ZDNET56%
Google will let you upload a video selfie to recover your account - but should you? 31%
By Jada Jones51%
7/23/2026, 10:00:48 AM
BS Summary: This article contains 23 faulty reasoning types, including Negativity Bias, Appeal to Authority, and Ambiguity (Equivocation), with Availability Heuristic as the most egregious example at 13.5% saturation with 175 hits. Analysis detected 1,581 faulty-reasoning hits from 1,292 analyzed words, generating a BS Score of 40.5% and a BS Rank of 31% (14,692 of 21,176 articles). This article is better (less manipulative) than 69.40% of the article peer group.
Google's new account recovery option prompts users to upload a selfie to prove their identity.
Here's what to know.
Google's selfie video sign-on helps users recover their accounts.
You should know how your biometric data is stored and used.
Google asserts that uploaded biometric data is never shared.
Google's introducing a new way to recover your account, and all you need is your face.
Users can upload a selfie video to regain access to their accounts if they've been locked out or are away from their usual device, the company said Thursday.
Also: Ernst & Young breach exposes client tax data - find out if you're at risk and what to do next
Uploading a selfie video to remedy an extremely stressful situation sounds simple enough, and in a blog post, Google promised that users' selfies are "encrypted at rest, meaning it's securely stored even when it's not being used."
Still, as we offer more of our permanent biometric data to tech companies, I asked security experts what users should know and consider before providing face scans to them.
Avoiding deepfakes
Among experts, the consensus is that uploading a live video of your face is generally more valuable for identity verification than still photos, because motion, depth, lighting changes, and microexpressions can confirm humanity.
However, some experts are concerned that video verification systems could be tricked by deepfakes.
Hackers can use generative AI to alter photos of faces and official documents, making them appear realistic.
Deepfakes are a genuine concern, and the technologies used to create them are more advanced than many people realize.
Ricardo Amper, founder and CEO of Incode Technologies, an identity verification and fraud prevention company, said that while a video is more valuable than a photo for verification, motion alone is not proof of life.
Also: An AI agent breached Hugging Face before an AI defender caught it: What users should do next
Amper said that hackers can create AI-generated faces capable of blinking, turning their heads, and responding to prompts with motion, and that human ability to distinguish a real person from a deepfake is declining.
"The more sophisticated attacks don't even try to fool the camera," he said.
"They bypass it entirely, injecting synthetic video directly into the data stream through virtual cameras and tampered or emulated devices."
Chris Boehm, field CTO at Zero Networks, a cybersecurity provider, recalled the massive deepfake scam that swindled British design and architecture firm Arup out of $25 million in 2024.
A company finance worker was duped into joining a conference call with deepfake renders of his colleagues, and was convinced to complete several wire transfers.
Though the worker was suspicious of the emails leading up to the meeting, his doubt was assuaged by the realistic deepfakes.
Also: I enabled Android's new security feature that detects fake cell towers - here's why
Your Google account may not be worth this much money, but it's possible for bad actors to use advanced technologies to access your information and that of thousands of others.
"Deepfakes have moved past the novelty stage," Boehm said.
"They're now a fraud tool with a track record."
Multiple methods are key
Since deepfakes pose such a serious threat to video verification methods, experts agree that multiple verification tools are required to mitigate their impact.
Amper said that these sophisticated defense tools use more than an image's pixels to determine realness by reading a device's finer details.
Google didn't detail exactly how or which technologies it uses to differentiate between real people seeking to recover their accounts and bad actors using deepfakes, as doing so would be a security concern.
However, Google's blog post said it uses its standard security practices, along with deepfake detection, to flag suspicious activity, including device location, time of attempted login, browser settings, and IP address.
"The most sophisticated models today can determine from a single image whether a face is real, because they don't judge the pixels alone -- they read the device itself: accelerometer and sensor data, camera integrity, and dozens of other signals that confirm this is a genuine selfie camera capture and not something injected into the stream," Amper said.
Also: I tested a 4TB quantum-resistant USB drive - but you don't have to spend $3000 for this much security
Chris Bevil, director of global cyber resilience and AI, at Commvault, a data protection company, has similar sentiments.
Bevil said that video verification is a great starting point, but there are other methods of confirmation beyond movement to verify authenticity, since hackers can inject synthetic video and fool simple defense systems.
"A video provides liveness and behavioral signals that a static photo cannot," he said.
"The key is layering it with device recognition, location, behavioral analytics, and additional verification when something does not align."
Google's blog post says the company uses multiple security methods to combat deepfakes and impersonation attempts, such as comparing your uploaded selfie video with another photo and requiring you to perform real-time movements to verify the video is genuine.
Also: Don't let an AI chatbot pick your password, ever
According to Tony Anscombe, chief security evangelist at ESET, a cybersecurity provider, it's imperative that companies use multiple authentication methods to deter hackers, whose tactics are evolving rapidly.
"The issue is whether one single method of authentication is being used to verify identity as opposed to multiple combined methods that would significantly reduce the overall risk of fraud," he said.
"Using multiple methods and even randomizing the methods used would disadvantage the attacker significantly."
Privacy is paramount
The same experts warned that people should not be liberal with handing out their biometric data for the sake of digital convenience; unlike a password, your face, iris, or fingerprint can't be changed if they're involved in a data breach.
To stay safe, users should know how their biometric data is stored, used, protected, and deleted.
Google's privacy policy states that if users choose to share biometric data, Google may use it for product development studies.
Also: Microsoft patches record 570 Windows security bugs with two exploited zero days - update now
Google's selfie video blog post states that users' selfie videos are recorded and stored securely, can be deleted at any time, and that users can opt out of sharing them with Google for "additional purposes."
Google confirmed to ZDNET that users' selfie videos are stored securely on the server, and that if users choose to share their selfie videos for Google's "additional purposes," one of those purposes may be improving the company's verification methods.
The experts I sought out agreed that on-device biometrics, such as fingerprint and face ID, are a more secure option for everyday use, since the data stays on the device rather than being transmitted for remote verification.
Also: Is that QR code a trap?
How to spot quishing scams before it's too late
However, Google's selfie video option seems to be a last-ditch attempt, made especially for people who are locked out of their account and are nowhere near their usual devices.
If you're particularly wary of sharing more of your biometric data with Google in this manner, Google's recovery contacts option might be a better fit.
Google allows users to add up to 10 people as recovery contacts, who should be people you trust.
Adding these contacts can help you recover your Google account if you're locked out.
Once you call on a recovery contact, you'll receive a unique code, and your contact will receive a prompt that you're requesting their help.
You'll need to contact them within 15 minutes, or the code expires.
Once your contact enters your code, you'll have access to your account.
Speakers
6speakers39%attributed speech782writer words
Voice mapSelect a segment to jump to its words
Selected voice
100%flagged-word coverageChris Boehm
93 attributed words18% of attributed speech72% writer coverage
Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.
Loading…
Loading…
Loading…
Analysis
Hover over highlighted words in the article to view the associated bias or fallacy analysis.