Google has allowed account login using video selfies.
Learn how Google has implemented a new account login feature using video selfies, providing a safer and more convenient method of authentication. Details about the technology and the benefits of the new method.
Краткий пересказ от QRazy ИИ
- Google is launching a technology for identity confirmation through video selfies, requiring a short video of the face.
- The system checks the person's liveness by means of blinking and head turns, protecting against deception by deepfakes.
- The feature is not yet available to everyone, and gesture-based verification (HGV) has proven to be vulnerable to bypassing using static images.
Google is launching a new way to verify identity for some users. Instead of a password or code, the system will prompt users to record a short video of their face, which will then be compared with the new clip during the next login.
How facial login will work
During the initial setup of the feature, the user will need a mobile device with a camera and a Wi-Fi connection. They will have to place their face in a designated area on the screen and perform several head movements following the app's instructions. This way, the system will capture the face from different angles.
Google requires that facial features are clearly distinguishable. Sunglasses or headgear cannot be worn during the recording, and no other people should appear in the frame.
The next time the account owner requests access, they will be prompted to record another short video. The algorithms will match it with the video saved during the setup of the feature.
Merely resembling the previous video is not enough. The user will have to blink, turn their head, or perform some other quick action. Such checks are designed to confirm that a living person, rather than a photograph or a pre-recorded video, is in front of the camera.
The feature is not yet available to everyone
Google is gradually rolling out this new login method, so currently, only some account owners can take advantage of it. The availability of the feature can be checked on the g.co/signin-selfie page.
The company claims that users' videos are stored in encrypted form and are protected until used for identity verification. Additional security mechanisms, according to Google, are intended to prevent malicious actors from deceiving the system using deepfakes or other counterfeit materials.
However, the promises of enhanced security seem particularly intriguing in light of another Google experiment—the Hand Gesture Verification technology, or HGV, which the company has begun testing in reCAPTCHA.
Gestures instead of traditional CAPTCHA
HGV was created as an alternative to classic checks where users must identify traffic lights, pedestrian crossings, or other objects in images. Modern AI systems are increasingly adept at such tasks, prompting Google to test not the knowledge of the user but their physical actions.
During the verification process, the site visitor is asked to turn on the camera and perform a simple gesture: wave their hand in front of the computer or show an open palm. Machine learning models analyze the movement, natural physics, motor skills, and signs of a living person’s presence.
The idea was that such a check would be difficult to pass using automated tools. In practice, security researchers quickly found a serious vulnerability.
The verification was fooled by a regular photograph
To pass the HGV, no actual video recording of a moving three-dimensional hand was necessary. Researchers managed to deceive the system by showing it a prepared image of a hand performing the required gesture.
The physical webcam turned out to be unnecessary as well. With the help of virtual camera software, such as OBS Studio, a static photograph of a palm could be transmitted into the video stream. The system interpreted this image as a result obtained from a real camera.
Since the verification allows the use of a still image and a virtual video device, bypassing it does not require sophisticated tools. Experts point out that the process can easily be automated with a simple script.
The experience with HGV demonstrates that just having a camera does not guarantee reliable verification of a living person's presence. Therefore, the effectiveness of video self-login will depend not only on facial recognition but also on how well Google can detect fake video streams, static images, and recordings created by artificial intelligence.