/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google launches Password Checkup, a Chrome extension that alerts users to breaches and prompts resets, and Cross Account Protection for apps with Google Sign in

Editor's note: Today is Safer Internet Day, but we'll be talking about it all week with a collection of posts from teams from across Google.

The Keyword

Context & Ripple Effects

Launched on Safer Internet Day, Password Checkup starts life as an opt-in Chrome extension that flags reused credentials found in breaches and pushes users to reset them, while Cross Account Protection extends breach signals to third-party apps built on Google Sign in. The design bet is that users will act on alerts if the tool comes to them.

The follow-on coverage validates that bet and shows the feature's migration path: within months Google reported that 1.5% of all website logins use compromised credentials based on the extension's own telemetry, then folded the check into the Google account dashboard and Android rather than leaving it as an install. By late 2023 the successor Safety Check feature runs automatically in the background on desktop, and by 2024 Google is pushing passkeys to 400M+ accounts — the same problem being solved one layer deeper.

First-order effects

  • Users who install the extension get per-site breach alerts and prompted password resets immediately; developers whose apps use Google Sign in inherit Cross Account Protection without building their own breach-detection flow.

Second-order effects

  • The extension doubles as a measurement instrument — its telemetry produced Google's 1.5% compromised-login figure, which gave Google the evidence base to justify shipping the check natively into the dashboard and Android instead of relying on installs.

Third-order effects

  • If the pattern holds, breach checking moves from user-initiated tools to always-on platform defaults running in the background, and ultimately to removing the reusable-password attack surface altogether via passkeys — shifting responsibility for credential hygiene from individuals to platform vendors.

The trend: Account-security tooling is migrating from opt-in browser extensions to automated platform defaults, on a path that ends in passwordless authentication.