A Google engineer has revealed that over 90% of active Gmail are not using two-factor authentication (2FA), The Register reports. Given the low uptake, The Register asked Google software engineer Grzegorz Milka why 2FA isn’t mandatory for all Gmail accounts. Milka attributes this to its usefulness, adding that “it’s about how many people would choose a different platform if we forced them to use additional security.” The statistic was presented during a presentation at the Usenix Enigma 2018 security conference in California.
Two-factor authentication is a security tool that requires a user password as well as an additional form of authorization. It adds an extra layer of security if your password is stolen or you use the same password for multiple sites. Google offers 2FA via a code sent to your phone via text message, voice call, mobile app, or via a security key inserted into your computer's USB port.
The Register reports that more than 10 percent of users who try to enable Google’s 2FA are having trouble entering their password sent via SMS. While 2FA provides substantial protection and most websites offer 2FA, it has limitations, and methods like SMS authentication are easier to hack than a hardware token. Google has previously said it plans to upgrade its two-factor authentication tool after a hack of popular profiles, but this new service will be aimed at those who need extra security, like politicians and executives.
