
Google wants your face to unlock your account: the unforeseen problem
Google has just launched a new account recovery system that promises to make things easier when you lose access to your mobile or computer: you just have to record a selfie video turning your head in several directions and send it to the company's servers. It sounds convenient. But behind this novelty lies a much more troubling trend that is capturing the biometric data of millions of users worldwide, according to xataka.com. Google is not the first to do this, nor will it be the last. But the question that no one dares to ask out loud is uncomfortable: what happens to your face if someone steals it?
When your face becomes a password
The logic behind the system is simple: if you lose your password, you change it in five minutes. If you lose your face, you have no other. Google promises that this information will be encrypted on its servers and that it will not use it for other purposes without your active consent. For now, the system will not work on Workspace accounts (Google's suite for businesses), children's accounts, or the Advanced Protection Program, designed for journalists and activists with sensitive information.
But Google is not alone in this race. Meta experimented years ago with facial recognition technology that allowed people to be automatically tagged in photos. In 2021, under pressure from regulators and privacy advocates, the company deleted more than one billion faces from its database and shut down the system.
Meta revives it after seeing promising results
The curious thing is that Meta has not given up on the idea. In October 2024, it resurrected the technology, this time focused on recovering hacked Facebook and Instagram accounts. By December 2025 it had become the standard recovery method, and the company claims it has improved the recovery rate of compromised accounts in the United States and Canada by more than 30%.
The results are clear. The problem is that every successful account recovery is also one more face in the database of a major tech company.
Age verification as a Trojan horse
If account recovery is the official gateway, child protection is the one opening quietly. In July 2025, Roblox began requesting selfie videos from teenagers aged 13 to 17 who wanted to unlock unfiltered chat. The company Persona estimates age based on facial features and, if unsure, requests an official document.
Discord announced in February 2026 that its more than 200 million monthly users would have to verify their age with a facial scan or document. The timing was unfortunate: the announcement came shortly after suffering a hack that exposed 70,000 identifications. The reaction was one of massive scepticism, and the company had to delay the rollout until the second half of 2026. Shortly after, a user demonstrated that the system could be fooled using a 3D avatar controlled with an Xbox or PlayStation controller.
TikTok combines its age verification by selfie with behavioural analysis (videos viewed, usage patterns) and has faced several lawsuits since 2021.
The dilemma with no easy answer
Major tech companies have a defensible argument: protecting minors and recovering hacked accounts are legitimate goals. The problem is that each such solution involves collecting and storing massive biometric data. And data, when valuable, ends up being stolen, sold or used for purposes its owners never imagined.
Are we comfortable exchanging our facial anonymity for a bit more convenience and security? For now, the decision is still yours. But each time you record that selfie video, it will be less so.
Source: xataka.com


