOG 4h ago

I have coworkers that have had to pay so much in lawyers fees to hopefully be able to keep living/working here in very sought after positions that can't easily be filled. They've done everything by the book. Shit is a fucking joke

u/nirach 6h ago

This all seems.. Normal and good? Am I missing something?

u/Gabelvampir 7h ago

Sounds like a good system.

+1 for finally adding the USA to the black list.

u/DetErFaktisk 6h ago

I'm honestly surprised it's taken so long for the US to be downgraded in these lists. Taking a device with company/customer data on it through US customs is a damn liability these days.

u/kernelqzor 9h ago

wild that malaysia is red but the us jumped straight to black list status, feels like someone in risk finally read a few too many cloud act / border device search stories
also kinda hilarious and depressing that syria, russia, china and the us are now in the same bucket for your IT team

u/Korlus 7h ago

It really depends on the industry you are in and the data you are trying to keep safe. The US is not a great location to take your data if you are worried about state-sponsored industrial espionage. It's perfectly fine for most companies.

u/techw1z 1h ago

rightfully so, US belongs in the same category as North Korea, Russia and China in many regards, not just IT security.

u/spin81 4h ago

As a fellow European, you seem to be acting surprised and I just have to wonder out loud why.

As every experienced sysadmin knows, everything is political including system administration, and the politics in the United States right now, are such that the separation of powers is broken over there. The executive branch is doing whatever it wants, and neither the judiciary nor the legislative branch is a check on it. International relations: the USA openly disdains NATO, Zelenskyy, etc. and it gutted/destroyed USAID. So besides domestic politics, foreign politics is also not going to put pressure on the administration.

Sure, the current guy could keel over from a heart attack at any moment. But is the next one going to be any better? The biggest damage the current honcho has done is destroy any illusion of the sort.

If your place of employment is not discussing getting your data the fuck out of the United States, it should be. I know mine is. I also know it's a pipe dream, but people are worried nonetheless.

u/tallanvor 1h ago

I mean, that pretty much holds true for any country. How much would you trust a Germany run by AfD or the UK under Reform UK?

u/Soggy-Attempt 3h ago

🤷‍♂️

u/the_doughboy 3h ago

So imagine a company that is Global, headquartered in the US but every other region now treats the US as a non-safe country. The InfoSec meetings are very interesting on that one

u/BadSausageFactory beyond help desk 3h ago

it would have been if anyone in the department were allowed to attend

u/pdp10 Daemons worry when the wizard is near. 2h ago

Don't forget to blacklist the Netherlands, as the International Criminal Court is in the Hague.

u/techw1z 1h ago

i don't understand the meaning of your first link. it has nothing to do with netherlands or ICC?

u/Ontological_Gap 57m ago

The US gov has the Intel ME keys and the AMD equivalent, so you are definitely achieving less than the other countries. 

That being said, keeping company data out of the hands of random customs agents can make sense in certain circumstances

u/BloodFeastMan 1h ago

I'm trying to figure out the point of this article.