News
MARKET SIGNAL:

Selfie Video Recovery Gives Google Accounts A New Login Path

Newsroom brief

Google is adding opt-in selfie video account recovery while keeping Workspace, child and Advanced Protection accounts outside the feature, giving consumer users another login path tied to facial verification controls.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: The Hacker News
Selfie Video Recovery Gives Google Accounts A New Login Path
Image source: The Hacker News

A new selfie video recovery option is giving Google account users another login path when they lose access to the usual device, email address or phone number, drawing on Google material shared through The Hacker News.

Selfie Video Becomes An Account Recovery Option

The sign-in method is an opt-in recovery path on top of existing email-address and phone-number methods.

Users set it up by looking into a device camera and completing a few guided head movements so the account can store a reference video.

When a user later cannot sign in, the recovery flow can ask for a new short video of the same face.

In Google's description, the new clip is compared with the saved selfie video to confirm that the account belongs to the person trying to regain access.

The feature changes the account-recovery surface because it gives users a biometric route when their usual phone or computer is unavailable.

Verification media therefore becomes part of the security control, alongside passwords, devices and secondary contact channels.

The setup sequence also requires the user to look into the device camera before the account stores the reference video.

Workspace And Advanced Protection Accounts Are Excluded

The selfie sign-in option is not available for Google Workspace accounts, child accounts or Google Accounts enrolled in the Advanced Protection Program.

The exclusion keeps the feature aimed at consumer recovery rather than managed enterprise accounts or users already placed under a higher-security programme.

The help document also makes clear that users cannot add a selfie video while they are already locked out or inside the account-recovery process.

That condition means the method has to be configured before the recovery event, not improvised after access is lost.

The same material identifies three purposes for selfie video: helping users get back into an account, unlocking more features or services by verifying that a person is real and has not violated policy, and creating an avatar for AI content that looks and sounds like the user.

Storage Controls Depend On User Choice

The saved selfie video is presented as encrypted at rest and used only to help users log in, unless users choose to share it for other use cases.

Account holders can delete the feature at any time and can change the optional setting that lets the company use the data to improve services.

The optional data use covers work on facial recognition, age estimation and other verification methods that may use physical features or movement.

That makes the consent setting part of the security design, because the same media can support account recovery or broader verification research depending on the user's choice.

Hand Gestures Move ReCAPTCHA Away From Image Challenges

The account-recovery feature arrived alongside a Google Cloud Fraud Defense hand-gesture verification system for reCAPTCHA checks.

That system asks users to perform simple hand gestures through a device camera as a liveness check against automated bot traffic.

Google said the hand-gesture system extracts 21 hand-knuckle coordinates.

For that reCAPTCHA flow, videos are not associated with a user's identity and are deleted after verification, with no image or video retention beyond the check.

Workspace, child and Advanced Protection accounts remain outside the selfie video recovery option, leaving those users on other recovery controls for now.

Share this article
inXf

Related articles

More
Deel Buys Clarity To Add Continuous Deepfake Checks To HR Platform
AI

Deel Buys Clarity To Add Continuous Deepfake Checks To HR Platform

TNW reported that Deel acquired Tel Aviv-based Clarity for a reported $45 million to $50 million, adding real time deepfake detection and identity verification across hiring, onboarding, device provisioning and access management.

Cracken Self-Serve AI Security Platform Puts Offensive Testing Behind Access Gates
Cybersecurity

Cracken Self-Serve AI Security Platform Puts Offensive Testing Behind Access Gates

TNW reported that Cracken opened a $199 monthly self-serve tier for proactive AI security testing while keeping its unrestricted offensive model and sensitive playbooks behind enterprise controls.

Microsoft Revokes 11 Secure Boot Shims After ESET Finds Bypass Risk
Cybersecurity

Microsoft Revokes 11 Secure Boot Shims After ESET Finds Bypass Risk

Ars Technica reported that ESET found 11 old UEFI shim images that Microsoft still trusted even after known defects. Microsoft revoked the shims in its June patch release, while the reason the lapse lasted for years remains outside the public account.

Gartner Metrics Shift Cybersecurity From Patch Counts To AI Attack Paths
Cybersecurity

Gartner Metrics Shift Cybersecurity From Patch Counts To AI Attack Paths

Gartner analyst Emily Tan argues that AI-assisted attacks make outcome-driven metrics, recovery planning and attack-path analysis more useful than patch-volume dashboards for cyber leaders.

Google AI Workflow Pushes Chrome Security Fixes To 1,072 Bugs
Cybersecurity

Google AI Workflow Pushes Chrome Security Fixes To 1,072 Bugs

BleepingComputer reported that Google attributed 1,072 Chrome security bug fixes to Chrome 149 and Chrome 150, while faster patch delivery remains part of the browser security plan.

Amazon Attribution Moves npm Hijack Risk Back To Maintainer Accounts
Cybersecurity

Amazon Attribution Moves npm Hijack Risk Back To Maintainer Accounts

Amazon Threat Intelligence linked the debug and chalk npm hijack to North Korea’s Sapphire Sleet, extending the supply-chain timeline while leaving public evidence gaps around older package records.

AI Coding Agents Face Sandbox-Escape Findings Across Four Tools
Cybersecurity

AI Coding Agents Face Sandbox-Escape Findings Across Four Tools

BleepingComputer reported that Pillar Security reproduced sandbox-escape paths in Cursor, OpenAI Codex, Gemini CLI and Google Antigravity, shifting attention from agent containment to trusted developer tools around the workspace.

Arch Linux Freezes AUR Package Adoption After Malware Takeovers
Cybersecurity

Arch Linux Freezes AUR Package Adoption After Malware Takeovers

Arch Linux temporarily blocked AUR package adoption after malicious package takeovers, shifting the immediate security problem from package removal to maintainer-account review and developer secret exposure.

Keep Reading

More Stories

Latest
Indosat AI Data Centre Plan Targets 1GW With Ooredoo, Nokia And NvidiaCloud & Data CentersAug 8, 2026Indosat AI Data Centre Plan Targets 1GW With Ooredoo, Nokia And NvidiaData Center Dynamics reported that Indosat, Ooredoo Group, Nokia and Nvidia launched Zankore by Indosat with a plan for up to 1GW of AI data centre capacity in Indonesia.Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightAIAug 8, 2026Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightCNBC reported that Black Hat cybersecurity leaders treated the Hugging Face AI-agent breach as a turning point for governing autonomous cyber models rather than a one-off failure.Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAIAug 8, 2026Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAI News reported that Alibaba plans revenue-sharing terms for some commercial users of its next Qwen open-weight AI model, following a licensing pattern already used by Moonshot for Kimi K3.Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanCapital & PolicyAug 8, 2026Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanArs Technica reported that a New Mexico judge ordered Meta to provide $567 million for treatment, screening, awareness and prevention after finding that its platforms contributed to a public nuisance.Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationAIAug 8, 2026Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationSiliconANGLE reported that Harvey AI is seeking at least $500 million in new funding that could value the legal AI startup at $15.5 billion after annualized revenue passed $350 million.Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaScience & TechAug 7, 2026Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaTech Collective SEA wrote that Shopee’s Vietnam share fell from 61% to 53% between May 2025 and April 2026 as TikTok Shop rose from 33% to 44%, showing how social commerce is reshaping regional ecommerce infrastructure.China Opens Security Review Of Palo Alto Networks ProductsCybersecurityAug 7, 2026China Opens Security Review Of Palo Alto Networks ProductsChina's cyberspace regulator opened a security review of Palo Alto Networks products, with no named product line, technical flaw or decision timetable disclosed.AI Pioneers Split Over Risk As Compute Buildout AcceleratesAIAug 7, 2026AI Pioneers Split Over Risk As Compute Buildout AcceleratesData Center Knowledge reported that Geoffrey Hinton, Fei-Fei Li and Andrew Ng disagreed at Ai4 over AI risk, jobs, openness and regulation, leaving infrastructure investors to plan capacity amid unsettled deployment rules.SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportTelco & ConnectivityAug 7, 2026SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportLight Reading reported that SpaceX urged the FCC to sunset High-Cost rural broadband subsidies, while rural telecom and electric-cooperative groups said LEO satellite coverage cannot replace terrestrial network support.OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutAIAug 7, 2026OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutBleepingComputer reported that OpenAI is rolling out GPT-5.6 Sol for paid ChatGPT users and GPT-5.6 Luna for Free and Go users, pairing unlimited free text chats with a new reasoning control and additional safeguards for users believed to be under 18.JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsCapital & PolicyAug 7, 2026JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsData Center Dynamics reported that JLL's EMEA Mid-Year Data Centre Report 2026 put FLAPD live capacity at 3.8GW, while the Middle East had 2.6GW in development paused and 13.8GW in planning.AWS Adds Persistent Runtime Instances For Production AI AgentsCloud & Data CentersAug 7, 2026AWS Adds Persistent Runtime Instances For Production AI AgentsAWS announced runtime instances for Amazon Bedrock AgentCore Runtime, adding managed infrastructure for multi-agent workflows, shared sessions lasting up to 14 days and GPU-supported production agent deployments.