Google Is Starting To Automatically Enroll Users To Use Two-Factor Authentication

Trojan Source, invisible source code vulnerability

Traditionally, the only way to differentiate the legitimate owner of an account and an unauthorized individual, is the former's knowledge of the account's login credential.

Through username and password combination, the owner of the account can log in from any devices, from anywhere. Without the credentials, the system will consider that person as an unauthorized individual. While this is a good thing, anyone who managed to get their hands on the login credential can log in to the account easily.

There is no precaution.

What this means, login credentials is the only thing anyone needs to log in into an account, whether or not they are the legitimate owner of the account.

This is why two-factor authentication (2FA) is needed.

2FA is a form of a multi-factor authentication method, which will grant some access only after successfully presenting two pieces of evidence. This ensures that the person trying to log in is the person who they say they are.

[block:block=87]

Earlier this 2021, Google announced that it was planning to forcefully transition as many of its users as possible to 2FA. The company elaborated further in October, saying it was planning to automatically enroll 150 million Google accounts in 2FA by the end of 2021.

As the year is ending, Google is finally forcing people into using 2FA.

On its support page, the company details this automatic enrollment process.

Google said that accounts that have been flagged for 2FA will get an email or notification about seven days before the requirement is enforced. Organizations with paid Google Workspace accounts won't be forced into 2FA, because they have the flexibility, and it's up to their administrators to decide.

For Google users who use Google Accounts for YouTube, the company has made 2FA a requirement for all "partner"-level creators starting November 1.

Google's 2FA is called "two-step verification" or "2SV."

It requires users to use something in addition to their login credentials to log in to their Google Accounts.

Usually, Google considers this "something" a code or a verification prompt sent to users phone. Besides that, users can also use a physical security key, like a USB stick.

Google email 2FA
The email Google sent to users to inform them about the mandatory use of 2FA.

If users don't provide a method of verification like Google Authenticator, or even SMS codes, Google will default to the standard 2SV method, which involves sending a prompt to appear on one of the devices linked to the users' Google account.

Should users lose their phone, Google will use a recovery email to help with gaining access to the account.

It should be noted that Google cannot automatically enroll everyone into 2FA.

Google said that it is enlisting 150 million user accounts. Google has way more than that.

According to Google, it is only "auto-enrolling Google accounts that have the proper backup mechanisms in place to make a seamless transition to 2SV."

Those backup requirements include a recovery phone number that can receive SMS codes or a recovery email.

In other words, if a Google user didn't provide his/her phone number or any other method for the second authentication method, Google cannot force that person to use 2FA.

Forcing that kind of person to use 2FA will risk that person losing his/her account.

Published