Google will let you upload a video selfie to recover your account - but should you?
Follow ZDNET: Add us as a preferred source on Google.

Follow ZDNET: Add us as a preferred source on Google.
Google's introducing a new way to recover your account, and all you need is your face.
Users can upload a selfie video to regain access to their accounts if they've been locked out or are away from their usual device, the company said Thursday.
Also: Ernst & Young breach exposes client tax data - find out if you're at risk and what to do next
Uploading a selfie video to remedy an extremely stressful situation sounds simple enough, and in a blog post , Google promised that users' selfies are "encrypted at rest, meaning it's securely stored even when it's not being used."
Still, as we offer more of our permanent biometric data to tech companies, I asked security experts what users should know and consider before providing face scans to them.
Among experts, the consensus is that uploading a live video of your face is generally more valuable for identity verification than still photos, because motion, depth, lighting changes, and microexpressions can confirm humanity.
However, some experts are concerned that video verification systems could be tricked by deepfakes. Hackers can use generative AI to alter photos of faces and official documents, making them appear realistic.
Deepfakes are a genuine concern, and the technologies used to create them are more advanced than many people realize. Ricardo Amper, founder and CEO of Incode Technologies, an identity verification and fraud prevention company, said that while a video is more valuable than a photo for verification, motion alone is not proof of life.
Also: An AI agent breached Hugging Face before an AI defender caught it: What users should do next
Amper said that hackers can create AI-generated faces capable of blinking, turning their heads, and responding to prompts with motion, and that human ability to distinguish a real person from a deepfake is declining.
"The more sophisticated attacks don't even try to fool the camera," he said. "They bypass it entirely, injecting synthetic video directly into the data stream through virtual cameras and tampered or emulated devices."
Chris Boehm, field CTO at Zero Networks, a cybersecurity provider, recalled the massive deepfake scam that swindled British design and architecture firm Arup out of $25 million in 2024. A company finance worker was duped into joining a conference call with deepfake renders of his colleagues, and was convinced to complete several wire transfers. Though the worker was suspicious of the emails leading up to the meeting, his doubt was assuaged by the realistic deepfakes.
Source: ZDNet