/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Google software engineer Grzegorz Milka says in conference presentation that under 10% of active Gmail users have two-factor authentication enabled

Iain Thomson / The Register :

The Register Iain Thomson

Context & Ripple Effects

The disclosure lands between two Google moves on the same problem. In late 2017, Bloomberg reported Google was preparing an Advanced Protection Program that swaps passwords-plus-codes for physical security keys and blocks third-party apps entirely, aimed first at high-profile targets. And Gmail itself is enormous — 900 million active users as of 2015 — so even single-digit adoption percentages represent hundreds of millions of unprotected accounts.

Milka's number is effectively Google admitting its largest consumer surface relies almost entirely on passwords alone, while the company's own internal data points the other way: by mid-2018 Google would report zero successful phishing of its 85,000+ employees since mandating physical Security Keys in early 2017.

First-order effects

  • Google faces an adoption-gap problem it can no longer frame as theoretical: the engineer behind the number works there, and the figure sits awkwardly beside the Advanced Protection Program rollout aimed at exactly the users most likely to be targeted.
  • Gmail's account-recovery and login flows become the de facto security perimeter for hundreds of millions of accounts protected only by passwords, since under one in ten users has enabled any second factor.

Second-order effects

  • Hardware-key vendors and authenticator-app makers gain a market argument straight from Google's own mouth — the same evidence base Google used internally to justify requiring keys for all employees.
  • Rivals get pulled into disclosure: Twitter's later transparency report showing just 2.3% of active accounts with 2FA suggests adoption rates became a comparable public metric across platforms once Google's number was on record.

Third-order effects

  • If the pattern holds, platforms stop treating 2FA as an opt-in user choice and move toward enforced or default-on phishing-resistant methods — the trajectory from Milka's statistic through employee-wide key mandates to programs like Advanced Protection.
  • Password-only authentication becomes a reputational liability rather than a neutral default, pushing regulators and large providers alike toward credential-hygiene disclosures such as Google's later finding that 1.5% of web logins use compromised credentials.

The trend: Consumer account security is shifting from optional user-enabled second factors toward platform-mandated, phishing-resistant authentication, with adoption rates becoming a public accountability metric.