Google software engineer Grzegorz Milka says in conference presentation that under 10% of active Gmail users have two-factor authentication enabled
Iain Thomson / The Register :
Context & Ripple Effects
The disclosure lands between two Google moves on the same problem. In late 2017, Bloomberg reported Google was preparing an Advanced Protection Program that swaps passwords-plus-codes for physical security keys and blocks third-party apps entirely, aimed first at high-profile targets. And Gmail itself is enormous — 900 million active users as of 2015 — so even single-digit adoption percentages represent hundreds of millions of unprotected accounts.
Milka's number is effectively Google admitting its largest consumer surface relies almost entirely on passwords alone, while the company's own internal data points the other way: by mid-2018 Google would report zero successful phishing of its 85,000+ employees since mandating physical Security Keys in early 2017.
First-order effects
- Google faces an adoption-gap problem it can no longer frame as theoretical: the engineer behind the number works there, and the figure sits awkwardly beside the Advanced Protection Program rollout aimed at exactly the users most likely to be targeted.
- Gmail's account-recovery and login flows become the de facto security perimeter for hundreds of millions of accounts protected only by passwords, since under one in ten users has enabled any second factor.
Second-order effects
- Hardware-key vendors and authenticator-app makers gain a market argument straight from Google's own mouth — the same evidence base Google used internally to justify requiring keys for all employees.
- Rivals get pulled into disclosure: Twitter's later transparency report showing just 2.3% of active accounts with 2FA suggests adoption rates became a comparable public metric across platforms once Google's number was on record.
Third-order effects
- If the pattern holds, platforms stop treating 2FA as an opt-in user choice and move toward enforced or default-on phishing-resistant methods — the trajectory from Milka's statistic through employee-wide key mandates to programs like Advanced Protection.
- Password-only authentication becomes a reputational liability rather than a neutral default, pushing regulators and large providers alike toward credential-hygiene disclosures such as Google's later finding that 1.5% of web logins use compromised credentials.
The trend: Consumer account security is shifting from optional user-enabled second factors toward platform-mandated, phishing-resistant authentication, with adoption rates becoming a public accountability metric.