Google selfie sign-in is now an account recovery option for people who set it up before they get locked out, Google said in a security blog post. The feature lets a user record a short video of their face, store it with Google, and later use a live selfie check to regain access if a password or authenticator is unavailable.
The new method joins Google's existing recovery tools, including recovery contacts and backup codes. It is aimed at the boring but painful case where a user cannot pass the normal sign-in checks. The tradeoff is also plain: users who want this fallback must hand Google a biometric video in advance.
Google says the feature is not available for every account. Workspace accounts, child accounts and accounts enrolled in Google's Advanced Protection Program cannot set it up. That last exclusion is the tell: Advanced Protection is Google's higher-security mode, built around security keys, tighter third-party app access and added Gmail checks for phishing.
How does Google selfie sign-in work?
To enroll, users record a video on a phone or computer camera while following prompts to move their head. Google says that video gives its systems a reference map of the user's face. If the user later needs the recovery option, Google asks for another live selfie video and compares it with the stored recording.
Google says the live check includes motion prompts meant to confirm that a real person is in front of the camera. That is liveness detection, the standard anti-fraud layer for face verification systems. It is supposed to make a printed photo or static image less useful to an attacker, though it does not make the system magic.
The obvious problem is that AI face-swapping and deepfake tools have become good enough to raise fraud concerns, including in near real-time video. Google says it uses multiple security layers to detect deepfakes. The company has not, in the information released, turned that claim into a public technical design that outsiders can audit.
What does Google do with the selfie video?
Google says the stored video is encrypted and will not be used for other purposes unless the user chooses to allow it. The company says the same selfie video can also be used for age verification for some account features and for creating an AI avatar.
During setup, Google includes an optional control that lets users permit the company to use the video to improve facial recognition technology. A Google spokesperson told Ars Technica that this opt-in is not required for account recovery, and that Google will not use the recording for other purposes if the user leaves the option off.
Google says users may delete the stored selfie video from account settings at any time. The company also says it may occasionally ask users to refresh their selfie video, which makes sense for a face-matching system that depends on a reference image aging less badly than the rest of us.
The feature is useful only if it is configured before trouble starts. Someone already locked out cannot retroactively create the face video needed for comparison. For users who are comfortable with Google holding another piece of sensitive identity data, the setup is meant to take only a few minutes. For users who want the strongest account protection Google offers, the company's own eligibility rules point them back to security keys rather than selfies.
This story draws on original reporting from Ars Technica.