5 Sources
[1]
Google Turns a Selfie Video Into Your Account's Spare Key
The next time you're locked out of your Google account, you can use your face as part of the account recovery process. Google has a new way for users to sign in to their accounts: a selfie video. If you've ever lost your device and gotten locked out of your Google account, you know it can feel like a desperate, Kafkaesque process to recover access and get back in -- especially for people who run their digital lives, from email messages to calendar appointments, on Google software. This new sign-in option is an additional way to unlock your Google account, like a spare key hidden in the bushes. "We always recommend that you set up more than one option," says Claire Forszt, a product manager at Google who focuses on identity and engagement. "Selfie is just the newest option in that list available for users. It's designed to help specifically in these vulnerable scenarios around not having access to the device where your passkey might be." Additional sign-in options include using recovery contacts and backup codes. I was able to set up my selfie video in less than five minutes, and the process was straightforward. Open your Google account and choose the Security & sign-in tab. Then scroll down to the How you sign in to Google section. If the selfie sign-in is currently available for your account, you'll see it as a new option at the bottom. Google is in the process of rolling this out globally to most accounts. I recorded my selfie video on an iPhone, and Google accepted it on my first attempt. It recommends keeping your face visible and eyes pointed at the camera in standard lighting. It also recommends that you're the only face seen in the recording; even a family portrait hanging behind you is a no-go. As prompted by Google, I lifted my chin slowly and stared at the ceiling for a second before bringing my head back to the center. Then it asked me to look directly at the camera for one last capture. Finally, it verified the selfie video and stored it under Security Settings. Google says it's safeguarding users against deepfake attacks with tools like liveness detection. "There might be instances where passing a selfie video alone may not always be sufficient to get you back into your account if we suspect something risky going on," Forszt says. "We evaluate the overall risk based on many factors." If you decide you want to enable this option, it's essential to set it up before you need it. "You can't add a selfie video while you're locked out of your account or in the account recovery process," reads Google's support page for the feature. Google gives users an option during the selfie video creation process to decide whether to opt in to that recording being used as training data. "Allow Google to use this and any previously provided selfie videos and related data to develop and improve our facial recognition, age estimation, and other verification methods that use your physical features or movement, across Google services," reads the description next to an optional checkbox. Users can go into their privacy settings later to adjust this setting, labeled Improve Google services, if they change their mind. This selfie video process may feel familiar to Google power users who have experimented with other recently released features. Google launched an AI avatar tool earlier this year in its Gemini app where users can create a digital clone of their likeness and insert it into AI videos. I tried this AI avatar feature when it first dropped and was stunned by how photorealistic and natural the generations of me were. While Google's approach to these selfie features gives users the choice to opt in, other tech companies have taken a different path with recent tools that involve your likeness and generative AI. Earlier in July, Meta faced harsh blowback from Instagram users when it automatically opted adults into their images being available for AI remixes by anyone, unless they dug around in the settings to opt out. The backlash was so severe that Meta fully deleted the feature three days after its launch. While some readers will, understandably, still be uncomfortable with this new sign-in method capturing and storing their likeness, I'm glad the feature is opt-in and will likely leave it enabled for my personal account. As someone who gets locked out of their accounts more than they'd like to admit, swiping my face card the next time I'm desperately attempting to claw my way back in will feel like a much-needed relief.
[2]
Google will let you upload a video selfie to recover your account - but should you?
Google's new account recovery option prompts users to upload a selfie to prove their identity. Here's what to know. Follow ZDNET: Add us as a preferred source on Google. ZDNET's key takeaways * Google's selfie video sign-on helps users recover their accounts. * You should know how your biometric data is stored and used. * Google asserts that uploaded biometric data is never shared. Google's introducing a new way to recover your account, and all you need is your face. Users can upload a selfie video to regain access to their accounts if they've been locked out or are away from their usual device, the company said Thursday. Also: Ernst & Young breach exposes client tax data - find out if you're at risk and what to do next Uploading a selfie video to remedy an extremely stressful situation sounds simple enough, and in a blog post, Google promised that users' selfies are "encrypted at rest, meaning it's securely stored even when it's not being used." Still, as we offer more of our permanent biometric data to tech companies, I asked security experts what users should know and consider before providing face scans to them. Avoiding deepfakes Among experts, the consensus is that uploading a live video of your face is generally more valuable for identity verification than still photos, because motion, depth, lighting changes, and microexpressions can confirm humanity. However, some experts are concerned that video verification systems could be tricked by deepfakes. Hackers can use generative AI to alter photos of faces and official documents, making them appear realistic. Deepfakes are a genuine concern, and the technologies used to create them are more advanced than many people realize. Ricardo Amper, founder and CEO of Incode Technologies, an identity verification and fraud prevention company, said that while a video is more valuable than a photo for verification, motion alone is not proof of life. Also: An AI agent breached Hugging Face before an AI defender caught it: What users should do next Amper said that hackers can create AI-generated faces capable of blinking, turning their heads, and responding to prompts with motion, and that human ability to distinguish a real person from a deepfake is declining. "The more sophisticated attacks don't even try to fool the camera," he said. "They bypass it entirely, injecting synthetic video directly into the data stream through virtual cameras and tampered or emulated devices." Chris Boehm, field CTO at Zero Networks, a cybersecurity provider, recalled the massive deepfake scam that swindled British design and architecture firm Arup out of $25 million in 2024. A company finance worker was duped into joining a conference call with deepfake renders of his colleagues, and was convinced to complete several wire transfers. Though the worker was suspicious of the emails leading up to the meeting, his doubt was assuaged by the realistic deepfakes. Also: I enabled Android's new security feature that detects fake cell towers - here's why Your Google account may not be worth this much money, but it's possible for bad actors to use advanced technologies to access your information and that of thousands of others. "Deepfakes have moved past the novelty stage," Boehm said. "They're now a fraud tool with a track record." Multiple methods are key Since deepfakes pose such a serious threat to video verification methods, experts agree that multiple verification tools are required to mitigate their impact. Amper said that these sophisticated defense tools use more than an image's pixels to determine realness by reading a device's finer details. Google didn't detail exactly how or which technologies it uses to differentiate between real people seeking to recover their accounts and bad actors using deepfakes, as doing so would be a security concern. However, Google's blog post said it uses its standard security practices, along with deepfake detection, to flag suspicious activity, including device location, time of attempted login, browser settings, and IP address. "The most sophisticated models today can determine from a single image whether a face is real, because they don't judge the pixels alone -- they read the device itself: accelerometer and sensor data, camera integrity, and dozens of other signals that confirm this is a genuine selfie camera capture and not something injected into the stream," Amper said. Also: I tested a 4TB quantum-resistant USB drive - but you don't have to spend $3000 for this much security Chris Bevil, director of global cyber resilience and AI, at Commvault, a data protection company, has similar sentiments. Bevil said that video verification is a great starting point, but there are other methods of confirmation beyond movement to verify authenticity, since hackers can inject synthetic video and fool simple defense systems. "A video provides liveness and behavioral signals that a static photo cannot," he said. "The key is layering it with device recognition, location, behavioral analytics, and additional verification when something does not align." Google's blog post says the company uses multiple security methods to combat deepfakes and impersonation attempts, such as comparing your uploaded selfie video with another photo and requiring you to perform real-time movements to verify the video is genuine. Also: Don't let an AI chatbot pick your password, ever According to Tony Anscombe, chief security evangelist at ESET, a cybersecurity provider, it's imperative that companies use multiple authentication methods to deter hackers, whose tactics are evolving rapidly. "The issue is whether one single method of authentication is being used to verify identity as opposed to multiple combined methods that would significantly reduce the overall risk of fraud," he said. "Using multiple methods and even randomizing the methods used would disadvantage the attacker significantly." Privacy is paramount The same experts warned that people should not be liberal with handing out their biometric data for the sake of digital convenience; unlike a password, your face, iris, or fingerprint can't be changed if they're involved in a data breach. To stay safe, users should know how their biometric data is stored, used, protected, and deleted. Google's privacy policy states that if users choose to share biometric data, Google may use it for product development studies. Also: Microsoft patches record 570 Windows security bugs with two exploited zero days - update now Google's selfie video blog post states that users' selfie videos are recorded and stored securely, can be deleted at any time, and that users can opt out of sharing them with Google for "additional purposes." Google confirmed to ZDNET that users' selfie videos are stored securely on the server, and that if users choose to share their selfie videos for Google's "additional purposes," one of those purposes may be improving the company's verification methods. The experts I sought out agreed that on-device biometrics, such as fingerprint and face ID, are a more secure option for everyday use, since the data stays on the device rather than being transmitted for remote verification. Also: Is that QR code a trap? How to spot quishing scams before it's too late However, Google's selfie video option seems to be a last-ditch attempt, made especially for people who are locked out of their account and are nowhere near their usual devices. If you're particularly wary of sharing more of your biometric data with Google in this manner, Google's recovery contacts option might be a better fit. Google allows users to add up to 10 people as recovery contacts, who should be people you trust. Adding these contacts can help you recover your Google account if you're locked out. Once you call on a recovery contact, you'll receive a unique code, and your contact will receive a prompt that you're requesting their help. You'll need to contact them within 15 minutes, or the code expires. Once your contact enters your code, you'll have access to your account.
[3]
If you get knocked on the head and get all your devices stolen and have amnesia, Google will let you back in with a selfie
Tired of worrying about how you might recover all the precious data stored in your Google account if you somehow lose your devices and forget your email address and phone number? Just give Google a video of your face and AI will recognize you to restore access. Selfie sign-ins are now available for Google accounts, the Chocolate Factory announced on Thursday. This option is restricted to regaining access after email or phone recovery options fail. Going through the process of adding a verification selfie is rather simple: Just follow the steps outlined on Google's help page for selfie video management to enroll. You need a device with a camera and the ability to move your head from side to side in order to show off your profile, as well as your full-frontal face card. That side-to-side movement is designed to prevent the use of live deepfake videos, as real-time face replacement tends to struggle with profiles. According to Google, if you can't use any other account recovery method, the company's system can prompt you to take another selfie video for comparison to the one taken earlier, verifying it's you and letting you back into your account. Why this, why now? This feature announcement from Google raised a number of questions among The Register's news team. Why now, for starters? Deepfake videos are constantly improving, and it's likely only a matter of time until a side view can be handled with ease. A Google rep told The Register that it sees a trend toward passkeys and other forms of device-based authentication, which means a lost device often means a lost account. "Users can choose whatever method they prefer, we expect most will prefer the ease of use of passkeys for signing in regularly, and use selfie for times like when they lose their phone or the device with their passkey," Google said in response to our questions. So it is not like Apple's Face ID or face unlock on Android, Google confirmed - "they serve different purposes." That, and it might not even be sufficient to prove you're you. "Passing a selfie video alone may not always be sufficient to get back into your account," Google explained in the email. "We evaluate the overall risk based on many factors and may require additional sign-in methods to help make sure it's actually you signing into your account." That's because Apple devices with Face ID, and some higher-end Android devices, are equipped with infrared cameras that capture depth maps to match points on a user's face to a stored 3D map of their appearance. Those are harder to fool. Google's selfie sign-in system, on the other hand, is essentially relying on plain video, AI, and the hope that deepfakes haven't become good enough to get around those turn-to-the-side distortions. Unfortunately, facial recognition AI is reliably unreliable. Heck, even Google's had plenty of run-ins with it over the years, and good facial recognition algorithms are a hot commodity nowadays. Then there's the fact that you're giving Google a live recording of your face, and that could be quite valuable to the company in other contexts. As Google noted in its announcement, those facial scans are encrypted at rest, are only stored with user consent, and are "used only for helping you sign in, unless you opt to share it for additional purposes." "You have the option to allow Google to use your video and related data to help ongoing efforts to develop and improve facial recognition, age estimation, and other verification methods," the company notes on the selfie help page. The option, labeled "Improve Google Services" on the page where users can record a selfie for account recovery purposes, is unselected by default, but we could imagine Google has a vested interest in getting you to click that. ®
[4]
Google has a new way to sign in to your account -- and it uses your face
Google just gave you a new account login option to help escape the maze of password resets and recovery contacts. The company has introduced a selfie video sign-in feature that can get you in even when you're locked out or using a different device. As with many face unlock systems, you register for a selfie sign-in by looking at the camera and moving your head around to capture it from different angles. Should you have trouble signing in later, you only have to record another selfie clip using "simple movements" to prove you're real. Google claims to preserve privacy. The video is encrypted when you're not using it, and it's only used for sign-ins unless you voluntarily share it for "additional purposes." You can delete the clip at any time. The system is designed to prevent AI-generated impersonations, and Google will use its regular security measures to watch out for suspicious login attempts. The selfie feature is available now, although you'll need to be eligible. Workspace accounts, children, and people enrolled in the Advanced Protection Program don't qualify. Some users with standard personal accounts are also ineligble, but we've asked Google for details and will let you know if there are more requirements. Why should I use a selfie video to sign in to my Google account? It could save you when all other options fail Google already has multiple ways to sign in to or recover an account beyond passwords, including passkeys, verification codes, alternate email addresses, and specially assigned contacts. You might still rely on those first, especially if you have access to familiar computers and phones -- they can sometimes be more convenient. However, a selfie video can help if you've exhausted your other options -- when you can't sign in to your backup email address, for example. It might also prove vital if you borrow someone else's computer or set up a fresh device. In some cases, it might simply be more convenient to record a video. There is a concern that AI might become advanced enough to fool the challenge system. For now, though, you shouldn't have to worry that hackers will use deepfakes to breach your account and steal sensitive data. While it's possible to create realistic AI videos, the models aren't sophisticated enough to produce plausible footage on demand.
[5]
Google Lets Users Sign In With Video Selfies | PYMNTS.com
"Selfie video is a new way to get into your account, giving you more options if you're ever locked out or don't have access to your usual phone or computer," the tech giant wrote in a Thursday (July 23) blog post. To set up a video, users look into their devices camera and make a few "short, guided head movements" to capture multiple angles, the blog post said. If users have trouble logging in later on, they can take another selfie to access their account. The new features compares the new video to the original one to confirm the user's identity. The company said the new feature was designed with privacy in mind. When users sign in with their selfie, Google employs multiple security levels to prevent impersonation attempts with deepfake photos and videos. In addition to its standard security measures against suspicious sign-ins, Google says it matches users' videos against their saved selfie and requires them to perform "simple movements" to verify the video is live. "Your selfie video is yours and you're in control. It is recorded and securely stored with your consent, and you can delete it at any time in your Google Account," the blog post added. "It's used only for helping you sign in, unless you opt to share it for additional purposes. Your selfie video is encrypted at rest, meaning it's securely stored even when it's not being used." This new log-in measure comes at a time when artificial intelligence has made impersonation easier than ever, as PYMNTS wrote recently. In some cases, this means allowing scammers to create fake employees. "Synthetic insiders use stolen identities, deepfake technology and remotely controlled devices to get hired, pass background checks and log in through approved accounts: access that looks legitimate because it is legitimate," that report said. "The person operating it is not who the company believes it hired." In related news, PYMNTS explored the identity/authentication landscape in an interview in May with Henry Patishman, executive vice president, identity verification solutions at Regula. "Every identity and authentication system in financial services was built on a foundational assumption: One human initiates an action, one system verifies that person, and it happens at one specific moment in time," he said, adding that while that paradigm has held for decades, "unfortunately, today, it no longer does."
Share
Copy Link
Google rolled out a new account recovery feature allowing users to regain access through video selfies with guided head movements. The AI-powered account recovery system uses liveness detection to combat deepfake threats, though security experts warn sophisticated attacks could bypass camera verification. Users control their biometric data with opt-in consent and encrypted storage.
Google has launched a selfie video sign-in option that transforms how users regain access to locked accounts. The new account recovery feature addresses a common pain point: getting locked out after losing devices where passkeys are stored
1
. "Selfie is just the newest option in that list available for users. It's designed to help specifically in these vulnerable scenarios around not having access to the device where your passkey might be," says Claire Forszt, a product manager at Google who focuses on identity and engagement1
. The feature is rolling out globally to most personal accounts, excluding Workspace accounts, children, and those enrolled in the Advanced Protection Program4
.
Source: How-To Geek
Setting up the feature takes less than five minutes through the Security & sign-in tab in Google Account settings
1
. Users record a video selfie to recover your account by making short, guided head movements that capture multiple angles, including lifting their chin to look at the ceiling before returning to center1
. This side-to-side movement serves a critical security function, as real-time face replacement technology tends to struggle with profile views3
. Users must complete this setup before getting locked out, as the option isn't available during active account recovery processes1
.
Source: Wired
The AI-powered account recovery system employs multiple layers of protection against increasingly sophisticated deepfake attacks. Google uses liveness detection alongside standard security measures that evaluate device location, time of attempted login, browser settings, and IP address
2
. "Passing a selfie video alone may not always be sufficient to get back into your account," Google explained, noting that overall risk assessment may require additional sign-in methods3
.Security experts acknowledge that video verification offers advantages over static photos for facial recognition purposes. Ricardo Amper, founder and CEO of Incode Technologies, explained that sophisticated defense tools read more than pixels, examining accelerometer and sensor data, camera integrity, and dozens of signals confirming genuine selfie camera capture rather than injected synthetic video
2
. However, concerns persist about AI-generated impersonation capabilities. Chris Boehm, field CTO at Zero Networks, referenced the $25 million Arup scam where deepfake renders fooled employees during a conference call, demonstrating that deepfakes "have moved past the novelty stage" and are now proven fraud tools2
.Google emphasizes user control over biometric data through opt-in consent and encrypted storage practices. Selfie videos are encrypted at rest and used only for helping users sign in with video selfies unless users voluntarily share them for additional purposes
5
. Users can delete their selfie video at any time through their Google Account settings5
.During setup, Google presents an optional checkbox labeled "Improve Google Services" that allows the company to use selfie videos and related data to develop facial recognition, age estimation, and other verification methods across Google services
1
. This option remains unselected by default, and users can adjust privacy settings later if they change their mind1
. The opt-in approach contrasts sharply with Meta's recent misstep, where Instagram automatically opted adults into AI remixes of their images, triggering such severe backlash that Meta deleted the feature three days after launch1
.
Source: The Register
Related Stories
Google positions selfie video as one option within a broader multi-factor authentication strategy that includes passkeys, recovery contacts, and backup codes
1
. The company sees a trend toward passkeys and device-based authentication, which creates vulnerability when devices are lost3
. "Users can choose whatever method they prefer, we expect most will prefer the ease of use of passkeys for signing in regularly, and use selfie for times like when they lose their phone or the device with their passkey," Google stated3
.The timing reflects broader authentication challenges as synthetic insiders use stolen identities, deepfake technology, and remotely controlled devices to pass background checks and gain legitimate access
5
. Henry Patishman, executive vice president of identity verification solutions at Regula, noted that traditional identity systems built on the assumption of "one human initiates an action, one system verifies that person" no longer hold in today's AI-saturated environment5
. Watch for continued evolution in biometric data security practices as deepfake technology advances and companies balance convenience with protection against increasingly sophisticated threats.Summarized by
Navi
[3]
1
Technology

2
Policy and Regulation

3
Science and Research
