
Google's new selfie video recovery requires a head-turn to foil deepfakes. The feature activates after passkeys fail; facial data can be used for AI training unless opted out.
Google said Thursday it now lets users recover a locked account by submitting a selfie video. The feature only activates when email or phone recovery fails, and passkeys are unavailable.
To enroll, a user follows steps on Google's selfie video management help page. The system requires a camera and prompts the user to turn their head side to side, showing both profile and front. That motion is designed to block live deepfake videos, which still struggle to replicate a profile view convincingly, Google said.
When no other method works, the system can ask for a new selfie video and compare it against the stored one. The stored video is encrypted at rest and used only for sign-in unless the user opts to share it for additional purposes, according to Google's help page.
A Google spokesperson told The Register the company sees a trend toward passkeys and device-based authentication, meaning a lost device often means a lost account. "Users can choose whatever method they prefer, we expect most will prefer the ease of use of passkeys for signing in regularly, and use selfie for times like when they lose their phone or the device with their passkey," the spokesperson said.
Google stressed that a selfie video alone may not always be enough to regain access. "We evaluate the overall risk based on many factors and may require additional sign-in methods to help make sure it's actually you signing into your account," the company said.
The system is not comparable to Apple's Face ID or Android face unlock, which use infrared cameras and depth maps. Those are harder to spoof. Google's method uses plain video and AI, and facial recognition software has a history of reliability issues, even within Google's own products.
The timing of the feature raised questions. The Register's news team noted that deepfake videos are constantly improving, and it may only be a matter of time until a side view can be handled with ease. Google's own facial recognition systems have misidentified people in the past, highlighting the challenge of relying on the technology for security.
Privacy questions also surfaced. The option to allow Google to use the video "to help ongoing efforts to develop and improve facial recognition, age estimation, and other verification methods" is unselected by default. Google has a clear interest in users enabling it, The Register noted. The facial data could be used to train Google's algorithms if the user opts in, though the company has not detailed data retention or sharing policies.
The feature puts Google into a new trade-off. Easier account recovery for users who lose their devices versus the risk that deepfake technology will eventually overcome the side-to-side defense. Google is betting the motion check buys enough time.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.