▲ 45 ▼ Forgot your Google password? Now you can log in with a selfie. (arstechnica.com) submitted 3 days ago by along_the_road@beehaw.org to c/technology@beehaw.org 23 comments fedilink hide all child comments
[–] smeg@feddit.uk 8 points 3 days ago (1 child) That's unlocking your phone, this is unlocking your entire Google account (e.g. on a new device) permalink fedilink source parent hideshow 2 child comments replies: [–] webghost0101@sopuli.xyz -1 points 3 days ago (3 children) Is that really that different? The article doesn’t go into any length to explain the technology. But assuringly its just an encrypted passcode created with an algorithm using measured face data. Crafting a secure reliable personal id based on pure visual appearance has been tricky and when this came out i disliked it but it was clearly a feat. What is the story here? Google trusting this technology? Them adding age verification to it? I am just confused what makes this enough of something to write/post it. permalink fedilink source parent hideshow 6 child comments replies: [–] Ooops@feddit.org 8 points 3 days ago* (1 child) Is that really that different? Conceptionally yes. You can refuse to unlock your phone with your face. You cannot refuse to allow Google to access your account (and thus your phone, too) with a picture of your face -no matter how bad the tech is- if Google implements this. permalink fedilink source parent hideshow 2 child comments replies: [–] TheButtonJustSpins@infosec.pub 2 points 3 days ago (1 child) You will have to set this feature up ahead of time if you want the option of regaining account access with a selfie later on. permalink fedilink source parent hideshow 2 child comments replies: [–] Ooops@feddit.org 2 points 3 days ago (1 child) for now... permalink fedilink source parent hideshow 2 child comments replies: [–] TheButtonJustSpins@infosec.pub 1 point 2 days ago I mean, I certainly hate Google, but I'm not sure I find it likely that they'll force every user to upload a video of themselves. I do think many will do it willingly, though. permalink fedilink source parent [–] jansk@beehaw.org 8 points 3 days ago (1 child) Very different, I would say. The security implication of authorising you on a new device is much more severe than logging you into a device you are already authorised against. permalink fedilink source parent hideshow 2 child comments replies: [–] smeg@feddit.uk 7 points 3 days ago Exactly, someone spoofing the biometrics to unlock my phone relies on them having physical access, whereas spoofing the biometrics on an account that can be accessed anywhere in the world is quite a bit bigger of a threat permalink fedilink source parent [–] TehPers@beehaw.org 3 points 3 days ago* Your phone stores the code on the device and does facial recognition locally. Apps on your phone only receive that data if they explicitly request your camera and perform the recognition themselves. This is vastly different than sending Google a video of your face that they save on their servers and use to analyze future selfie videos. But assuringly its just an encrypted passcode created with an algorithm using measured face data. From the article: Selfie videos can be used for login purposes, to verify your age for accessing certain account features, and to create an AI avatar. It's not just an encrypted passcode. permalink fedilink source parent
[–] webghost0101@sopuli.xyz -1 points 3 days ago (3 children) Is that really that different? The article doesn’t go into any length to explain the technology. But assuringly its just an encrypted passcode created with an algorithm using measured face data. Crafting a secure reliable personal id based on pure visual appearance has been tricky and when this came out i disliked it but it was clearly a feat. What is the story here? Google trusting this technology? Them adding age verification to it? I am just confused what makes this enough of something to write/post it. permalink fedilink source parent hideshow 6 child comments replies: [–] Ooops@feddit.org 8 points 3 days ago* (1 child) Is that really that different? Conceptionally yes. You can refuse to unlock your phone with your face. You cannot refuse to allow Google to access your account (and thus your phone, too) with a picture of your face -no matter how bad the tech is- if Google implements this. permalink fedilink source parent hideshow 2 child comments replies: [–] TheButtonJustSpins@infosec.pub 2 points 3 days ago (1 child) You will have to set this feature up ahead of time if you want the option of regaining account access with a selfie later on. permalink fedilink source parent hideshow 2 child comments replies: [–] Ooops@feddit.org 2 points 3 days ago (1 child) for now... permalink fedilink source parent hideshow 2 child comments replies: [–] TheButtonJustSpins@infosec.pub 1 point 2 days ago I mean, I certainly hate Google, but I'm not sure I find it likely that they'll force every user to upload a video of themselves. I do think many will do it willingly, though. permalink fedilink source parent [–] jansk@beehaw.org 8 points 3 days ago (1 child) Very different, I would say. The security implication of authorising you on a new device is much more severe than logging you into a device you are already authorised against. permalink fedilink source parent hideshow 2 child comments replies: [–] smeg@feddit.uk 7 points 3 days ago Exactly, someone spoofing the biometrics to unlock my phone relies on them having physical access, whereas spoofing the biometrics on an account that can be accessed anywhere in the world is quite a bit bigger of a threat permalink fedilink source parent [–] TehPers@beehaw.org 3 points 3 days ago* Your phone stores the code on the device and does facial recognition locally. Apps on your phone only receive that data if they explicitly request your camera and perform the recognition themselves. This is vastly different than sending Google a video of your face that they save on their servers and use to analyze future selfie videos. But assuringly its just an encrypted passcode created with an algorithm using measured face data. From the article: Selfie videos can be used for login purposes, to verify your age for accessing certain account features, and to create an AI avatar. It's not just an encrypted passcode. permalink fedilink source parent
[–] Ooops@feddit.org 8 points 3 days ago* (1 child) Is that really that different? Conceptionally yes. You can refuse to unlock your phone with your face. You cannot refuse to allow Google to access your account (and thus your phone, too) with a picture of your face -no matter how bad the tech is- if Google implements this. permalink fedilink source parent hideshow 2 child comments replies: [–] TheButtonJustSpins@infosec.pub 2 points 3 days ago (1 child) You will have to set this feature up ahead of time if you want the option of regaining account access with a selfie later on. permalink fedilink source parent hideshow 2 child comments replies: [–] Ooops@feddit.org 2 points 3 days ago (1 child) for now... permalink fedilink source parent hideshow 2 child comments replies: [–] TheButtonJustSpins@infosec.pub 1 point 2 days ago I mean, I certainly hate Google, but I'm not sure I find it likely that they'll force every user to upload a video of themselves. I do think many will do it willingly, though. permalink fedilink source parent
[–] TheButtonJustSpins@infosec.pub 2 points 3 days ago (1 child) You will have to set this feature up ahead of time if you want the option of regaining account access with a selfie later on. permalink fedilink source parent hideshow 2 child comments replies: [–] Ooops@feddit.org 2 points 3 days ago (1 child) for now... permalink fedilink source parent hideshow 2 child comments replies: [–] TheButtonJustSpins@infosec.pub 1 point 2 days ago I mean, I certainly hate Google, but I'm not sure I find it likely that they'll force every user to upload a video of themselves. I do think many will do it willingly, though. permalink fedilink source parent
[–] Ooops@feddit.org 2 points 3 days ago (1 child) for now... permalink fedilink source parent hideshow 2 child comments replies: [–] TheButtonJustSpins@infosec.pub 1 point 2 days ago I mean, I certainly hate Google, but I'm not sure I find it likely that they'll force every user to upload a video of themselves. I do think many will do it willingly, though. permalink fedilink source parent
[–] TheButtonJustSpins@infosec.pub 1 point 2 days ago I mean, I certainly hate Google, but I'm not sure I find it likely that they'll force every user to upload a video of themselves. I do think many will do it willingly, though. permalink fedilink source parent
[–] jansk@beehaw.org 8 points 3 days ago (1 child) Very different, I would say. The security implication of authorising you on a new device is much more severe than logging you into a device you are already authorised against. permalink fedilink source parent hideshow 2 child comments replies: [–] smeg@feddit.uk 7 points 3 days ago Exactly, someone spoofing the biometrics to unlock my phone relies on them having physical access, whereas spoofing the biometrics on an account that can be accessed anywhere in the world is quite a bit bigger of a threat permalink fedilink source parent
[–] smeg@feddit.uk 7 points 3 days ago Exactly, someone spoofing the biometrics to unlock my phone relies on them having physical access, whereas spoofing the biometrics on an account that can be accessed anywhere in the world is quite a bit bigger of a threat permalink fedilink source parent
[–] TehPers@beehaw.org 3 points 3 days ago* Your phone stores the code on the device and does facial recognition locally. Apps on your phone only receive that data if they explicitly request your camera and perform the recognition themselves. This is vastly different than sending Google a video of your face that they save on their servers and use to analyze future selfie videos. But assuringly its just an encrypted passcode created with an algorithm using measured face data. From the article: Selfie videos can be used for login purposes, to verify your age for accessing certain account features, and to create an AI avatar. It's not just an encrypted passcode. permalink fedilink source parent