Google Introduces Selfie‑Video Recovery to Unlock Locked Accounts
What Happened — Google announced a new account‑recovery option that lets users record a short selfie video to verify their identity when they’re locked out. The video‑based method sits alongside existing recovery channels such as email or phone‑SMS codes.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a shift toward biometric‑based recovery, raising the bar for access‑control policies that SOC 2 auditors will scrutinize.
- Provides an additional evidentiary artifact (the recorded video) that can be logged and retained for incident‑response audits.
- Highlights the need to update IAM controls, user‑training, and documented recovery procedures to stay aligned with the SOC 2 Access Controls criteria.
Who Is Affected – Cloud‑based SaaS platforms, identity‑as‑a‑service (IDaaS) providers, and any organization that relies on Google Workspace or consumer Google accounts for employee authentication.
Recommended Actions – Review your current account‑recovery workflow against SOC 2 CC6.1 (Logical Access) and CC6.2 (Identity Management). Map the new biometric option to your access‑control policy, capture audit‑ready logs of recovery events, and update user‑training materials to cover the selfie‑video process. Source: The Hacker News
Technical Notes – The feature uses on‑device video capture and AI‑driven facial‑liveness detection; no new CVEs are disclosed. It augments existing multi‑factor recovery channels without replacing them. Source: same