Google really, really wants your biometrics

Google will now let you sign into your accounts using a selfie video. Google says this is so that you can sign in if you forget your password, but that seems a bit thin—I’d say that most people let their iOS or Google password manager take care of passwords.

It seems much more likely to me that this is a way for Google to harvest some sweet biometrics from its users, which it can then associate with your Google account, and all the other data Google has on you.

The setup involves using your phone to capture a scan of your head. Google calls it a “selfie video,” but it’s much more like the in-depth 3D scan you perform to use Apple’s FaceID. The big difference is that Apple stores the scanned data on the phone, in the secure enclave where nobody can access it. Google, on the other hand, stores the resulting video on its servers.

Just to be clear, that’s a high-quality, standardized video scan of your face. This could be useful for training Google’s LLMs. It could also be used to feed a face-recognition database that could be used with, say, Ring cameras to help the police track people wherever they go.

That’s it for faces. But Google has also come up with a way to scan your hands, in equally rich detail. Hand gesture verification is an addition to its reCaptcha tech, and the sales pitch this time is that you can verify that you are human by waving your hand in front of your computer’s camera.

How deep is the scan? Google says that “The video is processed to extract hand landmark data, which includes 21 hand-knuckle coordinates.” So pretty deep.

Biometrics are a terrible ID system. You cannot change your face or your fingerprint, like you can with a password. Once it’s stolen, it’s stolen. Giving up your face or your hands for such trivial uses as avoiding a password, or not using a captcha, is insane. And once those scans are in a system that readily shares data with law-enforcement, it’s not coming back out.