News
MARKET SIGNAL:

Selfie Video Recovery Gives Google Accounts A New Login Path

Newsroom brief

Google is adding opt-in selfie video account recovery while keeping Workspace, child and Advanced Protection accounts outside the feature, giving consumer users another login path tied to facial verification controls.

Verified against source materialEdited by SendTech Times Cybersecurity Desk
Selfie Video Recovery Gives Google Accounts A New Login Path
Image source: The Hacker News

A new selfie video recovery option is giving Google account users another login path when they lose access to the usual device, email address or phone number, drawing on Google material shared through The Hacker News.

Selfie Video Becomes An Account Recovery Option

The sign-in method is an opt-in recovery path on top of existing email-address and phone-number methods.

Users set it up by looking into a device camera and completing a few guided head movements so the account can store a reference video.

When a user later cannot sign in, the recovery flow can ask for a new short video of the same face.

In Google's description, the new clip is compared with the saved selfie video to confirm that the account belongs to the person trying to regain access.

The feature changes the account-recovery surface because it gives users a biometric route when their usual phone or computer is unavailable.

Verification media therefore becomes part of the security control, alongside passwords, devices and secondary contact channels.

The setup sequence also requires the user to look into the device camera before the account stores the reference video.

Workspace And Advanced Protection Accounts Are Excluded

The selfie sign-in option is not available for Google Workspace accounts, child accounts or Google Accounts enrolled in the Advanced Protection Program.

The exclusion keeps the feature aimed at consumer recovery rather than managed enterprise accounts or users already placed under a higher-security programme.

The help document also makes clear that users cannot add a selfie video while they are already locked out or inside the account-recovery process.

That condition means the method has to be configured before the recovery event, not improvised after access is lost.

The same material identifies three purposes for selfie video: helping users get back into an account, unlocking more features or services by verifying that a person is real and has not violated policy, and creating an avatar for AI content that looks and sounds like the user.

Storage Controls Depend On User Choice

The saved selfie video is presented as encrypted at rest and used only to help users log in, unless users choose to share it for other use cases.

Account holders can delete the feature at any time and can change the optional setting that lets the company use the data to improve services.

The optional data use covers work on facial recognition, age estimation and other verification methods that may use physical features or movement.

That makes the consent setting part of the security design, because the same media can support account recovery or broader verification research depending on the user's choice.

Hand Gestures Move ReCAPTCHA Away From Image Challenges

The account-recovery feature arrived alongside a Google Cloud Fraud Defense hand-gesture verification system for reCAPTCHA checks.

That system asks users to perform simple hand gestures through a device camera as a liveness check against automated bot traffic.

Google said the hand-gesture system extracts 21 hand-knuckle coordinates.

For that reCAPTCHA flow, videos are not associated with a user's identity and are deleted after verification, with no image or video retention beyond the check.

Workspace, child and Advanced Protection accounts remain outside the selfie video recovery option, leaving those users on other recovery controls for now.

Share this article
inXf

Related articles

More
Smart TV Proxy SDKs Turn Free Apps Into a Hidden AI Scraping Supply Chain
Cybersecurity

Smart TV Proxy SDKs Turn Free Apps Into a Hidden AI Scraping Supply Chain

Bright Data's SDK has been reverse-engineered in research showing how free apps can turn consumer devices, including smart TVs, into residential proxy nodes for web-scraping traffic. The issue matters because AI data harvesting is increasing demand for residential IPs, while consent screens and background network behavior may not be clear to users or IT teams.

WhatsApp Usernames Hide Phone Numbers But Scam Risk Remains
Cybersecurity

WhatsApp Usernames Hide Phone Numbers But Scam Risk Remains

WhatsApp is rolling out usernames and optional keys to reduce phone-number exposure, but security researchers warn that impersonation and social-engineering scams can move to handles, profile images and trusted-looking accounts.

CISA Tightens GitHub Controls After May AWS Key Leak
Cybersecurity

CISA Tightens GitHub Controls After May AWS Key Leak

CISA said privileged AWS GovCloud keys from a contractor appeared in a public GitHub repository in May, prompting secret rotation, repository monitoring and new incident playbooks. Logs showed no customer or mission data exposure, while the contractor, repository, exposure window and exact AWS permissions remain outside the public account.

WeedHack Malware Turns Minecraft Mods Into a 116,000-System Infostealer Campaign
Cybersecurity

WeedHack Malware Turns Minecraft Mods Into a 116,000-System Infostealer Campaign

WeedHack has infected more than 116,000 systems by targeting Minecraft players through malicious mods, clients, cheats and utilities. McAfee telemetry shows 116,464 affected systems, 2,000 to 3,000 infections a day, more than 240 distribution URLs and 3,820 malicious JAR files. The next signal is whether Minecraft mod communities can move users back toward official download sources before infostealer distribution expands further.

Microsoft Revokes 11 Secure Boot Shims After ESET Finds Bypass Risk
Cybersecurity

Microsoft Revokes 11 Secure Boot Shims After ESET Finds Bypass Risk

Ars Technica reported that ESET found 11 old UEFI shim images that Microsoft still trusted even after known defects. Microsoft revoked the shims in its June patch release, while the reason the lapse lasted for years remains outside the public account.

UAE Sets a Social Media Age Gate. Enforcement Is the Hard Part.
Cybersecurity

UAE Sets a Social Media Age Gate. Enforcement Is the Hard Part.

The UAE Cabinet has barred children under 15 from social media accounts and full platform features. The rule puts age verification, child privacy, parental controls and platform compliance on a 12-month operating clock.

Keep Reading

More Stories

Latest
Nvidia Opens Medical Simulation Framework For Healthcare Robot TrainingAIJul 24, 2026Nvidia Opens Medical Simulation Framework For Healthcare Robot TrainingNvidia's open-source Medical Physics Simulation framework is designed to generate training environments for healthcare robotics, while the named adopter list does not include a patient-side deployment.FTC Orders Celsius Founders To Pay $16.5 Million Over Crypto Deposit ClaimsFintech & Digital PaymentsJul 24, 2026FTC Orders Celsius Founders To Pay $16.5 Million Over Crypto Deposit ClaimsA July 20 Federal Trade Commission settlement puts $16.5 million in Celsius founder payments alongside bans on deposit and crypto-trading products, with court approval still required.TSMC U.S. Fab Push Squeezes AI Chip MarginsChips & SemiconductorsJul 24, 2026TSMC U.S. Fab Push Squeezes AI Chip MarginsTSMC has announced $200 billion in U.S. manufacturing commitments since 2025, but overseas fab expansion is already diluting margins as AI chip customers face higher domestic production costs.OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider RiskCybersecurityJul 24, 2026OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider RiskSecurityWeek reported that OpenAI fixed the AgentForger flaw in ChatGPT Workspace Agents after Zenity Labs showed how a phishing link could create a hidden autonomous agent with access to already-authorised connectors.BitMEX Wind-Down Ends A Perpetual-Swap Pioneer After 11 YearsCrypto/Web3Jul 23, 2026BitMEX Wind-Down Ends A Perpetual-Swap Pioneer After 11 YearsCoinDesk reported that BitMEX will shut down operations on September 23, 2026, with new registrations halted, user withdrawals urged and remaining contracts set for forced closure before the final deadline.South Korea Tests AI-RAN And 5G For Industrial Robot NetworksTelco & ConnectivityJul 23, 2026South Korea Tests AI-RAN And 5G For Industrial Robot NetworksRCR Wireless reports that South Korea has put KRW17.2 billion ($11.6 million) behind SK Telecom and KT-led AI-RAN trials for shipyards, factories and robot workloads.CXMT Pre-IPO Contract Tests Crypto Price Discovery For China Chip ListingCapital & PolicyJul 23, 2026CXMT Pre-IPO Contract Tests Crypto Price Discovery For China Chip ListingA Hyperliquid contract linked to ChangXin Memory Technologies is pricing the Chinese memory-chip maker far above its planned Shanghai offer before a restricted STAR market debut.Treasury Warning Sends Moonshot Distillation Claim Toward AI SanctionsCapital & PolicyJul 23, 2026Treasury Warning Sends Moonshot Distillation Claim Toward AI SanctionsA U.S. Treasury warning over alleged AI model distillation brings Moonshot’s Kimi K3 release into a policy test for Chinese open-weight models, Nvidia GB300 access and export-control enforcement.Google Keeps TPU Priority On AGI As Cloud Demand Strains CapacityAIJul 23, 2026Google Keeps TPU Priority On AGI As Cloud Demand Strains CapacityAlphabet told investors that its first compute-allocation priority is frontier AGI development, while Google Cloud demand and AI infrastructure spending are pushing the company to use third-party capacity as a bridge.White House Presses PJM Grid Reform As AI Power Demand RisesCloud & Data CentersJul 23, 2026White House Presses PJM Grid Reform As AI Power Demand RisesThe White House warned PJM Interconnection to reform its board governance and stakeholder process as AI data centres and other large loads intensify disputes over grid reliability, electricity prices and infrastructure cost allocation.OpenAI Presence Makes Enterprise AI Agents A Consulting SaleAIJul 22, 2026OpenAI Presence Makes Enterprise AI Agents A Consulting SaleOpenAI’s Presence service is available to eligible enterprise customers through deployed engineers, not as a self-service product, with pricing still scoped individually.Kratos Takedown Leaves Microsoft 365 Session-Theft Risk UnfinishedCybersecurityJul 22, 2026Kratos Takedown Leaves Microsoft 365 Session-Theft Risk UnfinishedGerman and US law enforcement took more than 200 Kratos phishing-kit servers offline, but investigators still tie the service to roughly 1,800 customers and session-theft attacks against Microsoft 365.