Google account: how secure the new selfie-video login really is

Google is introducing a new way to regain access to your account: a short selfie video. This feature is designed for situations where you’ve been locked out and don’t have your usual phone or computer handy. When setting it up, you film yourself and follow a few guided head movements so the system can record multiple angles of your face. If you lock yourself out later, you record a new video, which is compared to the one on file. The rollout has been taking place in phases since July 23; you can check if your account is included at g.co/signin-selfie.
It’s not a replacement for your password
It’s important to note that the selfie video replaces neither your password nor your passkey. It’s an additional recovery method and joins recovery contacts and other options. Google itself recommends setting up several of these. Workspace accounts, children’s accounts, and accounts in the Advanced Protection Program are excluded. Ironically, these are the very users with the greatest need for protection. The stored video is encrypted, is used by default only for signing in, and can be deleted at any time. Google may use it to improve its detection capabilities only if you give your consent.
Does Google really detect deepfakes?
Google promotes multiple layers of protection against fake photos and videos. At the core is liveness detection. You’re asked to make small movements to confirm that a real person is sitting in front of the camera, not a photo. This works for simple attacks; a printed photo or an old video won’t pass this test.
The catch lies elsewhere. A modern deepfake blinks, nods, and turns its head on command. And the most dangerous type of attack bypasses the camera entirely. In a so-called “injection,” the fake live video is fed directly into the app as if it were coming from the camera. It is precisely this type of attack that motion checks cannot prevent. A widely cited study presented at the USENIX Security Conference as early as 2022 demonstrated that commercial liveness detection systems can be automatically circumvented. Furthermore, the usual certification schemes such as ISO 30107-3, iBeta, or FIDO test attacks in front of the camera, not injection attacks. Security firms have reported a sharp rise in such injection attacks over the past two years.

What you should take away from this
The U.S. security standard NIST states it clearly: biometrics should never stand on its own, but always combined with a second factor and a non-biometric alternative. And you can’t change your face the way you can change a password. In practice, this means that as one of several recovery options, the selfie video is useful and still better than recovery via text message, which is vulnerable to SIM swapping. For the actual login process, passkeys and hardware keys remain the stronger choice. Those who are particularly high-value targets should avoid using the face video; Google excludes this group from the Advanced Protection Program anyway.





