Breaking
Tech

How Google's selfie login works, and how safe it actually is

Ars Technica3 h ago
A smartphone screen showing facial recognition scanning
A smartphone screen showing facial recognition scanningPhoto: cottonbro studio / Pexels

Google has introduced a new feature that expands how people can access their accounts: some users can now log in with a short selfie video instead of a password. The same biometric data can also be used for age verification and to generate AI avatars.

The feature is built on facial recognition technology, but Google's approach differs from traditional face-unlock systems in that it requests a brief video stream rather than a single static photo. The video format is meant to make it harder to fool the system with a fake photo or screenshot; the system performs liveness detection to confirm a real, live face is in front of the camera.

Beyond login, the same selfie video can be used to estimate a user's age. This is offered as a way to verify age without uploading an ID document, at a time when age-based content restrictions are becoming increasingly common.

The feature's third use case is generating AI avatars: a user's facial features can be used as the basis for producing personalised digital characters usable across various apps.

What all three uses have in common is that they rely on sensitive biometric data. Passwords can be changed; a person's face cannot, which means a leak or misuse of facial data carries a risk that is far harder to undo.

Google says this data is processed on-device and is not sent to the company's servers as raw video footage; instead, a mathematical representation of the face — a biometric template — is generated and used for comparison. This approach is standard practice in many modern facial recognition systems.

Privacy experts acknowledge that such systems can be designed to be technically secure, but say the real concern is scope creep over time. A feature introduced for a narrow purpose can later be repurposed by companies to serve other products using the same underlying data.

From a security standpoint, the advantage of selfie login is a smoother user experience compared with forgotten or stolen passwords. But experts caution that biometric systems aren't foolproof either — advanced AI-generated imagery, or deepfakes, can fool some liveness-detection systems.

For regulators, the spread of facial recognition technology raises fresh questions around biometric data collection, retention periods and sharing with third parties; some jurisdictions already require explicit consent and strict retention rules for this kind of data.

The practical advice for users is to review privacy settings — showing what data is collected, where it's stored and what purposes it may be used for — before enabling features like this. Selfie login can be convenient, but every biometric convenience comes with a different privacy trade-off attached.

This article is an AI-curated summary based on Ars Technica. The illustration is a stock photo by cottonbro studio from Pexels.

Read next