Google will let you upload a selfie to restore your account – but should you?

Follow ZDNET: Add us as a favorite resource on Google.
Highlights taken by ZDNET
- Google selfie video login helps users to access their accounts.
- You should know how your biometric data is stored and used.
- Google asserts that uploaded biometric data is never shared.
Google is introducing a new way to restore your account, and all you need is your face.
Users can upload a selfie video to gain access to their accounts when they’re locked out or away from their regular devices, the company said Thursday.
Also: Ernst & Young breach exposes customer tax data – find out if you’re at risk and what to do next
Uploading a selfie video to fix a stressful situation sounds easy enough, and in a blog post, Google promised that selfies are “recorded at rest, meaning they’re stored safely even when they’re not in use.”
However, as we provide our endless biometric data to tech companies, I asked security experts what users should know and consider before handing over facial scanners.
Avoiding deepfakes
Among experts, the consensus is that uploading a live video of your face is often more important for verifying your identity than still images, because movement, depth, light changes, and microexpressions can confirm personality.
However, some experts are concerned that video verification systems can be fooled by deepfakes. Hackers can use artificial intelligence to alter facial images and legal documents, making them appear more realistic.
Deepfakes are a real concern, and the technology used to make them is more advanced than most people realize. Ricardo Amper, founder and CEO of Incode Technologies, an identity verification and fraud prevention company, said that while video is more important than image for verification, motion alone is not proof of life.
Also: AI agent breaks Face of Unity before AI defender catches it: What users should do next
Amper said that hackers can create AI faces that can blink, turn their heads, and respond to information with movements, and that the human ability to distinguish a real person from a deepfake is decreasing.
“Sophisticated attacks don’t even try to fool the camera,” he said. “They transfer it completely, injecting artificial video directly into the data stream with virtual cameras and modified or simulated devices.”
Chris Boehm, CTO at Zero Networks, a cyber security provider, recalled a deep-rooted scam that defrauded British design and architecture firm Arup of $25 million in 2024. A company finance employee was tricked into joining a conference call with deep translation for his colleagues, and convinced himself to complete several calls. Although the employee was suspicious of the emails leading up to the meeting, his suspicions were discovered to be real deepfakes.
Also: I enabled the new Android security feature that detects fake cell towers – here’s why
Your Google account may not be worth this much, but it is possible for bad actors to use advanced technology to access your information and that of thousands of others.
“Deepfakes have gone to a new level,” Boehm said. “They are now a historic fraud tool.”
Many methods are important
Since deepfakes pose such a serious threat to video authentication methods, experts agree that more authentication tools are needed to mitigate their impact. Amper said these advanced security tools use more than image pixels to determine authenticity by reading fine-grained device information.
Google did not specify exactly how it uses any technology to distinguish between real people who want to recover their accounts and bad actors using deepfakes, as doing so would be a security concern. However, Google’s blog said it uses its standard security procedures, as well as deepfake detection, to flag suspicious activity, including device location, login attempt time, browser settings, and IP address.
“The most advanced models today can determine from a single image whether a face is real, because they don’t judge pixels alone — they read the device itself: accelerometer and sensor data, camera integrity, and a bunch of other signs that confirm that this is a real selfie camera capture and not something injected into the stream,” said Amper.
Also: I tested a 4TB capacity USB drive – but you don’t have to spend $3000 for this much security.
Chris Bevil, director of cyber resilience and AI at Commvault, a data protection company, shares similar sentiments. Bevil said video verification is a good start, but there are other ways to verify beyond motion to verify authenticity, as hackers can inject artificial video and fool simple defense systems.
“Video provides behavioral cues that a static image cannot,” he said. “The key is to layer it with device recognition, location, behavioral analytics, and additional validation if something doesn’t match.”
Google’s blog says the company uses a number of security measures to combat deepfakes and impersonation attempts, such as comparing your uploaded video to another image and requiring you to make real-time movements to verify the video’s authenticity.
Also: Don’t let an AI chatbot choose your password, ever
According to Tony Anscombe, chief security evangelist at ESET, a cybersecurity provider, it’s important for companies to use multiple authentication methods to stop hackers, whose tactics are rapidly evolving.
“The issue is whether a single authentication method is used to verify your identity as opposed to multiple combined methods that can significantly reduce the risk of fraud,” he said. “Using multiple methods and even randomizing the methods used can seriously harm an attacker.”
Privacy is important
The same experts warned that people should not be comfortable giving away their biometric data for convenience; unlike a password, your face, iris, or fingerprint cannot be changed if they are involved in a data breach.
To stay safe, users should know how their biometric data is stored, used, protected, and deleted. Google’s privacy policy states that if users choose to share biometric data, Google may use it for product development studies.
Also: Microsoft patch records 570 Windows security bugs with two days of zero exploits – update now
A post on Google’s selfie blog says that users’ selfies are recorded and stored securely, can be deleted at any time, and that users can opt out of sharing them with Google “for additional purposes.”
Google confirmed to ZDNET that selfies are stored securely on a server, and that if users choose to share their selfies for “additional purposes” for Google, one of those purposes may be to improve the company’s authentication methods.
Experts I consulted agreed that on-device biometrics, such as fingerprints and face ID, are a more secure option for everyday use, as the data stays on the device rather than being transmitted for remote authentication.
Also: Is that QR code a trap? How to spot quishing scams before it’s too late
However, Google’s video option seems to be a last-ditch effort, designed mainly for people who are locked out of their account and nowhere near their regular devices. If you are very wary of sharing too much of your biometric data with Google in this way, Google’s recovery contacts option may be a better fit.
Google allows users to add up to 10 people as recovery contacts, which should be people you trust. Adding these contacts can help you find your Google account if you’re locked out. Once you call the receiving contact, you will receive a unique code, and the contact will receive a notification that you are requesting their assistance. You will need to contact them within 15 minutes, or the code expires. If your contact has entered your code, they will be able to access your account.



