Google will let you upload a video selfie to recover your account – but should you?

Google Pixel 10a

Kerry Wan/ZDNET

Follow ZDNET: Add us as a preferred source on Google.


ZDNET’s key takeaways

  • Google’s selfie video sign-on helps users recover their accounts.
  • You should know how your biometric data is stored and used.
  • Google asserts that uploaded biometric data is never shared.

Google’s introducing a new way to recover your account, and all you need is your face.

Users can upload a selfie video to regain access to their accounts if they’ve been locked out or are away from their usual device, the company said Thursday.

Also: Ernst & Young breach exposes client tax data – find out if you’re at risk and what to do next

Uploading a selfie video to remedy an extremely stressful situation sounds simple enough, and in a blog post, Google promised that users’ selfies are “encrypted at rest, meaning it’s securely stored even when it’s not being used.” 

Still, as we offer more of our permanent biometric data to tech companies, I asked security experts what users should know and consider before providing face scans to them. 

Avoiding deepfakes

Among experts, the consensus is that uploading a live video of your face is generally more valuable for identity verification than still photos, because motion, depth, lighting changes, and microexpressions can confirm humanity. 

However, some experts are concerned that video verification systems could be tricked by deepfakes. Hackers can use generative AI to alter photos of faces and official documents, making them appear realistic. 

Deepfakes are a genuine concern, and the technologies used to create them are more advanced than many people realize. Ricardo Amper, founder and CEO of Incode Technologies, an identity verification and fraud prevention company, said that while a video is more valuable than a photo for verification, motion alone is not proof of life.

Also: An AI agent breached Hugging Face before an AI defender caught it: What users should do next

Amper said that hackers can create AI-generated faces capable of blinking, turning their heads, and responding to prompts with motion, and that human ability to distinguish a real person from a deepfake is declining.

“The more sophisticated attacks don’t even try to fool the camera,” he said. “They bypass it entirely, injecting synthetic video directly into the data stream through virtual cameras and tampered or emulated devices.”

Chris Boehm, field CTO at Zero Networks, a cybersecurity provider, recalled the massive deepfake scam that swindled British design and architecture firm Arup out of $25 million in 2024. A company finance worker was duped into joining a conference call with deepfake renders of his colleagues, and was convinced to complete several wire transfers. Though the worker was suspicious of the emails leading up to the meeting, his doubt was assuaged by the realistic deepfakes.

Also: I enabled Android’s new security feature that detects fake cell towers – here’s why

Your Google account may not be worth this much money, but it’s possible for bad actors to use advanced technologies to access your information and that of thousands of others.

“Deepfakes have moved past the novelty stage,” Boehm said. “They’re now a fraud tool with a track record.” 

Multiple methods are key

Since deepfakes pose such a serious threat to video verification methods, experts agree that multiple verification tools are required to mitigate their impact. Amper said that these sophisticated defense tools use more than an image’s pixels to determine realness by reading a device’s finer details.

Google didn’t detail exactly how or which technologies it uses to differentiate between real people seeking to recover their accounts and bad actors using deepfakes, as doing so would be a security concern. However, Google’s blog post said it uses its standard security practices, along with deepfake detection, to flag suspicious activity, including device location, time of attempted login, browser settings, and IP address.

“The most sophisticated models today can determine from a single image whether a face is real, because they don’t judge the pixels alone — they read the device itself: accelerometer and sensor data, camera integrity, and dozens of other signals that confirm this is a genuine selfie camera capture and not something injected into the stream,” Amper said.

Also: I tested a 4TB quantum-resistant USB drive – but you don’t have to spend $3000 for this much security

Chris Bevil, director of global cyber resilience and AI, at Commvault, a data protection company, has similar sentiments. Bevil said that video verification is a great starting point, but there are other methods of confirmation beyond movement to verify authenticity, since hackers can inject synthetic video and fool simple defense systems.

“A video provides liveness and behavioral signals that a static photo cannot,” he said. “The key is layering it with device recognition, location, behavioral analytics, and additional verification when something does not align.”

Google’s blog post says the company uses multiple security methods to combat deepfakes and impersonation attempts, such as comparing your uploaded selfie video with another photo and requiring you to perform real-time movements to verify the video is genuine.

Also: Don’t let an AI chatbot pick your password, ever

According to Tony Anscombe, chief security evangelist at ESET, a cybersecurity provider, it’s imperative that companies use multiple authentication methods to deter hackers, whose tactics are evolving rapidly.

“The issue is whether one single method of authentication is being used to verify identity as opposed to multiple combined methods that would significantly reduce the overall risk of fraud,” he said. “Using multiple methods and even randomizing the methods used would disadvantage the attacker significantly.”

Privacy is paramount

The same experts warned that people should not be liberal with handing out their biometric data for the sake of digital convenience; unlike a password, your face, iris, or fingerprint can’t be changed if they’re involved in a data breach.

To stay safe, users should know how their biometric data is stored, used, protected, and deleted. Google’s privacy policy states that if users choose to share biometric data, Google may use it for product development studies. 

Also: Microsoft patches record 570 Windows security bugs with two exploited zero days – update now

Google’s selfie video blog post states that users’ selfie videos are recorded and stored securely, can be deleted at any time, and that users can opt out of sharing them with Google for “additional purposes.”

Google confirmed to ZDNET that users’ selfie videos are stored securely on the server, and that if users choose to share their selfie videos for Google’s “additional purposes,” one of those purposes may be improving the company’s verification methods. 

The experts I sought out agreed that on-device biometrics, such as fingerprint and face ID, are a more secure option for everyday use, since the data stays on the device rather than being transmitted for remote verification.

Also: Is that QR code a trap? How to spot quishing scams before it’s too late

However, Google’s selfie video option seems to be a last-ditch attempt, made especially for people who are locked out of their account and are nowhere near their usual devices. If you’re particularly wary of sharing more of your biometric data with Google in this manner, Google’s recovery contacts option might be a better fit.

Google allows users to add up to 10 people as recovery contacts, who should be people you trust. Adding these contacts can help you recover your Google account if you’re locked out. Once you call on a recovery contact, you’ll receive a unique code, and your contact will receive a prompt that you’re requesting their help. You’ll need to contact them within 15 minutes, or the code expires. Once your contact enters your code, you’ll have access to your account.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *