Google wants your face to be your backup password. I’d wait

Google now lets you use your face as a backup password. But with deepfakes and privacy risks, is it wise? Read why waiting is smart.

martes, 28 de julio de 2026 • 3 min read • Q2BSTUDIO Team

Autenticación facial: ¿riesgo o beneficio?

Google's announcement about using a 'video selfie' as an authentication method to access accounts has sparked intense debate in the cybersecurity field. The proposal is simple: you record a short video of your face, upload it to Google's servers, and when you need to recover your account or log in, you take another video that is compared to the original. If the algorithms determine a match, access is granted. On the surface, this is a step toward convenience, moving users away from insecure practices like password reuse. However, from a technical and business perspective, it is worth examining the implications closely before handing over such sensitive biometric data.

Facial biometrics are not new, but using them as a primary or backup authentication factor poses significant challenges. Artificial intelligence has advanced so rapidly that deepfakes —AI-generated videos that mimic a person's face and movements— are increasingly difficult to distinguish from real ones. Cybercriminals have already demonstrated the ability to digitally map a victim's face onto a body double who performs the necessary head turns to fool similar systems. Google claims to have protections in place and monitors for suspicious login signals, but the sophistication of attacks grows daily. For businesses, blindly trusting a single biometric layer can be a strategic risk.

At Q2BSTUDIO, as a software development and technology company, we understand that security is not a product but a continuous process. Our experience in cybersecurity and pentesting has taught us that any system, no matter how robust, needs constant evaluation against new threats. Biometric authentication must be complemented with other factors, such as hardware tokens or unique passkeys, which provide additional resilience without relying solely on facial data that, once compromised, cannot be changed like a password.

Beyond technical security, privacy is another delicate front. Google has indicated in the fine print that video selfies could be used to train its artificial intelligence models, improving facial recognition and age estimation. Although the company assures it handles data as described, the current regulatory context —with age verification laws driven by governments— adds uncertainty. How will those improvements be used? Will they be shared with third parties? Until clear and transparent regulation exists, prudence advises not to rush.

For organizations, the decision to adopt new authentication technologies should be based on a customized risk analysis. Not all companies handle the same type of data or face the same threats. That is why at Q2BSTUDIO we offer custom software solutions that integrate multi-factor authentication modules, advanced encryption, and real-time monitoring. Additionally, our platform on AWS and Azure cloud allows deploying secure and scalable architectures tailored to each client's specific needs.

Artificial intelligence, on the other hand, is not only a threat but also a defensive tool. AI agents can analyze behavior patterns to detect anomalous access, while Business Intelligence systems (such as Power BI) help visualize security metrics and make informed decisions. At Q2BSTUDIO we combine these capabilities to build resilient digital ecosystems.

Returning to Google's announcement, my recommendation is to adopt a 'wait and see' stance. It is not about rejecting innovation, but about giving time for the technology to mature and for best practices to be established. Meanwhile, traditional methods like passkeys and two-step authentication remain effective. Companies that already work with us know that we prioritize security without sacrificing user experience.

In summary, the human face is a powerful identifier, but it is also irrevocable. Handing it over to a large corporation without fully understanding the technical and legal consequences could be a misstep. Modern cybersecurity demands layers, redundancy, and above all, awareness. At Q2BSTUDIO, we continue to drive solutions that respect privacy and protect our clients' digital assets, integrating cloud, AI, BI, and custom development with an ethical and professional approach.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.