Google’s newly launched “Selfie Video Login” accounts: Password recovery and device loss support

Google announced a new feature called “Selfie for sign-in” on July 23 in an official blog post, allowing users to log back into their accounts using a pre-recorded selfie video if they forget their password or can’t find their usual device.
(Background: The EU digital wallet verification of age—does it need to link to Google or Apple? Developers flood GitHub and denounce a privacy nightmare)
(Additional context: The global “social media ban” wave targeting teenagers is accelerating—will Taiwan follow?)

Table of contents

Toggle

  • Login, no longer relying on memory
  • One face, two uses
  • Biometrics forced out by regulation

Account recovery has always been the most critical piece in the security chain. SMS verification codes can be intercepted, backup email accounts can be hijacked, and even real human customer service can be tricked by social engineering scripts into handing over account control. Over the years, platforms have tried everything to patch this hole, but they’ve never escaped a shared weakness: every recovery method ultimately depends on the user “remembering something.” And this time, Google is choosing to use a face, replacing memory.

Login, no longer relying on memory

On July 23, Google, in its official blog, jointly announced a new sign-in method—Selfie for sign-in—by Claire Forszt, Product Manager in Identity and Engagement, and John Gronberg, Director of Product Management. The setup process is not complicated: users simply face the device’s camera lens and complete a few specified head movements, and the system captures and archives facial images from different angles.

After that, if you ever get locked out of your account, or you don’t have the usual device to receive SMS verification codes, you can record another video, compare it with the previously saved images, and directly replace older recovery methods like SMS or backup email.

The real key to this verification is not simply capturing a face—it’s liveness detection. In simple terms, the system requires the user to perform real-time, non-pre-recorded actions on the spot to confirm that a living person is standing in front of the camera, not a photo, a prerecorded video, or a synthesized fake selfie video. This layer of detection, combined with Google’s existing suspicious sign-in detection mechanisms, blocks impostors together.

Eligible users can check whether they’ve been included on the rollout page. The feature will be pushed to users in different regions in batches and steps, rather than being fully opened at once. Google also emphasized that the saved selfie videos are encrypted and stored; the entire build-and-compare process only starts with the user’s consent. Users can also delete this record completely at any time in their account settings.

One face, two uses

The problem lies in the boundary of intended use. According to Google’s description page, the saved selfie video is intended by default for only one purpose: account sign-in. But as long as the user checks the consent option, Google can take the same material to improve facial recognition, age estimation, and other verification methods that rely on physiological traits and motions. In other words, a face recorded at first for account recovery may later very well become raw training material for an internal company age-judgment model—not just a backup stored in a database.

A Google spokesperson told Bloomberg that this new sign-in option is not designed for age verification. But the same description page also states that if Google’s technology suspects an applicant is underage, the system will directly block the creation of that selfie file. That means as soon as the user takes the first step to apply, the system is already quietly making an age determination—only without labeling it as “age verification,” leaving a deliberately ambiguous gap in the wording.

This isn’t the first time Google has let facial recognition drift beyond its intended purpose. It has also partnered with a third-party company, Private ID, using selfie images to verify user age to unlock access once thresholds are met for restricted content. The entire logic behind this, and the login feature this time, are essentially built on the same skeleton: first take a face image, then have an algorithm decide whether to grant access. The only difference is whether the thing being allowed is the account or the content.

Biometrics forced out by regulation

Recently, Australia has passed laws restricting teenagers’ use of social media. France is also moving forward with similar regulations. The UK and Malaysia have followed the same regulatory pace, requiring platforms to prove a user’s real age within the shortest possible timeframe. Big platforms are being forced to build, within the same time window, a biometric foundation that can answer “who is this, and how old are they.” Selfie for sign-in, to a certain extent, is a spin-off that grows out of that underlying infrastructure.

Passwords can be changed, email accounts can be cut and reworked—only the face can’t be swapped. When biometric traits become the final line of defense in a login flow, what users hand over is no longer just a set of verification data that can be reset; it becomes an identity proof that lasts a lifetime, comes only in one copy, and can’t be re-applied for.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned