Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherBrowse by ChannelAbout the NetworkJoin the NetworkProductsSub-MenuProducts OverviewBlog ProBlog PlusBlog PremierMicrositeSyndication PortalsAbout UsContactSubscribeSupport
Book a Demo
Search
Close

New Security Measure: Login Geolocation

By Scott Fennell on October 5, 2021
Email this postTweet this postLike this postShare this post on LinkedIn
Wrigley-Editing

In the past few months, we’ve implemented various security measures such as rate limiting, browser inspection, captcha and CSAM monitoring.  Here’s another: Login Geolocation.

Currently, the LexBlog platform keeps track of your IP address when you sign in.  This is so we can detect if you’ve never logged in from that IP before.  If not, we send you a warning email.  It’s then up to you to review this email, review your IP address and confirm it’s a legitimate session.

While I like this solution for its simplicity, it has two drawbacks:

  1. For many non-technical bloggers, IP addresses are not a meaningful piece of information.  This warning means virtually nothing at all to them.
  2. Many users have an internet connection that uses dynamic IP addresses, so therefore they get these warnings every time they sign in.  They (understandably) ignore them.

A better pattern would be to check physical location, also known as “geolocation,” as opposed to IP address. It addresses the two flaws above:

  1. Non-technical users understand that a far-flung country is suspicious.
  2. Even the most well-traveled blogger is not going to move around the surface of the earth as fast as a DDOS attack.  Therefore they will not get a significant volume of false positives from their normal work/home/travel routine.
Though still in development, this solution will look something like this upon release.

It’s worth noting that geolocation is not exactly perfect.  It can be off by a few cities.  In most cases, it will report your city or a directly neighboring one.  If it misses, it will likely miss to the same city each time, and you are likely already familiar with what city that is, because most web platforms use the same geolocation software and provide the same hits and near-misses.

That small drawback is far preferable to the issues we are facing currently.  The false positive problem is so significant that many users filter these warning emails, or have even gone so far as to request that this security feature be disabled.  If you, dear reader, fall into that category, please consider reversing course.

Login geolocation will be a helpful security measure, but actually it’s just a stepping stone.  We plan to build on this work and eventually graduate to a flow where the user is blocked altogether when logging in from a new location, until he clicks an approval link in the warning email.  We plan to continue with that roadmap in early 2022.

Photo of Scott Fennell Scott Fennell

Scott is a WordPress theme and plugin developer with a penchant for connecting the dots between services like MailChimp, Cloudflare, and GoDaddy. He has been published in A List Apart and CSS-Tricks.

Read more about Scott FennellEmail
  • Posted in:
    LexBlog
  • Blog:
    99 Park Row
  • Organization:
    LexBlog
  • Article: View Original Source

LexBlog, Inc. logo
Facebook LinkedIn Twitter RSS
Real Lawyers
99 Park Row
  • About LexBlog
  • Careers
  • Press
  • Contact LexBlog
  • Privacy Policy
  • Editorial Policy
  • Disclaimer
  • Terms of Service
  • RSS Terms of Service
  • Products
  • Blog Pro
  • Blog Plus
  • Blog Premier
  • Microsite
  • Syndication Portals
  • LexBlog Community
  • Resource Center
  • 1-800-913-0988
  • Submit a Request
  • Support Center
  • System Status
  • Resource Center
  • Blogging 101

New to the Network

  • Beyond the First 100 Days
  • In the Legal Interest
  • Cooking with SALT
  • The Fiduciary Litigator
  • CCN Mexico Report™
Copyright © 2025, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo