There you have it! Google just started letting people unlock a locked account with nothing but a …
July 23, 2026 · 0 likes · 0 comments
Insights
There you have it! Google just started letting people unlock a locked account with nothing but a video of their own face.
It is called selfie video sign-in. You record a short clip turning your head, Google stores that reference video, and if you ever get locked out with no password and no 2FA device in reach, that video gets you back in. We covered the full rollout on UnbiasedHeadlines.com: https://lnkd.in/eDPXVHkc
Google says the video is encrypted and you can delete it anytime, which is a reasonable design. But Google's own identity product manager, Claire Forszt, told Wired the part that should worry you: a selfie video alone "may not always be sufficient to get you back into your account if we suspect something risky going on."
Read that again. The company that built the system does not fully trust the system it built.
One catch buried in the fine print: you cannot set this up once you are already locked out. It only works if you configured it in advance, the exact moment nobody thinks to prepare for the day they lose everything.
There is also a checkbox during setup letting that same face video train Google's facial recognition and age-estimation AI. Opt-in, not default, but it sits right there for anyone rushing through.
Now the part that actually matters. In 2024, an employee at the design firm Arup sat on a video call with people who looked and sounded exactly like his colleagues. He had doubts, then got talked out of them. Arup lost $25 million on a live call, not even a stored biometric system somebody had time to study.
Ricardo Amper, CEO of identity firm Incode Technologies, said attackers do not even need to fool the camera anymore. They inject synthetic video straight into the data stream through tampered devices.
I have watched biometric access get marketed as "more secure" for years. It is more convenient. Those are not the same word.
You can change a password in ten seconds. Your face, you only get once.
You've been warned.
It is called selfie video sign-in. You record a short clip turning your head, Google stores that reference video, and if you ever get locked out with no password and no 2FA device in reach, that video gets you back in. We covered the full rollout on UnbiasedHeadlines.com: https://lnkd.in/eDPXVHkc
Google says the video is encrypted and you can delete it anytime, which is a reasonable design. But Google's own identity product manager, Claire Forszt, told Wired the part that should worry you: a selfie video alone "may not always be sufficient to get you back into your account if we suspect something risky going on."
Read that again. The company that built the system does not fully trust the system it built.
One catch buried in the fine print: you cannot set this up once you are already locked out. It only works if you configured it in advance, the exact moment nobody thinks to prepare for the day they lose everything.
There is also a checkbox during setup letting that same face video train Google's facial recognition and age-estimation AI. Opt-in, not default, but it sits right there for anyone rushing through.
Now the part that actually matters. In 2024, an employee at the design firm Arup sat on a video call with people who looked and sounded exactly like his colleagues. He had doubts, then got talked out of them. Arup lost $25 million on a live call, not even a stored biometric system somebody had time to study.
Ricardo Amper, CEO of identity firm Incode Technologies, said attackers do not even need to fool the camera anymore. They inject synthetic video straight into the data stream through tampered devices.
I have watched biometric access get marketed as "more secure" for years. It is more convenient. Those are not the same word.
You can change a password in ten seconds. Your face, you only get once.
You've been warned.