READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Google Adds Selfie Video Sign-In, Storing Your Face on File as an Account Recovery Option

Google Adds Selfie Video Sign-In, Storing Your Face on File as an Account Recovery Option
Google is rolling out a feature letting users unlock locked accounts with a short selfie video instead of a password or 2FA device. It's convenient, but it means Google now stores a biometric reference video of your face, and security researchers warn deepfake tech is getting good enough to fool liveness checks.

Google is rolling out a new way to get back into your account when you're locked out: a video of your own face.

The feature, called selfie video sign-in, lets users record a short clip turning their head at Google's prompt. Google compares that clip to a reference video stored earlier and, if it matches, lets you back into your account, according to The Verge. It's meant for the scenario everyone dreads: no phone, no password, no access to your usual two-factor app.

Setup takes a few minutes. Users go to their Google account's Security & sign-in tab, find the How you sign in to Google section, and record a reference video by following on-screen prompts, according to Engadget. Google recommends no glasses, no masks, no other people or busy backgrounds in frame, and normal lighting.

Wired's Reece Rogers tested it and said the whole process took under five minutes, with Google accepting the video on the first try. Google told Wired the feature is rolling out globally to most accounts, though it's not available for Workspace accounts, child accounts, or accounts enrolled in Google's Advanced Protection Program, per Engadget.

Why Google Says This Is Safe

Google says the reference video is encrypted and stored securely, and users can delete it anytime, according to The Verge. During sign-in, Google requires a live video, not a photo, and checks for what the company calls liveness, meant to catch attempts to fake identity with a static image or a pre-recorded deepfake.

Claire Forszt, a Google product manager focused on identity, told Wired the feature is designed for a narrow use case: getting back into an account when you don't have your usual device. "We always recommend that you set up more than one option," she said. Forszt also confirmed Google evaluates broader risk signals beyond the video match itself. "There might be instances where passing a selfie video alone may not always be sufficient to get you back into your account if we suspect something risky going on."

One detail: Google gives users the option to let their selfie videos be used as training data to improve its facial recognition and age-estimation systems, according to Wired. That's opt-in, not default, but it means the same video you record for account security could also end up feeding Google's broader AI development if you check that box.

The Deepfake Problem

ZDNET talked to actual security experts, and the consensus wasn't reassuring.

Ricardo Amper, founder and CEO of identity verification firm Incode Technologies, told ZDNET that motion alone isn't proof you're dealing with a real person anymore. Attackers can generate AI faces that blink, turn, and respond to prompts in real time. And the more advanced attacks don't even try to fool the camera. "They bypass it entirely, injecting synthetic video directly into the data stream through virtual cameras and tampered or emulated devices," Amper said.

ZDNET pointed to the 2024 case where design and architecture firm Arup lost $25 million after an employee was tricked by deepfake video renders of colleagues on a conference call, a scam detailed by Chris Boehm, field CTO at cybersecurity firm Zero Networks. The employee had doubts going in but was talked out of them by how convincing the fake video calls looked.

If criminals can already fake video well enough to con a finance employee out of $25 million in a live call, a stored biometric sign-in system is a real target. Google's answer is that its liveness detection and "standard security practices" catch impersonation attempts, but neither Google nor any of the four outlets covering this rollout has published independent, third-party test results showing how the system performs against state-of-the-art deepfake injection attacks specifically.

What's Actually New Versus What Isn't

Google already let people log in with their face through phone face unlock or biometric passkeys. What's new is using a face video specifically as an account-recovery backup, alongside existing options like recovery contacts and backup codes, according to Wired.

A practical catch: you cannot set up selfie video sign-in while you're already locked out. Google's own support page says it has to be configured in advance, per Wired, meaning it's not a fix for people who need help right now, only a preventive step for later.

Google has not published a specific date for full global availability, saying only that the phased rollout is ongoing. Users can check eligibility at Google's dedicated sign-in page. Whether Google will release independent audit results on deepfake resistance, or whether regulators will ask for them given the Arup precedent, remains an open question.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
ZDNETGoogle will let you upload a video selfie to recover your account - but should you?
center-left
WiredGoogle Turns a Selfie Video Into Your Account’s Spare Key
center-left
EngadgetGoogle adds selfie video as a log-in option
left
The VergeGoogle now lets you sign in to your account using a selfie video