Google begins testing login system that uses phone notifications for authentication instead of passwords
Context & Ripple Effects
This late-2015 test is the seed of a decade-long arc in Google's account security. Within months it fed into Project Abacus, Google's plan to bring password-free logins to Android apps, and by 2021 the phone prompt had become the primary factor: Google began verifying 2FA-enabled users with a tap on their phones and said it would automatically enroll all users in 2FA.
From there the pattern matured into device-bound credentials — Android security-key tech extended to iPhones and iPads in 2019, then passkey support rolling out on Android and Chrome — culminating in Google making passkey creation the default prompt while explicitly keeping passwords alive during what it calls the pivot.
First-order effects
- Test participants gain sign-in that swaps typed passwords for a notification tapped on their own phone, cutting credential-entry friction for Google accounts immediately.
- Google shifts the trust anchor of its login flow from something users remember to a device it controls the software stack for.
Second-order effects
- Rival identity providers and app makers face pressure to match phone-prompt authentication or lose users who now expect no-password sign-in.
- Phishing economics weaken: stolen passwords lose resale value when the verifying factor is a possession prompt tied to the account holder's handset.
Third-order effects
- If the pattern holds, authentication consolidates around device-anchored credentials — passkeys as default, passwords demoted to fallback — making platform vendors like Google and Apple the de facto gatekeepers of web sign-in.
The trend: Authentication is migrating from knowledge-based secrets to device-bound prompts and passkeys, with Google's rollout cadence setting the pace for the industry.