Why Apple shows a strange location for a two-factor login confirmation

icloud 2fa location
IDG

Erich Riehl uses Apple’s two-factor authentication (2FA) system with his iCloud account. This is the system that Apple released in September 2015, and which replaces the older two-step system entirely in iOS 11 and macOS 10.13 High Sierra. (If you’re using two-step and upgrade to either of those, Apple converts you to 2FA.)

The first step in Apple’s 2FA is a location alert that appears on every computer and iOS you own logged into the same Apple ID account. The notion is that you should validate that the location is correct before you proceed to get the code. Clicking Don’t Allow terminates the login attempt.

For Erich, however, he’s seeing a login attempt from Monroe, Louisiana, which he found confusing. He gets this alert when he is trying to log in at iCloud.com, and wondered if it were legitimate.

Because Apple doesn’t explain when you log in that it’s going to alert you on all your connected devices, this can seem counter-intuitive when you’re using a browser—because the device from which you’re logging in tells you there’s a login attempt.

The location can also be imprecise. My wife routinely is told she’s logging in from about 30 miles south, although on the same home network, it’s more accurate for me. If we both had this issue, I’d expect that the IP address of our network was misplaced in whatever geo-identification system Apple relied on to match IPs with a rough place on the globe. (I checked with Erich, and his ISP is based in Louisiana, and it only happens when he tries to log in.)

If you’re using a VPN (virtual private network), you may be told that you’re logging in from far away as well! Keep that in mind if you’re worried about someone intercepting your connection—the far end of your session, where Apple “sees” you connecting to the Internet, is almost always going to be one of the data centers at which the VPN service has its servers located.

I wrote earlier about whether it’s a good idea to allow you to confirm your identity from the same machine you’re trying to log in from.

Ask Mac 911

We’ve compiled a list of the questions we get asked most frequently along with answers and links to columns: read our super FAQ to see if your question is covered. If not, we’re always looking for new problems to solve! Email yours to mac911@macworld.com including screen captures as appropriate. Mac 911 can’t reply to—nor publish an answer to—every question, and we don’t provide direct troubleshooting advice.

  
Shop Tech Products at Amazon