Interesting that such a large company trusts what could become a future direct competitor (Google) with their application data.
Interesting also that the app logins were not limited to requests coming from the company's IP range.
They should all be issued with those one-time code keyfobs. If you don't have physical possession of the device that displays a unique number (which changes frequently) that you have to enter into the login form, you won't be able to get in.
