security, #api, #cybersecurity, #webdev
Last Tuesday, a paying customer in Austin couldn't finish checkout. Our fraud engine had flagged her IP as a "high-risk VPN." She was on Spectrum. At home. Watching Netflix on the same connection. The blacklist we paid $400 a month for had her entire /24 range marked as "datacenter" because a hosting company once leased part of that range three years ago, and nobody had bothered to refresh the entry.
That single false positive cost us a $2,100 annual contract. It also exposed something uglier: most VPN detection is astrology with better marketing.
Our tools struggle to separate a Tor exit node from a corporate VPN, a residential proxy, or a phone tethering through a coffee shop. We dump them all in one bucket labeled "risky" and move on.
Why geolocation alone is a broken fraud signal






