Skip to main content
Home » Emerging Technology » News » Google wants your face as a password. Here is what you are actually agreeing to.

Google wants your face as a password. Here is what you are actually agreeing to.

4 min read
Google wants your face as a password. Here is what you are actually agreeing to.

Stay connected with KayaToday, follow us on Instagram and Facebook for the latest news and reviews delivered straight to you.


Biometric authentication has been creeping into everyday life for years, from fingerprint sensors on smartphones to face unlock on laptops. Google has now taken that logic one step further, offering users the option to recover a locked account by recording a short video of their face. It sounds convenient. The details, as usual, deserve a closer look.

The feature, confirmed by a Google spokesperson and reported by Ars Technica, allows eligible users to register a selfie video with Google in advance. If they later forget their password or lose access to an authenticator, that video becomes a fallback credential. Google matches a new selfie against the stored recording to verify identity and restore access.

What you are actually handing over, and what Google promises to do with it

Setting up selfie sign-in requires recording yourself moving your head as directed, giving Google’s models enough angles to map your face accurately. That video is stored on Google’s servers in encrypted form. The company’s landing page for the feature states the video will not be used for other purposes unless the user explicitly opts in.

That opt-in is worth noting. During setup, Google presents a toggle asking whether the company may use your selfie to improve its facial recognition technology. According to a Google spokesperson, leaving that box unchecked means the video is used solely for account recovery and age verification, and for creating an AI avatar if the user chooses. The opt-in is not required to activate the feature.

Google also allows users to delete the stored video at any time through their account settings, which is a meaningful control to have in writing. Whether that deletion is immediate and complete at the infrastructure level is, as with most cloud services, harder to verify independently.

The deepfake problem Google has not fully solved

The more substantive concern is not privacy but security. Selfie-based verification is only as strong as the system’s ability to distinguish a real human face from a convincing fake, and that bar is rising fast. AI-generated deepfake video has become accessible enough that near-real-time face spoofing is no longer a theoretical threat reserved for nation-state actors.

Google says it has multiple layers of security measures designed to detect deepfakes, including a liveness check that requires the user to move their head during the selfie. The company has not disclosed the technical specifics of those detection layers, which makes independent assessment difficult.

The clearest signal of the feature’s relative security standing comes from Google itself. Selfie sign-in is explicitly unavailable to accounts enrolled in Google’s Advanced Protection Program, which is the company’s highest-security tier designed for journalists, activists, politicians, and others at elevated risk of targeted attacks. Advanced Protection requires a physical security key, restricts third-party app access, and applies more aggressive Gmail phishing scans. The fact that selfie sign-in does not qualify for that tier tells you where Google’s own engineers place it on the trust hierarchy.

The feature is also unavailable for Google Workspace accounts, child accounts, and any account already in Advanced Protection. For the average consumer account, it sits alongside existing recovery options such as backup codes and recovery contacts rather than replacing them.

Convenient for most users, but not a security upgrade

For users in Malaysia and Singapore who manage personal Google accounts and occasionally get locked out, selfie sign-in is genuinely useful as a last-resort recovery tool. Losing access to a Google account can mean losing years of Gmail, Google Drive files, and linked services, so having an additional fallback has real practical value.

The risk calculus is different for business users or anyone who holds sensitive data in their Google account. For those users, the existing Advanced Protection Program, combined with a hardware security key, remains the more defensible choice. Selfie sign-in is a convenience feature dressed in biometric clothing, not a hardened authentication upgrade.

The broader trend here is what matters most. As AI-generated media becomes cheaper and more realistic, any authentication system that relies on visual appearance faces a structurally harder problem over time. Google’s liveness detection may be robust today. The question is whether it can keep pace with tools that are improving on a monthly basis. Facial recognition as a recovery mechanism is a reasonable bet for 2025. Whether it holds up through 2027 is a genuinely open question, and one that Google, regulators, and users alike will need to revisit sooner than most expect.

Read More: Firefighting Drones Are Being Tested in the US. Here Is What They Can and Cannot Do.

Faraz Khan is a freelance journalist and lecturer with a Master’s in Political Science, offering expert analysis on international affairs through his columns and blog. His insightful content provides valuable perspectives to a global audience.
248 articles
More from Faraz Khan →
We follow strict editorial standards to ensure accuracy and transparency.