{"slug": "everyone-knows-your-face", "title": "Everyone Knows Your Face", "summary": "Google and Meta both launched facial recognition features this week, with Google introducing selfie video sign-in for account recovery and Meta launching Facebook Verified to confirm users are human, not AI-generated scammers. The features share a common approach of using biometric data to solve trust online, but critics note that opting in can train Google's facial recognition systems and that Meta's free badge only confirms a user is not an AI, not their actual identity.", "body_md": "This week, within days of each other, Google and Meta both shipped facial recognition as the answer to trust online. Turns out you don't need a bar stool and a theme song for everybody to know your face anymore — you just need a Google Account or a Facebook profile. Google launched\n\n[selfie video sign-in](https://techcrunch.com/2026/07/23/google-will-now-let-you-sign-in-to-your-account-with-a-selfie-video/): record a short video of yourself once, and if you ever get locked out, a fresh selfie against that saved clip gets you back into your account. Meta launched\n\n[Facebook Verified](https://www.engadget.com/2222353/meta-launches-facebook-verified/): hand over a facial-recognition selfie, get it checked against your existing profile photos, and earn a badge that tells other people you're a real human and not an AI-generated scammer.\n\nDifferent problems on paper — account recovery versus catfish detection — but the same instinct underneath: when trust online breaks down, the reflexive fix at two of the biggest companies on the internet is the same sentence. *Give us your face.*\n\nI'm not here to pretend either company invented villainy this week. Account recovery is a real problem, and so is the flood of AI-generated fake profiles both companies are actually responding to. What's worth sitting with is why *this* is the fix everyone reaches for now, whether it's even good at the job, and what it costs to hand over.\n\n## The Same Playbook, Twice\n\nI've written this exact post before, about a different Google product wearing a different name. Back in April I covered\n\n[YouTube's AI avatar feature](https://blog.ppb1701.com/smile-for-the-algorithm) — record a selfie, read a few prompts, and Google builds a photorealistic digital double of your face and voice for Shorts. Safe, consensual, deletable, they said. Underneath, Google was collecting a clean, user-verified biometric sample and tying it to the most complete identity profile a company has ever built on a person. Selfie sign-in is the same architecture moved from \"fun creative toy\" to \"core account security\" — a much quieter on-ramp to the same outcome, since nobody scrutinizes a security settings menu the way they scrutinize a flashy new AI feature.\n\nThe messaging matches too: encrypted at rest, deletable anytime, used only for sign-in — unless you opt in to something else. That \"something else\" isn't vague by accident. The Register got Google on record about what it actually covers:\n\n[training Google's own facial recognition and age-estimation systems](https://www.theregister.com/security/2026/07/23/if-you-get-knocked-on-the-head-and-get-all-your-devices-stolen-and-have-amnesia-google-will-let-you-back-in-with-a-selfie/5276669). So opting in doesn't just share your data — it makes your face training material for the next generation of the same verification tech.\n\nMeta's version fits an even more specific playbook I mapped out in\n\n[Always On. Always Watching.](https://blog.ppb1701.com/always-on-always-watching): whatever protects a company from liability ships loud, with a press release and a friendly free badge; whatever expands what it can collect ships quiet, opt-out, buried under a menu. Facebook Verified is textbook loud — free, publicized, framed entirely around protecting\n\n*you* from scammers. Meta is also careful to state, in its own announcement, exactly what the badge doesn't do: it\n\n[confirms you're not an AI, not that you are who you claim to be](https://appleinsider.com/articles/26/07/24/facebook-verified-is-here-so-you-can-tell-if-your-new-friend-is-really-an-ai). That's a narrower promise than most people will read into a \"Verified\" checkmark, and it's worth remembering exactly that specific, bounded claim the next time the feature quietly expands. It's probably not an accident that the free badge stays this narrow, either — Meta already has a paid tier, Meta Verified, sitting right next to it. Give away real identity verification for free and there's less reason for anyone to pay for the fuller version. Keep the free badge to \"not an AI\" instead, and the subscription still has somewhere to go — especially for the accounts Meta actually wants to keep invested in the platform: creators and public figures with an audience worth pulling in and keeping there.\n\nWhich it will, because Meta has a documented habit of doing exactly that. Ask how many times Meta has said a tool \"only\" does one narrow thing, and look at what happened to the Meta Pixel. It shipped as a simple ad-conversion tracker for website owners — see who clicked, measure a campaign, nothing more. It ended up embedded on hospital patient portals and telehealth checkout pages, and just over a week ago\n\n[a federal judge forced Meta into discovery](https://www.techtimes.com/articles/320676/20260716/consent-defense-rejected-google-meta-face-discovery-over-prescription-pixel-data.htm) over Pixel code that fired on a prescription site before any consent screen even loaded, sending patient and prescription data back to Meta. That case is still active litigation in the same stretch of time Meta is asking people to hand it a facial-recognition selfie and trust the stated purpose. This is also the same company that has paid out over $2 billion across two separate biometric settlements — $650 million to Illinois in 2020, $1.4 billion to Texas in 2024 — for facial recognition it swore was limited, and that pulled facial-recognition code out of its smart glasses app under public pressure as recently as June. None of those settlements functioned as a deterrent. They functioned as a line-item cost, and the business resumed on schedule. The badge is the press release. The face-matching pipeline built to issue it is the actual product, and \"only for X\" has never been where the story ends with this company.\n\nZoom out further and it connects to a third post:\n\n[Prove You're Human. Pay With Your Data.](https://blog.ppb1701.com/prove-youre-human-pay-with-your-data) That one was about reCAPTCHA quietly shifting from \"solve a puzzle\" to \"hand over a phone number tied to a device tied to a billing address\" — not because bots have phone numbers, but because the real target was anonymity itself. Selfie sign-in and Facebook Verified are the same play from the opposite direction. reCAPTCHA anchors your identity from the outside, through the sites you visit. A biometric login anchors it from the inside, through the account itself, voluntarily, as a \"security upgrade.\" Different door, same room: \"prove you're human\" and \"prove you're you\" are collapsing into the same checkpoint, and it's always one of a handful of companies holding the key.\n\n## It's Not Even a New Idea\n\nNone of this started with Apple's Face ID, for what it's worth. Windows Hello beat it by two years, signing people into a PC with an infrared depth camera back in 2015. Xbox got there earlier still — the original Kinect, launched in November 2010, had \"Kinect Identity,\" recognizing your face and signing you straight into Xbox Live, no controller needed. The detail that makes it more than a coincidence: that Kinect\n\n[ran on depth-sensing hardware licensed from an Israeli company called PrimeSense](https://appleinsider.com/articles/17/10/25/microsoft-kills-kinect-just-as-apple-dives-into-facial-recognition-with-iphone-x-face-id) — and Apple bought PrimeSense outright in 2013, four years before Face ID shipped. The lineage runs straight from a 2010 Xbox peripheral to the sensor in every iPhone since. What's actually new this week isn't the concept. It's doing this at Google- and Meta-account scale, over a regular camera, with none of the dedicated depth-sensing hardware that made the earlier versions work at all.\n\n## Does It Even Work?\n\nThat gap matters, because nobody launching this week asked the more basic question: does the matching hold up against a normal human life? Glasses come off, contacts go in, people get tans, dye their hair, grow out a beard and shave it clean. None of that is exotic — it's just what living in a body looks like over the months between \"I enrolled\" and \"I actually need this to work.\"\n\nApple's Face ID is the gold-standard comparison, and even it needs a lot of help to manage that. It uses a dedicated infrared depth sensor to build a real 3D map, not a 2D photo comparison, and\n\n[it re-learns your face with every successful unlock](https://support.apple.com/en-us/118243) to absorb gradual change. When a change is too sharp for that drift correction, Apple's answer is a second enrollment slot —\n\n[Alternate Appearance](https://www.tomsguide.com/phones/iphones/my-iphone-face-id-wasnt-recognizing-me-consistently-this-one-setting-fixed-it) — so two genuinely different looks can both register as you. And even with all that,\n\n[Apple still warns upfront](https://support.apple.com/en-us/102381) that sunglasses, face coverings, and dramatic changes can knock it over, and that the odds of a false match get meaningfully worse for identical twins and close siblings, full stop — its own advice for that situation is to just use a passcode. I've seen the fragility of even this \"solved\" version firsthand: someone's Face ID worked fine all day, then failed the moment their glasses slid a couple centimeters down their nose so they could read something up close. Same face, same glasses, tipped at a slightly different angle — and the phone didn't know them.\n\nThat's the system with a dedicated depth sensor and a daily-updating model. Google's selfie sign-in and Meta's verification selfie are both working with less: a single enrollment image or clip, compared later against whatever ordinary camera happens to be pointed at you, with no described drift correction and no alternate-appearance option. Google's own setup instructions even require\n\n[removing glasses, masks, and hats to enroll](https://www.engadget.com/2221520/google-adds-selfie-video-log-in/) in the first place — meaning the reference image on file is, from day one, a version of your face you might not wear day-to-day. And that's assuming the recovery flow even reminds you of that at the moment you need it, or that you'd think to check in the panic of actually being locked out. More likely: a string of failed attempts while you're stressed and not thinking about whether your glasses are on, followed by whatever standard brute-force mitigation Google runs on repeated failures — which, on most systems, means a cooldown period that locks you out of trying again for a while. The one moment this feature exists to save you in is the same moment it's most likely to rate-limit you into a longer wait.\n\nIf you want to see how that plays out with real stakes attached, look at Virginia's Mobile ID app — a comparable idea, enrolling a face and checking it later against a live camera, except its reference point is a recent, professional ID photo rather than a months-old selfie, which should make it the\n\n*easier* version of this problem. In practice,\n\n[App Store reviews describe it flatly failing](https://apps.apple.com/us/app/virginia-mobile-id/id6480013606) to verify real people repeatedly enough that users never finish registration, with the\n\n[face-scan step giving zero feedback](https://mwm.ai/apps/virginia-mobile-id/6480013606) along the way. That's a state government app, live in production, struggling with an easier version of the exact problem Google and Meta just shipped at a much larger scale. Nobody's published a false-rejection rate for \"grew a beard\" or \"got contacts\" against either company's new system. Given how much dedicated hardware it took Apple to get this merely good, there's a real chance plenty of people will enroll in good faith, change in some ordinary human way, and discover the fallback doesn't recognize them the one time they actually need it — at which point you've handed over a permanent biometric for a feature that may not even reliably work.\n\n## The Legal Shape of This\n\nBiometric data isn't just sensitive in the abstract — it's regulated, unevenly, in ways that matter here. Illinois' Biometric Information Privacy Act requires written notice and consent before collecting biometric identifiers, and it's the law behind both Meta's settlements and\n\n[prior litigation against Google](https://www.biometricupdate.com/202002/google-hit-with-new-biometric-data-privacy-class-action-under-bipa) over facial recognition products. Unlike a password, a faceprint can't be reset if it's compromised — that's the entire reason laws like BIPA exist. A password breach means you change your password. A biometric breach means the thing that leaked was your actual face, forever. Both companies' answers here are the same ones they always give: encryption at rest, user-initiated deletion, consent-gated collection. All true as far as it goes, and none of it addresses what happens to the profile already built by the time someone thinks to delete anything.\n\n## What I'd Actually Do\n\nI don't recommend either of these for myself. I value my privacy, and there are too many what-ifs sitting in this right now — matching reliability nobody's tested, an \"additional purposes\" clause that funds the next model, and a biometric that can't be reset if it leaks. That's enough unknowns to leave it off.\n\nBut if you want to go there anyway — maybe you post YouTube videos a lot, or Google is your photo cloud storage, or Facebook Marketplace and Dating are how you actually use the platform — go in deliberately. For Google, that's **Security & sign-in → How you sign in to Google**, not whatever nudge Google puts in front of you, and actually read what \"opt in for additional purposes\" unlocks before leaving it checked. If you've already got a passkey or hardware key set up, ask honestly whether you need this at all, or whether it's one more biometric anchor added to a pile that was already tall enough.\n\nFor Meta, I can't point you to an equivalent settings path yet, because there isn't a well-documented self-serve one — Meta's own rollout materials talk about eligibility and phased markets, not a menu you go dig through. My honest bet is you won't need to go looking for it at all: expect an in-app prompt to show up on its own once you're eligible, the same way plenty of Meta's other \"opt-in\" features have arrived — front and center, one tap to accept, and easy to miss that you're handing over a facial-recognition selfie in the process. If that's how it lands for you, treat that prompt with the same deliberateness as the Google settings menu: read what you're agreeing to before you tap continue, not after.\n\nThe video is convenient. The companies holding it are the same ones that have spent this entire series proving they treat \"convenient\" and \"trust me\" as interchangeable.\n\nSmile for the login. Just know what room you're smiling into.", "url": "https://wpnews.pro/news/everyone-knows-your-face", "canonical_source": "https://blog.ppb1701.com/everyone-knows-your-face", "published_at": "2026-07-24 15:24:01+00:00", "updated_at": "2026-07-24 15:40:43.412980+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-policy", "ai-ethics", "computer-vision", "ai-products"], "entities": ["Google", "Meta", "Facebook Verified", "YouTube", "The Register", "AppleInsider"], "alternates": {"html": "https://wpnews.pro/news/everyone-knows-your-face", "markdown": "https://wpnews.pro/news/everyone-knows-your-face.md", "text": "https://wpnews.pro/news/everyone-knows-your-face.txt", "jsonld": "https://wpnews.pro/news/everyone-knows-your-face.jsonld"}}