Google Adds Selfie Video Sign-In—Liveness Checks Take On Deepfakes

Google's selfie video option lets locked-out users recover accounts with a liveness-checked face video that is encrypted at rest and deletable at any time.

Google selfie video sign-in biometric account recovery

In Brief

  • Google’s new selfie video option lets locked-out users recover account access by recording a short face video that is matched against an encrypted reference video
  • Guided head movements during enrollment double as liveness checks that Google says help defeat impersonation attempts using fake photos and deepfakes
  • The reference video is encrypted at rest, deletable at any time, and used only for sign-in unless users opt to share it—but child, Workspace and recovery-mode accounts are excluded

Google announced selfie video sign-in on Thursday, a backup method that lets users who are locked out of their Google Account recover access by recording a short video of their face, the company said in a blog post. “Selfie video is a new way to get into your account, giving you more options if you’re ever locked out or don’t have access to your usual phone or computer,” Google wrote.

Enrollment requires looking at the device camera and completing a few short, guided head movements to capture multiple angles. To recover access later, users record a fresh selfie video that Google compares against the stored reference. Eligibility can be checked at g.co/signin-selfie, with The Verge describing a phased global rollout.

The deepfake question got a direct answer. “When you use a selfie to sign in, we use multiple layers of security to help prevent impersonation attempts like fake photos and videos (i.e., deep fakes). For example, we match your video against your saved selfie and require you to perform simple movements to prove it’s a live video,” Google wrote, adding that its standard suspicious-sign-in detection stays active on top.

How Google’s selfie video sign-in handles biometric data

Google is pre-empting the obvious privacy objections in its own copy: “Your selfie video is yours and you’re in control. It is recorded and securely stored with your consent, and you can delete it at any time in your Google Account. It’s used only for helping you sign in, unless you opt to share it for additional purposes. Your selfie video is encrypted at rest,” the blog post states.

The reference video lives server-side rather than on-device—The Verge notes it is stored in the cloud so recovery works from any hardware, drawing the comparison to Apple’s Face ID enrollment “but without the need for added infrared light.” That is the design trade-off: Face ID never leaves the device, while Google’s recovery scenario requires the template to be reachable when your usual devices aren’t.

Practical guardrails apply, according to TechSpot: Google recommends recording alone without sunglasses, masks, or hats; a QR code hands off setup from a camera-less PC to a phone; and child accounts, Workspace accounts, and accounts already in recovery mode are ineligible. Setup lives under Security & sign-in, then How you sign in to Google.

The password’s long goodbye gets a face

Selfie video slots into Google’s broader retreat from passwords, building on passkeys and recovery contacts. Account recovery has always been the weakest link in that stack—the moment when a user has lost every enrolled factor—and Google is betting a liveness-checked face video beats security questions and backup codes that users lose or attackers phish.

TechCrunch frames the launch against growing regulatory scrutiny of biometric data collection, noting liveness checks are becoming a baseline requirement as deepfake tooling spreads—the same abuse wave Frontierbeat covered when the UN warned that AI-powered impersonation and harassment were outpacing platform defenses.

The stakes of getting it wrong are asymmetric: a false accept hands over an entire Google identity. Google’s wager is that layered liveness checks plus sign-in anomaly detection keep that risk below the very real, very common harm of permanent account lockout.

FAQ

How does Google’s selfie video sign-in work?

You enroll by recording a short video with guided head movements; if you’re ever locked out, you record a new selfie video and Google matches it against the encrypted reference to restore access.

Is the selfie video safe from deepfakes?

Google says it uses multiple security layers—matching against the saved selfie, required live movements as a liveness check, and standard suspicious-sign-in detection—to block fake photos and deepfake videos.

Who can use selfie video recovery?

Eligible personal accounts in the phased global rollout (check g.co/signin-selfie); child accounts, Workspace accounts and accounts already in recovery mode are excluded, per TechSpot.

Leave your vote