Google has begun implementing a new account recovery option that utilizes "selfie video" verification, allowing users to regain access to their accounts by submitting a video of their face. This feature is presented as an alternative for users who have lost their phone or forgotten their password.
To set up the feature, users navigate to the Security & sign-in section of their Google Account, select "Selfie video," and follow prompts to record a short video of their face and basic movements. This initial video is then stored by Google and used for comparison against subsequent videos submitted during sign-in or account recovery attempts.
While Google states that these videos are encrypted at rest, stored securely, and can be deleted through security settings, the introduction of this biometric data collection raises several security and privacy concerns. Users can reportedly opt out of allowing their video data to be used for improving Google's verification systems, implying that without opting out, the data may be used for this purpose. Google also asserts that the videos are not shared with third parties.
Critics of the feature highlight the inherent risks associated with using facial biometrics for high-privilege account recovery. Facial recognition systems, even top-tier ones, are not infallible, with evaluations by the US National Institute of Standards and Technology (NIST) indicating non-zero false positives and negatives, and performance degradation under varying conditions like lighting or camera quality. These systems do not store literal images but rather mathematical representations of facial features, which are then compared against new inputs.
The evolving sophistication of deepfake technology is another major concern. Research has shown that advanced deepfake attacks can achieve high success rates against some commercial facial verification systems in controlled environments, demonstrating the potential for such systems to be bypassed.
From a privacy standpoint, the collection of high-fidelity video recordings of users' faces and head movements for basic account management is seen as a significant long-term risk. Even with current privacy assurances regarding encryption, storage, and non-sharing, privacy policies and data usage practices can change over time. The mere existence of such a repository of sensitive biometric data makes it a potential target for data breaches.
Security experts advise against enabling this feature. Instead, they recommend using robust security practices such as strong, unique passwords managed by a password manager, enabling two-step verification with hardware security keys or passkeys (rather than SMS codes), maintaining secure offline backup codes, and regularly reviewing and updating recovery email addresses and phone numbers.






