In a fresh development, this week, Google unveiled you can start using it as a form of authentication—a way to get into your account. How much is your face worth to you?
In a fresh development, it’s kept on file for reference. In the future, if you want to log in or recover your account, you take a fresh video selfie and Google compares the two. If its algorithms believe they’re a match, you get into your account. Here’s how it works: You take a “video selfie” of yourself and upload to Google’s servers.
According to the latest update, want this newsletter to come directly to your inbox? Sign up on our website! Welcome to Safe Mode, your weekly report for pressing security and privacy news—and what steps to take next.
Industry observers note that but I don’t recommend giving Google a copy of your likeness just yet. On the surface, this move fits with making authentication easier, so that people don’t resort to weak strategies like reusing passwords.
Industry observers note that cybersecurity experts have already seen how AI enables the faking of other people’s appearances in real time. Attackers can digitally map their target’s face onto a body double, who then performs the required head turns (and other movements) in similar authentication checks. My main security concern: How rapidly AI is improving at fooling such authentication systems with deepfakes.
As part of the ongoing story, when asked, Google said it has protections in place against this kind of hack, and that it is “constantly adapting to fresh threats to improve security across our products.” Google also said it monitors for signals that indicate a suspicious login attempt.
Industry observers note that google notes deep in a help file that it will use video selfies to help train its AI to improve facial recognition and age estimation if so permitted. Even if you trust Google to treat the data strictly as described, we don’t know yet how such improvements will intersect with the recent waves of government-mandated age verification laws. Given the size and strength of Google’s security team, this explanation might be enough—were it not for my main privacy concern.
As part of the ongoing story, tried-and-true methods of authentication and recovery still work—passkeys require little effort, for example. I wouldn’t say to automatically reject all fresh security advancements. But in this case, a wait-and-see approach doesn’t hurt for now. Until we all have a better sense of how major tech firms will use our face data, you don’t lose anything by being more hesitant to share that info with them.
The report highlights that openAI’s models showed us a glimpse into a Skynet-style future…and that was amid already less than great news about Windows 10 and yet more data leaks. Big news in cybersecurity is often not comforting, and such was the case this week.
As part of the ongoing story, turns out my colleague Sam did as well, and he published a great list on the ways you might be unintentionally oversharing online—and how to fix them. Privacy is on my mind this week, thanks to Google and its fresh video selfie authentication method.
In a fresh development, the reminder to check my app permissions. Sometimes, I forget to go back and check which might have access to my location and photos. I took some satisfaction yeeting them off my phone (as the kids say). My favorite tip?
According to the latest update, since joining the team in 2016, she’s written about CPUs, Windows, PC building, Chrome, Raspberry Pi, and much more—while also serving as PCWorld’s resident bargain hunter (#slickdeals). Currently her focus is on security, helping people understand how best to protect themselves online. Her work has previously appeared in PC Gamer, IGN, Maximum PC, and Official Xbox Magazine. A 15-year veteran of technology and video platform releases journalism, Alaina Yee covers a variety of topics for PCWorld.