/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google says data from its new “Password Checkup” Chrome extension shows that 1.5% of all website logins use credentials that have been compromised

Karl Bode / VICE :

VICE Karl Bode

Context & Ripple Effects

Six months after Google shipped the Password Checkup Chrome extension, which alerts users when their credentials appear in known breaches, the company is publishing what the tool observed in the wild: 1.5% of all website logins it checked relied on compromised credentials. The finding quantifies a problem Google had already sized indirectly — its earlier study with UC Berkeley counted 3.3 billion credentials stolen via third-party breaches in a single year, on top of phishing and keylogger theft.

The arc here is Google using Chrome as a measurement instrument first and a remediation layer second. It follows the same pattern as its 2015 extension that warned users typing their Google password into the wrong site: put the check where the password is entered, then let the telemetry justify broader intervention.

First-order effects

  • Users running the extension who are part of that 1.5% get prompted to reset affected passwords immediately, turning an invisible breach exposure into an actionable queue.
  • Websites whose login flows surface in Checkup data gain evidence of how much of their traffic authenticates with already-breached pairs — pressure that lands on their account-security practices without any regulator involved.

Second-order effects

  • Browser rivals and password managers face rising user expectations for built-in breach alerting, since Chrome has made a passive password field look negligent by comparison.
  • Credential-stuffing attacks lose yield at the margin: every reused-and-flagged password that gets reset shrinks the pool of valid pairs attackers recycle from third-party breaches.

Third-order effects

  • If the pattern holds, credential hygiene migrates from user responsibility to platform enforcement — a trajectory Google itself extended by later deploying Duplex to help Chrome users fix compromised passwords automatically, moving from alerting to agent-driven remediation.
  • Browsers consolidating this role make them de facto authentication auditors for the web, concentrating both security benefit and sensitive breach-matching data in a handful of browser vendors.

The trend: Browsers are evolving from neutral rendering surfaces into the web's default credential-enforcement layer, progressing from warnings to measurement to automated password repair.

Discussion

  • @karlbode Karl Bode on x
    Some interesting data here. I was actually kind of surprised the number of compromised login credentials in regular use wasn't higher. Oh, and stop using the same damn password everywhere. https://twitter.com/...
  • @brooklyndan Dan Rosenbaum on x
    Given the number and extent of reported exploits, I'm surprised the number is that low. https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Earlier this year, Google released a Chrome extension for warning users when they use weak passwords. Google has now published results of what it found out from running the extension https://security.googleblog.com/ ... https://twitter.com/...
  • @deciphersec Decipher on x
    Six months ago, @google released a Password Checkup extension for Chrome that flags known unsafe passwords. The stats show that users opt to reset 26% of the unsafe passwords flagged by the Password Checkup extension. https://security.googleblog.com/ ...
  • @ericgeller Eric Geller on x
    Google says users reset 26% of the passwords that its Password Checkup tool warns are unsafe, and 60% of resulting passwords are “secure against guessing attacks.” In total, 1.5% of scanned sign-ins trigger a password compromise warning. https://security.googleblog.com/ ...