Skip to main content
← Back to market wire
AI toolsArs Technica

Forgot your Google password? Now you can log in with a selfie.

Google's selfie videos can be used for account access, AI Avatars, and age verification.

Desk analysis

AI-assisted2 min read

Google has added a new wrinkle to the login ritual: a short video of your face, stored on its servers, can now stand in for a forgotten password. The mechanism is straightforward. Users record a clip during setup, Google encrypts it, and the biometric template becomes a recovery key for the account. Workspace users, children's accounts, and anyone in the Advanced Protection Program are excluded, which quietly signals where Google believes the friction is acceptable and where it is not.

The interesting part is not the feature itself. It is the convergence. The same facial capture pipeline that unlocks an account can, with minimal additional engineering, feed age estimation, identity verification, and the company's expanding portfolio of AI-generated avatars. Google is careful to say the stored video will not be repurposed without opt-in. That phrasing leaves the door open. The infrastructure for biometric identity is being laid down under the cover of a convenience feature.

For the labor market, the direct connection is thin. This is a consumer security update, not an HR or workplace tool. But the underlying trend matters to anyone whose professional identity lives inside a Google account. Biometric recovery shifts the security burden from something you know to something you are. That trade-off is familiar in enterprise settings, where hardware keys and platform authenticators have already made headway. Bringing it to the mass consumer market, where password reuse and SMS-based two-factor remain the norm, is a meaningful expansion of the attack surface and the privacy footprint alike.

The competitive read is equally quiet. Passkeys, the FIDO-based credential standard that Apple, Microsoft, and Google have all endorsed, were supposed to be the password-killer. They still are, for the forward-looking user. Selfie recovery is the safety net for everyone else, the people who never set up a passkey and never will. Google is hedging its bets: a cryptographic future for the prepared, a biometric fallback for the rest.

The privacy calculus has not changed, even if the packaging has. A video of your face, encrypted at rest, still represents a category of data that regulators, courts, and law enforcement can compel a company to hand over in ways a memorized password never could. Google knows this. The disclaimers on the setup page acknowledge it in the careful language of legal compliance. Users, drawn in by the promise of never being locked out again, are unlikely to weigh it. That gap between corporate clarity and consumer attention is where the real risk lives.