
Google has rolled out a new way to sign into accounts that replaces passwords with a selfie video. The feature, currently in testing, lets users verify their identity by recording a short clip of their face, which is then compared to an encrypted version stored on Google’s servers. This approach aims to provide an additional layer of security and convenience for users who struggle with traditional password-based authentication methods.
How it works
Eligible users can set up the selfie video by heading to their Google account settings under Security & sign-in > How you sign in to Google > Selfie video. The setup process guides users through recording a clip, with instructions to avoid sunglasses, hats, or masks, as these can interfere with the facial recognition technology. If the device lacks a camera, a QR code can transfer the process to a smartphone or other camera-equipped device.
Once stored, the selfie video becomes a fallback option for signing in from other devices. Google’s system prompts users to move their heads during verification to prevent spoofing with photos or videos. The company claims that multiple security layers can detect deepfakes.
Not all accounts qualify for the selfie video feature. Child accounts, Google Workspace accounts, and those in recovery mode are excluded from the feature, as these accounts often have additional security requirements or restrictions.
Related: EU fines Google $1bn over search bias
Why passwords are under fire
Tech companies have spent years pushing alternatives to passwords, which are often weak or reused. A 2023 report found that 123456 remained the most common password globally, despite its obvious vulnerabilities. Hackers can brute-force simple passwords in minutes, and even complex ones are at risk if leaked in data breaches.
Passkeys—biometric or PIN-based authentication tied to specific devices—have gained traction as a more secure option. Google’s selfie video method doesn’t replace passkeys but serves as a backup when users lose access to their usual devices or recovery contacts.
Security experts still recommend multi-factor authentication (MFA) for most users, preferably using authenticator apps rather than SMS codes, which attackers can easily intercept.
For now, the selfie video feature remains in limited testing. If it proves reliable, it could join passkeys and MFA as another tool in Google’s expanding arsenal of password alternatives.
