top of page

Canadian Shield

  • Jun 24
  • 4 min read
Scutum – Roman shield
Scutum – Roman shield

This is a shield. Not the one I wanted to show, but a shield nevertheless. I actually wanted to show an image of the coat of arms of Canada, even though it was created long after the point at which it might reasonably have been placed on an actual shield, but I stopped when I found a notice on the Governor General’s website stating that the heraldic emblems may not be reproduced without written consent. (I strongly suspect that my using that image would have been covered by “fair use”, but this approach is more dramatic)


Instead, I went looking for another shield, and landed on the Roman scutum, which probably began being used by the Roman army in the fourth century BCE. But, while Roman armour, weaponry, and military tactics are very interesting, they’re not really what I wanted to talk about.


Back to the Canadian Shield, then, which is why I wanted to use the Canadian coat of arms in the first place. The Canadian Shield is a large area of exposed Precambrian (estimated to be about 4.28 billion years old) rock which surrounds Hudson Bay and covers an area of approximately 8 million km2. It covers a great deal of eastern Canada, Greenland, and the US, stretching as far west as Alberta and the Northwest Territories, and as far south as the US Midwest.


While it now consists mainly of rolling hills, worn by millions of years of erosion, it once had mountains higher than any others existing today, and it can be very interesting to drive on highways which were cut through the rock decades ago and which still show clear markings of where the dynamite was placed.


And that is the circuitous route by which I came to the other Canadian Shield.


Though I vaguely recall hearing about the service previously, I was reminded of it when I heard an episode of CyberSecurity Today, in which David Shipley interviews Jon Ferguson, who is VP at CIRA.


For background, a Top-Level-Domain (TLD) is the rightmost part of an internet address, and identifies the broadest subdivision on the internet. At its simplest, TLDs are broken into several groupings, which include generic top-level domains (such as .com, .org, and .edu) and country-code top-level domains (such as .ca, .uk, and .au).


Each TLD has what is called a domain registrar, and CIRA is the registrar for the .ca domain, along with providing other services related to domain-management and cybersecurity. This means that CIRA manages the registration and indexing for all internet sites under the .ca domain. Examples include https://www.canada.ca/, which is the official site of the government of Canada, Get Cyber Safe, which is a site dedicated to providing information regarding cybersecurity and how people can protect themselves online, and the Canadian Shield site itself (though that, technically, is a page under https://www.cira.ca).


So, whenever we attempt to connect to a site under the .ca domain, we are accessing CIRA-managed DNS servers (either directly, or indirectly, through values cached on other DNS servers). This is a very valuable service, and entirely under-appreciated by almost everyone who surfs the internet.


The first step in the DNS process is to identify your primary DNS resolver, which is the service that takes the address you enter and translates it into an IP address. Most people will use the default resolver provided by their service provider, while others use a third-party such as Cloudflare (1.1.1.1) or Google (8.8.8.8).


Most of these services are provided by for-profit companies, partly as a public service, but also because they can gather enormous amounts of data around browsing habits and user behaviour. Sometimes, there are well-defined privacy policies which reduce the privacy implications to a minimum, but there are also services which are provided by non-profit organizations.


Another consideration is around whether the DNS resolver simply handles “traditional” DNS resolution, or provides other services or features as well. There are pros and cons to each approach, and Canadian Shield provides three levels of service.


“Private” is an open service without filtering, but your traffic data is kept for the minimum time necessary, and is not used for marketing or resale. And the servers are based in Canada.


“Protected” provides additional security, through blocking or flagging a domain which contains malware or engages in phishing. This is in addition to any other tools you are using, and supports the idea of “defence in depth”.


“Family” adds a block to sexual content, though I couldn’t find how this is defined, and it does NOT include other forms of content which may be considered inappropriate for children, such as drugs or gambling, or self-harm.


There are also three ways to use the service. The first is as a “pure” DNS resolver, which means you need to log into your router to change the default DNS resolver address – this can be intimidating for non-technical people, but is a fairly straightforward process.


But this doesn’t help you if you are away from home, unless you want to make similar updates to all your mobile devices. There is a simpler way, though – the Canadian Shield app, for iOS and Android. In addition, there is a browser extension which is available for Chrome and Firefox.


The most important point, though, is that there are many excellent services out there, and some of them are extremely powerful and useful. You just have to look for them. Or listen to cybersecurity podcasts.


Or read blogs, like this one.


Cheers!

Comments


Want to learn more?

Thanks for subscribing!

What do you think?

Thanks for submitting!

© 2026 by RG

88x31.png

TIL Technology by RG is licensed under a Creative Commons Attribution 4.0 International License, except where otherwise specified. 

Please feel free to share, but provide attribution.

bottom of page