"Users can choose whatever method they prefer, we expect most will prefer the ease of use of passkeys for signing in regularly, and use selfie for times like when they lose their phone or the device with their passkey," Google said in response to our questions.
How Google's selfie sign-in enrollment and recovery work
Google announced on Thursday that users can now enroll a verification selfie for account recovery. Enrollment follows steps on Google's help page: a device with a camera is required, and the user must record a short video that includes a full-frontal face card and a deliberate side-to-side head movement to show a profile. The feature is explicitly restricted to use only when conventional recovery — email or phone recovery options — fails. If the system needs further assurance, Google can prompt the user to take another selfie video for comparison to the one recorded earlier, and will use that comparison to decide whether to restore access.
Why Google frames selfie recovery as a complement to passkeys
A Google representative told The Register the company is seeing a trend toward passkeys and other device-based authentication, and framed the selfie option as a fallback for lost devices. "Users can choose whatever method they prefer," the company said, adding that it expects most people to use passkeys for regular sign‑ins and the selfie mechanism "for times like when they lose their phone or the device with their passkey." Google also emphasized that the selfie system "is not like Apple’s Face ID or face unlock on Android" and said the different technologies "serve different purposes."
Plain video, AI comparison, and the depth-map distinction
Google's selfie sign-in uses plain recorded video and AI-based comparison. That design contrasts with some device-embedded face authentication, which the Register piece describes as using infrared cameras that capture depth maps to match points on a user's face to a stored 3D map. According to the article, those depth-map systems — typically associated with Apple devices using Face ID and some higher-end Android devices — are "harder to fool." Google’s system instead relies on the side-to-side movement and the hope that real-time face-replacement deepfakes will struggle with profile views, while acknowledging that "passing a selfie video alone may not always be sufficient to get back into your account" because the company "evaluate[s] the overall risk based on many factors."
Privacy controls and optional research use
Google says the facial scans are encrypted at rest and stored only with user consent. By default, recordings are "used only for helping you sign in," but users are offered an opt-in labeled "Improve Google Services" on the page where they record a selfie. That option, the help text notes, is unselected by default; if a user enables it, Google may use the video and related data "to help ongoing efforts to develop and improve facial recognition, age estimation, and other verification methods."
What this means for technologists, end users, and adversaries
- Technologists and security teams: The change highlights a practical trade-off driven by rising passkey adoption. Google framed selfie recovery as a fallback for lost devices; teams implementing authentication will need to weigh reliance on device-bound credentials against the operational need for an out-of-band recovery path that does not depend on possession of a specific device.
- End users and the general public: For individuals, Google presents a choice: use passkeys for everyday convenience and enroll a selfie only for rare recovery situations. Users should note that Google may require additional sign-in signals beyond a selfie, and that opting into "Improve Google Services" permits broader use of collected videos for research.
- Adversaries and deepfake makers: The Register flagged a tension the company itself acknowledged — deepfake videos are constantly improving, and the side-profile requirement is intended to make live deepfakes harder to use. The article warned, however, that future improvements could reduce the effectiveness of that defense.
The new selfie recovery feature is positioned as a narrowly scoped fallback: encrypted, consent-based, and gated behind failed email or phone recovery. Yet the Register's reporting underscores two persistent tensions — the evolving capability of deepfakes and the value of facial recordings for research — and quotes Google and its help pages acknowledging both. The company has placed technical and policy controls around the feature, but the long‑term effectiveness of side‑profile checks and plain-video verification will be judged as deepfake tools continue to evolve.




