|
||
|
||
A border used to be something you crossed. On today’s Internet, a border can follow you. It can be inferred from an IP address, reproduced inside a cloud platform, embedded in an automated compliance system and ultimately revealed by something as mundane as an HTTP status code. This is one of the less visible ways in which geopolitics is reshaping the architecture of the Internet: not necessarily through spectacular shutdowns or nationwide firewalls, but through technical decisions that determine what works, for whom and from where.
A recent technical finding from Iran illustrates the problem. Imad Payande, who first documented and shared the case on LinkedIn, noticed that LinkedIn’s short-link domain, lnkd.in, behaved differently when accessed from an Iranian IP address. His testing provides the technical starting point for the broader Internet-governance question I want to explore here: what happens when geopolitical boundaries are translated into the infrastructure of an ostensibly global Internet? For readers unfamiliar with it, lnkd.in is LinkedIn’s short-link domain. When a link is shared through LinkedIn, the platform can use a shorter lnkd.in address that redirects the user to the intended content or destination. It is a mundane piece of Internet plumbing, largely invisible to users precisely because it normally works without requiring their attention. In the testing Imad published, however, this otherwise unremarkable intermediary behaved in a remarkable way. From an Iranian IP address, a LinkedIn short URL of the form https://lnkd.in/p/XXXXXXXX returned HTTP/2 403 Forbidden. LinkedIn itself remained accessible from the same connection, returning HTTP/2 200 OK. When the same lnkd.in URL was accessed through a non-Iranian IP using a VPN, the behaviour changed: the short link returned the expected HTTP/2 301 redirect, and the intended LinkedIn content subsequently loaded successfully with a 200 response.
The technical traces Imad shared make the distinction more significant. From the Iranian connection, lnkd.in resolved normally, the TLS 1.3 handshake succeeded and the certificate was valid for the domain. The request appeared to reach infrastructure serving LinkedIn traffic and received an explicit 403 Forbidden response. The observed response included x-colo-gcp: PROD-TLV. Through the VPN, the same URL produced the expected 301 redirect, while the observed infrastructure header was x-colo-gcp: PROD-FRA.
Based on those traces, the behaviour does not immediately resemble a simple DNS failure, a TCP reset, an obvious TLS interception problem or a blanket inability to access LinkedIn from Iran. The request appears to reach the service; what changes is the response. That still does not tell us why. Security or abuse-prevention controls, geolocation policies, CDN configuration, routing differences or other internal platform rules could potentially explain the result. Without confirmation from LinkedIn or Microsoft, it would be premature to attribute the behaviour definitively to sanctions. But Imad ‘s finding raises a question that extends well beyond one URL shortener or one technology company: if geography-based corporate risk or compliance controls are involved, at what point does sanctions compliance become infrastructure-level exclusion?
That question matters because sanctions do not remain legal documents once they encounter the Internet. They have to be translated into technical systems. Governments write laws and regulations; lawyers interpret them; compliance departments convert those interpretations into corporate policies; engineers and vendors then translate those policies into access rules, account restrictions, geolocation controls and automated decisions. At the end of this institutional chain, the user does not encounter the legal reasoning. The user encounters the interface—or, in this case, a 403 Forbidden.
This translation from law into code is politically significant. A legal rule can contain qualifications, exemptions and distinctions between different kinds of activity. Software, by contrast, requires operational decisions. A system must ultimately allow, deny, flag or escalate. For a global technology company, the incentives surrounding those decisions can be highly asymmetric. Accidentally providing a prohibited service may carry regulatory, financial or reputational consequences. Accidentally denying an ordinary user access to a permissible digital function may carry little comparable cost for the company. Under those conditions, excessive caution can become rational corporate behaviour. That is the essence of what is often described as “over-compliance”: not necessarily doing what sanctions law explicitly demands, but restricting more activity than the law requires because uncertainty itself has become a business risk. When this logic moves into digital infrastructure, however, its consequences extend beyond corporate compliance. A risk-management decision made in a legal or compliance department can become part of the effective architecture of Internet access for millions of people.
This complicates the familiar story of Internet censorship. We normally imagine the state as the actor standing between the citizen and the global network. Governments order websites blocked, compel Internet service providers to filter traffic, manipulate DNS, throttle connections or disconnect networks altogether. That model remains important, particularly in countries with extensive systems of Internet control. But it no longer describes the whole landscape. A growing amount of power over Internet access is exercised by private actors operating elsewhere in the stack: cloud providers, platforms, app stores, payment companies, identity services, content-delivery networks, cybersecurity firms and the vendors that provide them with geolocation and compliance tools.
The result is a different kind of fragmentation. A country does not need to be disconnected from a platform for its citizens to experience a diminished version of it. The main website may work while an API does not. An account may remain accessible while a developer service is unavailable. A platform may load while an authentication provider, download server, cloud dependency or redirect service refuses to function. Each individual restriction may appear minor. Taken together, they can create an Internet that is formally global but functionally unequal.
This is why the language of “Internet access” is becoming inadequate. Access sounds binary: either a person is connected or disconnected, a website is blocked or available. In reality, the contemporary Internet increasingly operates through layers of conditional permission. A user can be connected to the global network while being progressively excluded from the services that make that network socially, professionally and economically useful. Connectivity, in other words, does not necessarily mean participation.
There is a philosophical irony here. The early Internet was often imagined as a technology that would weaken the significance of geography. Packets could cross borders with little concern for the nationality of the person sending them. The network appeared to offer a space in which physical location mattered less. Yet much of the contemporary Internet is rebuilding geography on top of that supposedly borderless architecture. An IP address becomes an approximation of location; location becomes jurisdiction; jurisdiction becomes a category of legal or commercial risk; risk becomes corporate policy; and policy becomes a technical decision about whether a request should succeed.
The border has therefore not disappeared. It has changed form. Instead of encountering it only at airports, customs posts or national telecommunications gateways, users may encounter it inside the application layer. The Internet has developed something resembling an invisible passport system: users do not necessarily present their nationality or legal status, but infrastructure continually makes assumptions about them based on where their traffic appears to originate. Those assumptions can determine what they are permitted to see and do.
For people in sanctioned jurisdictions, this dynamic presents a particular paradox. International restrictions are generally justified as instruments directed at states, institutions, industries, transactions or designated individuals. But digital systems do not always preserve those distinctions cleanly. When companies respond to regulatory uncertainty by drawing wider boundaries than necessary, restrictions aimed at governments or economic activity can spill into the informational lives of ordinary people.
The consequences deserve attention because people living in politically and economically isolated societies may have an unusually strong need for access to global digital infrastructure. Researchers depend on international collaboration, engineers on global technical ecosystems, students on educational resources, journalists on communication platforms, entrepreneurs on professional networks, and civil-society actors on connections beyond national borders. If geopolitical isolation produces corporate risk, corporate risk produces technological caution, and technological caution produces further isolation, sanctions can generate effects that move far beyond their original political target.
This is where an old insight about cyberspace takes on a new geopolitical meaning. Lawrence Lessig famously argued that “code is law”: the architecture of digital systems can regulate behaviour just as effectively as formal legal rules. In the contemporary Internet, we might extend that proposition. Compliance code can become a form of foreign policy implemented through infrastructure. Not because engineers or technology companies necessarily intend to conduct foreign policy, but because their systems determine the practical consequences of geopolitical decisions.
A geolocation rule can function like a border. A risk classification can function like a visa regime. An automated access-control decision can reproduce a geopolitical distinction thousands of kilometres from the institution that originally created it. None of these analogies is perfect, but they point toward a significant redistribution of power. The Internet is governed not only through treaties, national laws and telecommunications regulators, but increasingly through private technical architectures whose rules may be difficult for outsiders to see, contest or even identify.
That opacity creates a problem of accountability. If a government blocks a website, there is at least a political actor whose policy can be examined and criticised. But when access is restricted somewhere within a chain of cloud services, compliance systems, geolocation databases and platform policies, responsibility becomes harder to locate. The government that created the sanctions framework may say that communications remain permitted. The technology company may say that its main service is available. The network operator may correctly observe that it has not blocked the connection. Each statement can be true, while the user remains unable to use part of the service.
For this reason, technology companies should be more transparent about jurisdiction-based restrictions. Users and researchers need to be able to distinguish between government-mandated blocking, legally required corporate compliance, discretionary risk management and ordinary technical or security measures. These are fundamentally different forms of governance, even if they can produce the same result on a screen. Where restrictions are legally required, companies should explain the basis where possible. Where companies impose broader controls as a matter of risk management, there should be room to ask whether those restrictions are necessary and proportionate, particularly when they affect communications and access to information.
The case of lnkd.in is therefore interesting precisely because it is so small. We do not yet know what policy, configuration or technical decision explains the behaviour documented in Imad Payande’s testing, and the evidence should not be presented as proof of sanctions-driven over-compliance without further confirmation. But small anomalies can reveal large structural questions. The future of the “splinternet” may not consist only of countries constructing visibly separate national networks. Fragmentation can also emerge incrementally, through thousands of decisions made by companies responding to different legal regimes, political pressures and perceptions of risk.
The global Internet may therefore fragment without ever appearing to break. From a distance, the same websites will remain online and the same domain names will continue to resolve. Up close, however, the network may behave differently depending on where a person stands. One API will work in one country but not another; one cloud service will accept an account while another refuses it; one link will redirect while another returns 403 Forbidden.
The central question of Internet governance has long been: who controls the Internet? Perhaps that question is no longer sufficient. We should also ask who determines the conditions under which the Internet works, who translates geopolitical boundaries into technical ones, and who is accountable when those boundaries extend further than the law itself requires.
A government can say it did not block the link. A company can say its platform remains available. A network provider can say the connection succeeded. All three can be correct.
And the user can still be standing on the wrong side of an invisible border.
Sponsored byIPv4.Global
Sponsored byDNIB.com
Sponsored byRadix
Sponsored byCSC
Sponsored byVerisign
Sponsored byWhoisXML API
Sponsored byVerisign