# Suspicious login emails coming from all over

**URL:** https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706
**Category:** Feature
**Created:** [April 8, 2019, 12:52am UTC](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706 "2019-04-08T00:52:59Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![southpaw](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/southpaw/32/79352_2.png) [@southpaw](https://meta.discourse.org/u/southpaw)
#### Post date: [April 8, 2019, 12:52am UTC](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706/1 "2019-04-08T00:52:59Z")

</div>

Please help me understand this feature.

> [@Discourse 2.2.0.beta4 Release Notes](https://meta.discourse.org/t/discourse-2-2-0-beta4-release-notes/101272/1):
>
> ### Improved Account Security: Suspicious login emails and report
> 
> Admins that sign in from a new country will receive an email detailing the login, including IP, estimated location, browser, and device. We’re continuing to refine this feature, and plan to alert based on the geographic distance between the locations, not simply the country. Admins can also view the new suspicious logins report for a summary of new location logins.

Question 1: Am I understanding correctly that this E-mail is triggered only when an Admin’s account is signed into from a distant IP? These E-mails are **not** being sent to non-Admin users, right?

Question 2: Is anyone else getting these from bizarre locations? I know the logins triggering the E-mails are me, but recently I’ve been located in distant locations I’ve never visited, especially not at the date and time given.

If I’ve understood Q1 correctly, then Q2 is not that big a deal. I’m a little more concerned only if _any_ user might get such an E-mail, as we do have some who would panic.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [April 8, 2019, 1:39am UTC](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706/2 "2019-04-08T01:39:15Z")

</div>

> [@southpaw](#):
>
> recently I’ve been located in distant locations I’ve never visited, especially not at the date and time given.

If you have gotten these notifications and they are not from locations, and especially times, that you do not recognize, then you should, in fact, be very worried.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [April 8, 2019, 1:50am UTC](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706/3 "2019-04-08T01:50:35Z")

</div>

> [@southpaw](#):
>
> this E-mail is triggered only when an Admin’s account is signed into from a distant IP? These E-mails are **not** being sent to non-Admin users, right?

Correct this is admin-only, so we can make sure it’s working properly, also these are _by far_ the most risky accounts to have compromised.

> [@southpaw](#):
>
> recently I’ve been located in distant locations I’ve never visited, especially not at the date and time given.

The question to ask, is why your IP address is geolocating to such a weird and/or incorrect area. What IP address was it? Did you at least recognize the operating system and browser reported, are those operating systems and browsers you regularly use?

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [April 8, 2019, 2:03am UTC](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706/4 "2019-04-08T02:03:02Z")

</div>

Do you use any kind of VPN or DNS privacy service?

---

<div class="post-metadata">

### Author: ![southpaw](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/southpaw/32/79352_2.png) [@southpaw](https://meta.discourse.org/u/southpaw)
#### Post date: [April 8, 2019, 3:20am UTC](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706/5 "2019-04-08T03:20:03Z")

</div>

> [@codinghorror](#):
>
> The question to ask, is why your IP address is geolocating to such a weird and/or incorrect area. What IP address was it? Did you at least recognize the operating system and browser reported, are those operating systems and browsers you regularly use?

I _know_ these logins are me. Yes, I’ve asked myself those questions, and confirmed I logged in on the browser and device indicated at the time indicated. The location is what’s strange.

 ![image](https://global.discourse-cdn.com/meta/original/3X/d/6/d6210ce36457b61c751d47f9fff8083b1efb3054.png)  
I’ve never been to Seattle, don’t think I’ve been to Newark, but definitely haven’t been there today.

> [@Stephen](#):
>
> Do you use any kind of VPN or DNS privacy service?

No.

The Windows login in Seattle currently is 174.24.132.70, and I’m in North Carolina.

The Android login in New Jersey just 6 hours ago was 66.87.30.249, one mile from my current location.

So this is why I was wondering if it’s happening to other people. Surely I can’t be the only person whose IP addresses resolve to the ISPs’ regional office or corporate HQ?

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [April 8, 2019, 3:52am UTC](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706/6 "2019-04-08T03:52:15Z")

</div>

> [@southpaw](#):
>
> The Windows login in Seattle currently is 174.24.132.70, and I’m in North Carolina.

This is a disagreement amongst iplocation DBs as you can see cc @nbianca

 ![image](https://global.discourse-cdn.com/meta/original/3X/c/4/c46b4e487c8c0a64a63c9b8ed4092ccd883f3698.png)

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [April 8, 2019, 4:36am UTC](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706/7 "2019-04-08T04:36:49Z")

</div>

Yep, there are no real geographical constraints for subnets. They’re allocated to providers and in a lot of cases the networks will only update their records once or twice a year.

On top of that mess, all of the IP lookup databases who compile that data are effectively best-effort.

There was a time that certain providers gave each customer a static address with lookup data that was _too_ accurate. Of the two approaches I guess the former is preferable?

---

<div class="post-metadata">

### Author: ![gym32](https://avatars.discourse-cdn.com/v4/letter/g/e47c2d/32.png) [@gym32](https://meta.discourse.org/u/gym32)
#### Post date: [April 8, 2019, 5:29am UTC](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706/8 "2019-04-08T05:29:51Z")

</div>

IIt hapened to me too, Weird places, mostly Africa. I just ignored it, didn’t know what to do. Now I don’t get these login emails anymore. But would still like to understand what was the problem.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [April 8, 2019, 8:33am UTC](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706/9 "2019-04-08T08:33:29Z")

</div>

The issue here is that we are in 2-3 month cadence for updating maxmind, and this data is going stale real fast, this is probably the second or third time this happened.

This issue does not exist in today’s maxmind db.

We do not want to be downloading 60mb from 200 or so containers every day, I will not be surprised if maxmind just burn our IP if we do this.

What we can do though is have some sort of middle ground here that forces an update in a slightly more aggressive cadence without risking getting our infrastructure IPs burnt or get a terrible reputation with maxmind.

My proposal would be:

1. Add site setting for `refresh_maxmind_db_during_precompile_days` default to say 2 days.

2. During `assets:precompile` if we did not download maxmind in `refresh_maxmind_db_during_precompile_days` then spin a thread to download maxmind and join on it prior to finishing assets:precompile

End result is that in our infrastructure maxmind will only be up to 2 days old, but we will need to deploy sites to update it.

Also for self hosters, rebuilds will always ensure maxmind is pretty fresh.

@codinghorror thoughts?

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [April 8, 2019, 8:42am UTC](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706/10 "2019-04-08T08:42:13Z")

</div>

Some incremental improvement is probably fine and should suffice.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [April 8, 2019, 8:43am UTC](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706/11 "2019-04-08T08:43:22Z")

</div>

OK, @nbianca can you make [this](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706/9) happen?

---

<div class="post-metadata">

### Author: ![nbianca](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nbianca/32/157984_2.png) [@nbianca](https://meta.discourse.org/u/nbianca)
#### Post date: [May 8, 2019, 11:28am UTC](https://meta.discourse.org/t/suspicious-login-emails-coming-from-all-over/113706/13 "2019-05-08T11:28:06Z")

</div>

This was implemented in:

[https://github.com/discourse/discourse/pull/7340](https://github.com/discourse/discourse/pull/7340)
