Google Adds Selfie Video As a Log-In Option (engadget.com) 54
An anonymous reader quotes a report from Engadget: You'll now be able to use selfie videos to log into your Google account. It has long been possible to log into Google using your face, via your phone's face unlock or if your passkey login uses biometrics for verification. This is yet another option to get into your account using your face to authenticate your identity, which could be especially useful if you don't have access to the phone or computer you typically use or if you got locked out of your account and none of the other log-in options are working.
[...] Google will ask you to turn your head in certain ways during the verification and every time you use the option to log in. The company says it's to fend off impersonation attempts, such as deepfake videos, and prove you're currently in front of the camera. It will, of course, have to save your selfie video and use it for comparison for future logins.The company says it will encrypt your video and only use to help you sign in, but if you ever change your mind, you can delete it from your Google account. It's worth noting the option is currently unavailable for Workspace accounts, child accounts and those enrolled in Google's Advanced Protection Program.
You can set it up and give it a try at g.co/signin-selfie.
[...] Google will ask you to turn your head in certain ways during the verification and every time you use the option to log in. The company says it's to fend off impersonation attempts, such as deepfake videos, and prove you're currently in front of the camera. It will, of course, have to save your selfie video and use it for comparison for future logins.The company says it will encrypt your video and only use to help you sign in, but if you ever change your mind, you can delete it from your Google account. It's worth noting the option is currently unavailable for Workspace accounts, child accounts and those enrolled in Google's Advanced Protection Program.
You can set it up and give it a try at g.co/signin-selfie.
Google Authenticator to sync TOTP keys (Score:2)
If you're using your Google Account to sync your TOTP keys across devices using Google's Authenticator app, you need some way to sign in to Google for that.
Re: (Score:2)
And if you keep your passwords on post it notes on the fridge, you might as well grab a beer when you're there; how's that relevant, though? Google Authenticator is just one of the options and you can even export your GA TOTP keys to another app, or a wholly isolated device.
Re: Google Authenticator to sync TOTP keys (Score:2)
Who's that insane? Hiding 2FA behind what 2FA is supposed to protect!
Print that on paper an put it in a physically safe place.
Re: (Score:2)
If you're using your Google Account to sync your TOTP keys across devices using Google's Authenticator app, ...
... then you're doing it wrong (IMO).
The TOTP apps tend to hide the secret key a bit too much. The initial QR code used to set them up contains the secret key, so why can't they provide an easy option for users to view and backup the secret?
FWIW, there's a simple command line tool for TOTP:
CURRENT KEY: oathtool -b --totp "$SECRET_KEY"
NEXT KEY: oathtool -b --totp "$SECRET_KEY" --now "+30 seconds"
Works with any TOTP secret. When setting up a new TOTP key, there's usually some option to get the actual key rath
Re:remember totp? (Score:5, Insightful)
Re: (Score:1)
TOTP has the huge disadvantage of being a pain for non tech folk to understand and use. The selfie-video is less secure than TOTP, but more secure than SMS texts. Passwords are reused between different sites.
If you are happy with your security, keep using it. And if you have a friend or relative who use ones password for every site, switch them to the video.
Re: (Score:2)
Why would Google offer a completely anonymous service?
People keep complaining about Gmail spam. I've never seen any, but let's assume they are not lying. Wouldn't a service like Gmail want to validate who users are, and perma ban ones who abuse their service for spamming?
If you want anonymity you are looking in the wrong place.
Re: (Score:1)
What anonymity?
"All your information are belong to us"
The only way to be anonymous would be to never go online at all, never have a cell phone, never have a state ID or SSN, never have a bank account, et cetera. And, they could probably still find you (global surveillance satellites that can read the pilot's license number on a housefly's back).
Back to TFA... how many times will you have to try the video selfie thing before it works?
Re:remember totp? (Score:4, Interesting)
Bingo.
Google demands phone numbers to log into accounts now if you change your IP address for some reason and haven't logged in in a while. Phone numbers that clearly have *nothing* to do with security as you don't have one associated with your account.
They're a surveillance company now, not an ad-supported general Internet services company, pretty much moving to a Flock-like business model. Anyone who doesn't have a Google exit plan needs to figure one out. And anyone who does... needs to seriously considering executing.
Re: (Score:2)
If I hadn't already migrated away from Gmail a few months ago, this would have been the thing that made me. Not acceptable on any planet.
Re: (Score:2)
TOTP and passkeys also have the huge disadvantage of being useless when you don't have access to the saved secret. So they need to solve the case of dead device needing to be replaced.
Multiple devices with a wallet/password vault outside their ecosystem that can save TOTP/passkeys is a more secure solution.
However since they want to make a solution within their system and isn't reasonable to require multiple devices, there are not many good solutions outside of the auth factor being something that proves wh
Re: (Score:2)
I don't get it (Score:1)
What's wrong with passwords. I can type mine in while I'm driving. I sure as hell can't scan the phone 2 orbits around my head under ideal light conditions in order to satisfy the face/selfie unlock crap.
But honestly, why do we have accounts at all? 99% of the crap we do on our phone doesn't actually need it. Forcing people to log into web sites in order to post seems like a good idea, but really it's still full of bots and sock puppets. Tear off the bandaid and lets all just go fully anonymous. If I don't
Re: (Score:2)
Because most people have things like email and photo storage that they really don't want to lose access to.
Re: (Score:2)
I don't. I haven't signed into a Google account on my phone in years. I run Lineage without Gapps or even microG stubs and just use F-droid.
https://battlepenguin.com/tech... [battlepenguin.com]
Re: (Score:1)
Because... gotta have Facebook and Twitter/X (still, calling it X sounds like I'm talking about a porn site), gotta have at least two emails (that you remember), gotta have all the online movie and game sites (because physical discs are going obsolete because "everybody has 500MB/s download speeds"), you get paid electronically, you do your taxes online, you file for Social Security online.
There is no being truly anonymous anymore... you leave breadcrumbs everyplace you go, not to mention the fact that all
Not to be outdone (Score:5, Funny)
Facebook has added a Dick Pick login option.
Re: Not to be outdone (Score:3)
I thought snapchat patented that.
Re: (Score:2)
So Anthony Weiner was just trying to log into his accounts?
Surely safe! (Score:2)
I am sure there is no way to out another phone in front of a locked phone and play a video with a face.
And in the era of the AI making such a video from a photo should not be really difficult.
Re:Surely safe! (Score:4, Insightful)
I am sure there is no way to out another phone in front of a locked phone and play a video with a face.
I'm making an assumption, but TFS notes that it directs you to look in various directions. If it varies what directions it asks for, that can be used to ensure it's not simply a prerecorded video.
Though a live AI generated video for it would entail too much lag at the moment, that still seems like a huge weakness. Even worse, if they're saving these videos, then THEY can easily create a video of your login motions in any order. It's essentially enough info to build a full 3d model of your face. That means they could use it to login to OTHER sites on your behalf, unlike locally saved and verified biometric data.
We promise we're not... (Score:2)
We promise we're not using these videos for weird sexual purposes. Well, other than Steve that sick freak.
5-dollar wrench hack (Score:2)
That's not the worst part (Score:5, Insightful)
The worst part isn't that now anyone who can get a few pictures of your face off the Internet can log in on your account. The worst part is that you can't recover from it. You can't change your face so once they've got it all you can do is disable this feature completely, and hope Google doesn't re-enable it.
Re: (Score:2)
As it points out in the summary, it requires you to turn your head on command, to prevent people using photos of you.
Google has form here. Their Pixel phones with face unlock cannot be fooled by photos, or even videos of people's faces. The only thing that works is an identical twin.
Re: (Score:2)
>As it points out in the summary, it requires you to turn your head on command, to prevent people using photos of you.
Yeah, no way you could use a real-time avatar program to fake that. Last time I checked, the cheap ones couldn't do profiles... but for just how long do you think that will remain true?
Re: (Score:2)
I'm sure someone will publish a proof of concept if it really is so easy, but if they are using the same tech as the Pixel phones (which don't have IR, just ordinary cameras) then so far nobody has been able to get past it with a real time avatar app.
Re: (Score:2)
For phone use, it is probably a lot easier to get into the phone some other way. Especially if you just want to reset a stolen phone to sell it in some country where the government does not care and hence the Telcos will accept devices on the list of stolen ones.
Re: (Score:3)
For phone use, it is probably a lot easier to get into the phone some other way. Especially if you just want to reset a stolen phone to sell it in some country where the government does not care and hence the Telcos will accept devices on the list of stolen ones.
No, if you don't have the LSKF (Lockscreen Knowledge Factor, i.e. PIN/PatternPasscode) for a Pixel, you can't reset a stolen device, not since Android 15. The anti-reset feature (called "Factory Reset Protection") dates back to 2014, but it had some holes, which I fixed in Android 15.
The way it works is that there's a "boot secret" stored in TrustZone (TZ) and in a directory in /data. The device always boots in the "I'm stolen" state, and until the correct secret is sent to TZ, it remains in that state.
Re: (Score:2)
Yo are apparently easy to convince as long as the ones manipulating you use big words.
Re: (Score:2)
Yo are apparently easy to convince as long as the ones manipulating you use big words.
What have "they" convinced me of?
Re: (Score:2)
The anti-reset feature (called "Factory Reset Protection") dates back to 2014, but it had some holes, which I fixed in Android 15.
Actually I mostly fixed it in Android 14. The solution architecture was the same as described above, except that TZ's role was played by a low-level userspace daemon instead. This means that "I'm stolen" mode on Android 14 doesn't disable KeyMint, and it opens up more userspace/kernel attack vectors. The reason for doing this is because leaving it in userspace for a year gave me a chance to flush out any corner cases I had missed. Privileged low-level flashing tools could bypass it -- which is not true
Re: (Score:2)
Yeah, no. Turning your head on command? I see a future where a side view and a head shot is all you need, and AI will generate the head turning from those. Then you'd just loop a video of the head in each position to simulate li
Re: (Score:2)
Let us know when this future arrives and can beat their system.
Given how careful Google has been with account security, with zero mass hacks ever, unlike say Apple where their incompetence was responsible for a huge crime wave of stolen iCloud photos, I would be very surprised if this wasn't secure.
Re: (Score:1)
The thing that sucks is, for people who wear glasses, those video selfie things usually want you to take your glasses off... without my glasses on, and the phone held far enough away that my head fits in the box, I can't see what directions it's telling me to turn my head in.
(Trying to set up an account on CoinBase was half an hour of just that step in the KYC process)
Re: (Score:2)
Yes, as if nobody could feed some photos into a genAI chatbot and have it generate a video of that face performing those actions on command. Right, nobody could possibly do that, not in our lifetime... wait a minute, I'm getting an update from the studio...
Re: (Score:2)
Indeed. Pretty much true for all biometrics that can easily be stolen. Like, you know, the ones that store your biometric data in a cloud.
Training AI (Score:5, Informative)
Bad idea... (Score:3)
VERY bad idea.
I thought passkeys were the future? (Score:2)
... subject says it all.
Maybe rename the article to "Google admits passkeys are unusable for normal people."
Re: (Score:2)
Ah, yes, passkeys. The magic that will likely screw you over. Funny how basically no actual security experts talk about them, except to point out they are not that good.
Data harvesting? (Score:4, Insightful)
They sure seem to be keen on collecting a lot of facial and related data on individuals, examples being this, and the upcoming registration of Android app developers [keepandroidopen.org] which requires Gov ID for each one.
Yeah, I also don't use fingerprint or facial recog on any of my other devices. That's like leaving post-it notes with your password on it pasted on every glass and door handle you use, or tattooing it on your forehead and walk around in public. In the stupid way I see things. (Also, I have quite faint fingerprints - presumably congenital - and every damn electronic fingerprint scanner takes multiple tries. Paper and ink seem to work fine though.)
Re: (Score:2)
Indeed. It looks like they are trying to get as much face data as they can. At the same time, this is not something that will increase security meaningfully for more than maybe a few weeks. Hence they are likely lying about their intentions.
Hmm. Does Google have some "smart" glasses with facial recognition in the pipe?
Dropping MFA and using generic access (Score:4, Insightful)
We all know that MFA wants to have at least two of these: Something you know, something you have or something you are.
This will reduces it to one, something you are, and then a real insecure version of it. As this works from any device, it is relatively simple for an attacker far away to use a devise setup for deep-fake injection to gain access.
How does this differ from apps using fingerprint or face recognition? Note that the biometric data is stored on your phone and that the authentication is done on that specific phone. Not somewhere else in the cloud. This means you both need that specific device and your face. It is much less likely that an attacker has remote access to your phone AND is able to inject a deep-fake into the path of your camera.
In my opinion, this is a really bad idea. Both from a security perspective and by providing Google with your biometric information.
Re: (Score:2)
Yes. Only using only biometrics is _really_ the dumbest version of 1FA. And Google will know that. I guess they are just putting on a show.
Re: (Score:2)
however what they don't tell you (Score:2)
I give it 1-2 months (Score:2)
Then this will also be broken routinely. If it takes that long.
Terrible Idea (Score:2)
Great idea! (Score:2)
No thanks (Score:2)
File it under: Train your AI on me (Score:2)