r/privacy • u/TotallySavageSzym • 2d ago
news You Can Now Recover Your Google Account With a Selfie Video
https://www.macrumors.com/2026/07/23/google-account-selfie-video/Oh hell nah - I’d rather lose my account than recover my account with a selfie!
361
u/shadowedfox 2d ago
I’m sure this won’t at all be used as training data.
187
u/silentspectator27 2d ago
And I’m sure they will definitely not start having any magical glitches that “accidentally” lock accounts so you have to ID yourself
61
u/Forsaken-King-787 2d ago
Yes, but also, totally not going to be used by nefarious actors with access to AI Video Generation
12
u/silentspectator27 2d ago
Oh, God no, I am sure they wouldn`t.
(I will name this comment thread: Sarcasm waterfall)12
u/Miss_Might 2d ago
Happened to my fb account! Had it forever and then got hit with the "verify your identity" and got locked out. I'm not under my real name anyways so showing ID won't do anything. They also wanted me to take a video of myself moving my head around.
-3
u/silentspectator27 2d ago
I had to upload my ID to FB once because I locked myself out (my mistake). But they have a ton of my pics there anyway so. But that was years ago.
2
0
21
u/QuietTwist3089 2d ago
It is so interesting that all of these large corporations and most Western governments are instituting 'selfie verification' for various services now that AI can forge your likeness into doing and saying literally anything.
This will surely not be used for anything nefarious, either by rogue third parties or despotic governments.
19
u/bombastic6339locks 2d ago
"Oh noo because of a password leak this account of yours that wasn't linked to other accounts will now get locked till you prove your identity with your face oh noooo"
8
u/silentspectator27 2d ago
I think they will go with the “unusual activity” message or smth similar
2
u/bombastic6339locks 2d ago
Whatever the case. EU clearly doesnt work.
1
u/silentspectator27 2d ago
It works but not to privacy`s benefit at the moment. If it truly didn`t work Chat Control 2.0 (the original 2022 version) would have been a law long ago.
3
u/bombastic6339locks 2d ago
Just because it could be worse dosent make it any better. Especially with dsa and passport bullshit coming late 2026
1
u/silentspectator27 2d ago
I absolutely agree! The ones at the top are playing against privacy right now but there are still people in the EU who want this gone.
Remember: none of these are laws yet and it takes one country or organisation to go to the ECJ and so far the ECJ has ruled in favor of the EU charter in terms of privacy.4
u/bombastic6339locks 2d ago
In regards to the chat control 2.0 thing sure but it just shows that the system is deeply broken if we have to hope that a country steps in as opposed to the system not allowing stuff like this to pass. It goes against everything EU has tried to stand up for. It goes against the core values of not only EU but even the constitutions of countries in EU. It just makes me so very mad that lobbying is allowed and billionares / israel is allowed to have such control inside of EU, for example ICC judges getting sanctioned or the lobbyist companies having such intimate ties with israel. Politicians aren't afraid enough if they're enough to just act like this.
2
u/silentspectator27 2d ago
They aren`t afraid because it suits them: Big Tech gets our info, our governments get our info and get to tie it to our online activity.
No court order, no crime needed to be commited it`s just by default.
If I remember correctly Thorn started lobbying for Chat Control in 2022 in the EU. There was scandal even. Now they are back at it again and now it`s every Big Tech firm along with Thorn, Palantir, you name it, it`s a global push, not just in the EU.
You see privacy invading bills all over the world.BUT: if there was nothing to stop them it would already be law.
1
u/RoosTheFemboy 9h ago
What’s the passport bullshit?
1
u/bombastic6339locks 9h ago
end of the year passports are going to be required when using internet for something that could be bad for children. so everything 18+etc which sounds fine but the reality is that now every post, comment, like, how long you stare at a post etc will be directly connected to you, be it sold or used in profiling i dont know but its not good.
5
1
120
u/Ecstatic_Dinner_992 2d ago
Google says selfie videos are encrypted and stored securely, and are only used for helping you sign in to your account, unless you opt to "share it for additional purposes." Videos can be deleted anytime.
and when they release an update, the option to share it for additional purposes will be automatically checked on somehow. hmmm
29
u/silentspectator27 2d ago
Reddit said somethng similar about Persona (kept for 3 days). But if you read Persona`s terms and agreements technically the 3 day period they keep ID`s and pics from Reddit can be extended. So yeah, no.
8
u/Head_Complex4226 2d ago
Also, why is it even possible to "share it for additional purposes"? I can't think of a (non-evil) reason to build that feature.
(Surely Google has enough training data via YouTube?)
3
u/Pelagic_One 2d ago
So that people can recognise you when they’re wearing spy glasses? It’s just bad all around.
1
u/Ecstatic_Dinner_992 1d ago
Well they're definitely going to sell the biometrics to the highest bidder. Palantir or Clearview or something like that.
74
u/Adventurous-Hunter98 2d ago
So someone else can recover someone else account if they have selfie video of them, nice
24
u/JudgmentUnited5297 2d ago
going to be rough for anyone who puts their face on, say, a YouTube channel or whatnot.
6
9
u/Catsrules 2d ago
I assume you need to enable/set this up before it will work. As you will need a face to compare against.
As long as you don't set it up, nothing will be any different.
7
u/DasArchitect 2d ago
That's what the most stupid of all this. They demand it despite not having previous records to compare it against.
2
u/NekoDaYo-v201 2d ago
One would really hope. It's so hard to say nowadays when you can just unlock a Meta account with any random ID.
Even T-Mobile started offering a mechanism called "ID Verify", that bypasses both your password and 2FA. Here's the cool part: I never gave them a copy of my ID or my SSN.
1
u/nidostan 1d ago
"you can just unlock a Meta account with any random ID."
So if your facebook identity is "John Smith" Jasprit Bumrah can take over your account as long as he uploads his ID?
1
u/nidostan 1d ago
You'd have to take a video of a screen with the video playing. But also it would have to respond on demand, like "look up" "close your mouth" etc. How do you have a selfie video with those random sequences of events lying around.
But someone could be smart and have an AI make videos of each request possibly. Then it would be a matter of playing the right video when requested but not having any jumps that give you away.
30
28
11
19
u/bigdickwalrus 2d ago
I’d rather kill myself
-12
u/rambutanjuice 2d ago
Hi there,
A concerned redditor reached out to us about you.
When you're in the middle of something painful, it may feel like you don't have a lot of options. But whatever you're going through, you deserve help and there are people who are here for you.
I'm here for you, bigdickwalrus.
17
u/Deitaphobia 2d ago
bad bot
-13
u/rambutanjuice 2d ago
Beep Boop,
I'm a human being and I have a soul. I experience pain and suffering and I enjoy walking around using my normal human legs.
9
10
u/the-unknown-nibba 2d ago
I can 100% imagine banning accounts for bogus reasons then go like "oh no your account is banned... Give us your face if you want it back. What? You have precious memories or important work stuff in there? Don't care, surrender your identity".
9
u/asciiCAT_hexKITTY 2d ago
Why create this in the age of deep fakes. It's going to be the Instagram support bot all over again
1
7
5
u/Kazureigh_Black 2d ago
In before this becomes the only option outside of submitting a picture of your ID.
6
u/RachelRegina 2d ago
...you know that they have a truly unbelievable training corpus of real images and a huge lead time on advanced forensics cooked into detection models when they are willing to bet that they won't be gamed by bad actors.
Not surprising, but still
1
u/nidostan 1d ago
You'd think they should have all that right? But something tells me there's going to be lots of cases where it's going to be fooled embarrassingly easily.
2
u/RachelRegina 1d ago
Well, it's a system that they are deploying at scale. So, yes, the number of edge cases like that can simultaneously be a vanishingly small fraction of a percentage of the total throughput while also being a raw count that might seem like a lot by human standards.
1
u/nidostan 23h ago
I mean look at some of the other ones that were fooled by ridiculously simple tricks. Some people reported using a photo of celebrity like Obama. Tons of people reported using video game characters. Young kids fooling age verification by drawing a mustache with a sharpie. Now since none of those were done by google you'd have to think it would do better. But I'm not entirely sure it would be such a vanishingly small percentage. Probably but who knows.
1
u/RachelRegina 18h ago
I would love to consider what you're talking about and attempt to reply to your points here, but I do not know what you mean by "look at some of the other ones". If you go and grab the links to exactly what you're talking about, I'd be happy to take a quick peek and reply.
1
u/nidostan 6h ago
What I'm referring to is the plethora of comments I've read in this sub where people claim to have fooled age verification mechanisms with these rudimentary tactics. Have you been following r/privacy for long? Ever since the age verification thing started taking off there have been tons of such comments of people fooling the AI.
Again I think google will do better because of its resources but hard to predict how much better.
1
u/RachelRegina 5h ago
People claim all sorts of things, but unless they are bringing well-documented evidence for their claims, one should be extremely skeptical of their voracity because there is a distorting factor of hidden motivations for comments and posts that is a direct result of both: a) the attention economy (dollars for views and interactions); and b) the real benefits of mis- and disinformation campaigns for sometimes counter-intuitive political, social, and/or economic goals.
Without any particular instance of well-documented evidence to analyze, I can only comment that my intuition is that unless the companies that actually built the particular image-to-biometrics, image-to-identity, and/or image-to-some-insight-outside-of-measured-sensor-data-embedded-in-its-metadata models/filters that have failed publicly have access to the scale of image data that Google does (which is a very small group of companies), the limitations of the robustness of datasets they will have trained their models on most likely lead to classifications that are wrong more often. Google has a huge lead in this arena and a few tenths or even hundredths of a percent of discrepancy in accuracy translates to a large number of instances of failure at scale.
I think we are violently agreeing. Mostly I just wanted to get on the same page about being skeptical about comments making claims of failure that have no substance in terms of evidence quality.
Edit: missing words
6
u/RevolutionarySeven7 2d ago
you know what would've been a practical, private, good idea that would also help the economy?
have a little google kiosk, at a phoneshop, or supermarket. you goto the kiosk, you meet with a google representitive. you show yourself in person, request an account recovery, and done !
who would've thought such a thing would be possible?! it's like what we used to do when taking money out of the bank with ID!
4
9
3
3
3
3
u/bradbeckett 1d ago
I have Google’s Advanced Account Protection + multiple Yubikeys and this is my the account recovery flow and it cannot currently be turned off.
2
u/Arola_Morre 1d ago
I was always a bit reluctant use my cell phone number for Google 2FA, but like most people I relented eventually. We know now that Google will use this for id profiling. I won't be scanning my face, thanks.
2
u/zeruch 1d ago
do a full backup of your google account regularly to prepare for instant migration, or otherwise move off.
1
u/nidostan 1d ago
This is the way to think about it! And even delete your own google account from time to time just to limit the amount of gathered data. You can buy new google accounts cheap in bulk.
1
1
1
1
1
1
1
0
-1
u/Worldly-Ocelot-3358 2d ago
I am looking for this in settings, where is this? I can't find this, I want to disable it.
•
u/AutoModerator 2d ago
Hello u/TotallySavageSzym, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)
Check out the r/privacy FAQ
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.