LIVE · cybersecurity feed
Live wire
security

Google wants to store a selfie video of your face

A new selfie video verification feature could make recovering your Google Account easier. But it also creates new security and privacy concerns.

zeroday.news · 8d ago

Google has begun implementing a new account recovery option that utilizes "selfie video" verification, allowing users to regain access to their accounts by submitting a video of their face. This feature is presented as an alternative for users who have lost their phone or forgotten their password.

To set up the feature, users navigate to the Security & sign-in section of their Google Account, select "Selfie video," and follow prompts to record a short video of their face and basic movements. This initial video is then stored by Google and used for comparison against subsequent videos submitted during sign-in or account recovery attempts.

While Google states that these videos are encrypted at rest, stored securely, and can be deleted through security settings, the introduction of this biometric data collection raises several security and privacy concerns. Users can reportedly opt out of allowing their video data to be used for improving Google's verification systems, implying that without opting out, the data may be used for this purpose. Google also asserts that the videos are not shared with third parties.

Critics of the feature highlight the inherent risks associated with using facial biometrics for high-privilege account recovery. Facial recognition systems, even top-tier ones, are not infallible, with evaluations by the US National Institute of Standards and Technology (NIST) indicating non-zero false positives and negatives, and performance degradation under varying conditions like lighting or camera quality. These systems do not store literal images but rather mathematical representations of facial features, which are then compared against new inputs.

The evolving sophistication of deepfake technology is another major concern. Research has shown that advanced deepfake attacks can achieve high success rates against some commercial facial verification systems in controlled environments, demonstrating the potential for such systems to be bypassed.

From a privacy standpoint, the collection of high-fidelity video recordings of users' faces and head movements for basic account management is seen as a significant long-term risk. Even with current privacy assurances regarding encryption, storage, and non-sharing, privacy policies and data usage practices can change over time. The mere existence of such a repository of sensitive biometric data makes it a potential target for data breaches.

Security experts advise against enabling this feature. Instead, they recommend using robust security practices such as strong, unique passwords managed by a password manager, enabling two-step verification with hardware security keys or passkeys (rather than SMS codes), maintaining secure offline backup codes, and regularly reviewing and updating recovery email addresses and phone numbers.

ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]