Google's selfie sign-in: audit your account recovery
Google now lets you recover a locked account with a selfie video. Account recovery is the softest part of your identity perimeter — go look at yours.
Google shipped a new way back into a locked account: record a short selfie video, and if it matches the one you saved, you're in. Announced July 23, it's a backup recovery method, not a replacement for your password or passkey. The feature is fine. The reason to pay attention is that it puts a spotlight on the part of your security posture almost nobody audits — account recovery — which is where attackers have been going for years while everyone else hardened the front door.
What actually happened
Per Google's announcement, written by product leads John Gronberg and Claire Forszt, setup means looking at your camera and completing a few guided head movements to capture multiple angles. When you're locked out later, you record a fresh video and Google compares it against the stored one.
Google's stated safeguards:
- The guided movements act as a liveness check, aimed at defeating still photos and deepfake video.
- Videos are encrypted at rest and used only for sign-in unless you opt into more.
- You can delete the video from your account at any time.
- Rollout is gated — you check eligibility at
g.co/signin-selfie.
Google describes multiple layers of defense against impersonation, including standard suspicious-sign-in detection on top of the match itself. The announcement is written for consumer Google Accounts; it does not spell out how this interacts with Workspace admin policy, which is the first thing to check before you assume it applies to your business accounts.
Why it matters for your business
Your Google account is a master key. It resets your bank login, your Shopify admin, your domain registrar, your payroll. Nobody attacks your 32-character password — they attack the flow that exists specifically to let you in when you've lost it.
So take the twenty minutes. For every account that could reset another account, go look at what recovery methods are actually enabled right now. In most small businesses we've audited, the answers include: a personal phone number belonging to someone who left in 2023, a shared inbox three people can read, and a recovery email nobody has logged into since setup. Any one of those is a full compromise path that skips your MFA entirely.
On the biometric question specifically: a liveness-checked video is meaningfully harder to forge than an SMS code you can SIM-swap, and it's a real upgrade over a stale recovery email. It is also a face, which you cannot rotate after a breach the way you rotate a key. Our read is that it's worth enabling as a backup where the alternative is a weaker method — and worth skipping if you already have hardware keys enrolled and a documented recovery path. What matters more than which method you pick is that you know, today, what your list actually says. Go read it.
Key takeaways
- Google launched selfie video sign-in on July 23 as a backup account-recovery method, with guided head movements as a liveness check against deepfakes
- Videos are encrypted at rest, deletable at any time, and rollout is gated by an eligibility check at g.co/signin-selfie
- The announcement targets consumer Google Accounts — verify Workspace admin behavior before assuming it covers your business accounts
- Audit recovery methods on every account that can reset another one; stale phone numbers and shared inboxes bypass your MFA completely
Do you know every way into your business accounts? We map the recovery paths across your stack — who can reset what, from where, with which second factor — and close the ones nobody remembers setting up. Ask us for an access audit or see the systems we've hardened.
Sources: Google — Introducing selfie for sign-in, TechCrunch — Google will now let you sign in to your account with a selfie video.
- #account-security
- #identity
- #deepfakes
- #small-business
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Qualcomm's price increase hits your hardware budget
Qualcomm told customers of a double-digit price increase on chips shipped after September 1. The AI buildout is now repricing hardware that has nothing to do with AI.
Read it24,000 exposed BMCs leak hashes: close your IPMI port
A 2004 protocol flaw with no patch is handing out password hashes from 24,000 internet-exposed server BMCs. The fix is network exposure, not a firmware update.
Read it