Agregátor RSS

6 things you should know about Google’s new selfie sign-in system

Computerworld.com [Hacking News] - 5 Srpen, 2026 - 11:45

Losing access to your Google account might just be the epitome of a modern-day nightmare.

Especially if you’re using Android and even more so if you’re invested in lots of different Google services on top of that, the amount of access and info connected to that one single sign-in is just staggering. Think about it: You’ve got everything from your Android apps and settings to potentially your email, your documents and spreadsheets, and all of your assorted files in Google Drive. And that’s to say nothing of all the images you might be backing up to Google Photos, the notes you might be storing in Google Keep, and even random things you might not think about like your browsing activity in Chrome or your location-related data in Maps.

It’s a lot, to say the least. And that’s precisely why it’s so important to think about your Google account security proactively and do everything you can to (a) make sure no one else ever gains access and, equally important, (b) make sure you never lose access to that all-encompassing sign-in.

At this point, you’re hopefully already doing smart stuff like using a unique and secure password and relying on two-factor authentication to add an extra layer of security beyond that — or maybe using a passkey for an alternate form of two-factor protection.

But even with all of those layers, the issue still remains of what happens if for any reason you aren’t able to get into your own Google account one day. And now, Google’s got a new option to help you make sure that nightmare never actually comes to pass.

Suffice it to say, it’s well worth your while to consider. But there are some important things you should know about it first.

[Get fresh Googley insight in your inbox with my free Android Intelligence newsletter. One new and useful tip every Friday!]

The ins and outs of Google selfie sign-in

The system of which we speak is an option to use a sophisticated selfie of yourself to sign into your Google account in an emergency — if all of your usual methods are for whatever reason not getting you through the gate. It happens more often than you’d think. And having multiple secure workarounds in such a scenario could be a massive lifesaver if it ever happens to you.

Depending on where you look, the option is called “selfie for sign-in,” “video verification,” or sometimes just “selfie video.” (Hey, this is Google we’re talking about here. Branding has never been a strength.) The system was announced in a random blog post a couple weeks back and has been slowly but surely showing up under the hood for accounts around the world ever since — but you’d never know it unless you happened to poke around in the exact area of your Google account settings where the option appears.

In my experience so far, it seems most average Android-owning animals are woefully unaware of its existence — and those who are aware of it are mostly perplexed by how exactly it works and if or when it’s advisable to use.

I’ve set it up on my own personal Google account, and I’ve explored every last nook and cranny. Here’s everything there is to know:

1. Selfie sign-in is super simple to set up

Seriously — it couldn’t be much easier. Just go to this page within the Google account settings site on a device with a camera (like, y’know, your phone or maybe an Android tablet).

Provided the feature is available on your account now, you’ll just click a couple o’ quick buttons to get the process started, then you’ll follow some simple prompts to stare into your camera longingly for a few moments.

Setting up a Google selfie sign-in is surprisingly swift ‘n’ simple.

JR Raphael, Foundry

The system will ask you to turn your head in specific directions. Then, it’ll take a handful of seconds to process and save your stunning turn on the virtual runway.

The process takes less than a minute to verify and save your selfie video.

JR Raphael, Foundry

And — well, that’s pretty much it.

2. Your selfie video is only for access to your Google account — not your phone or tablet

This is slightly confusing, since most modern Android devices offer the ability to use biometrics on the lock screen and show your face to unlock the phone itself — but the selfie sign-in system we’re speaking of here has nothing to do with any of that. It won’t unlock your device in any scenario or have any connection to any specific phone or tablet.

It’s connected purely to your Google account, and its sole purpose is acting as a mechanism to let you sign into that account — not to unlock or access any specific piece of hardware.

Speaking of which…

3. It’s only there as a last resort

Once you set up your selfie sign-in, odds are, you’ll never actually think about it again or have a reason to use it. Anytime you sign into your Google account, you’ll still use your standard password, passkey, and any two-factor authentication you’ve placed on the account.

The selfie path is there only in the event that all those regular methods are for some reason failing you. It’s unlikely, but it’s not impossible. And with your selfie video saved, if that situation ever arises, you’ll have an easy alternate way to prove your identity — by submitting a live on-the-fly selfie video and allowing Google to match it with your original saved one — so you can avoid getting locked out.

4. The selfie sign-in is designed to be both private and secure

When it comes to matching a saved selfie video and a new live one, Google requires different movements to verify validity and avoid any impersonation attempts.

Google says the data from your saved selfie video is always encrypted, too — not just in transport but also at rest, when it isn’t actively being used — which means no one else should ever be able to access it or do anything with it. You can always opt to delete a saved selfie video entirely, if you want, via that same Google account settings page.

And on that note…

5. You can prevent your selfie video from being used for any form of training

Lots of folks are understandably uneasy about the idea of their personal data — including their personal faces! — being used for any manner of machine learning these days. Google does ask for permission to do that and anonymously lean on your submission to help improve its facial recognition systems when you sign up for the selfie sign-in option, but critically, you can easily say no thanks.

When you’re in the midst of the selfie sign-in setup, look for the option to “Improve Google services.” It’ll appear at the bottom of the initial service agreement.

Keep that box unchecked, and your selfie video will never be used for any form of training or other purposes.

JR Raphael, Foundry

As long as you don’t check the box in that area, your selfie sign-in data will never be used for anything other than its primary intended purpose. And if you ever change your mind or are unsure of how you initially answered, you can also always revisit and revise that decision on that same Google account settings page.

The option to opt out of model training is always available on the selfie video settings screen.

JR Raphael, Foundry

6. Selfie sign-ins are (so far) only for individual Google accounts

With this initial rollout, Google’s selfie sign-in option is not available for accounts that are part of a Google Workspace team or organization. That kind of makes sense, since in any such situation, you could always turn to an admin for help if you were ever to lose account access, anyway.

This is something more intended for individual Google accounts, where you’re on your own and largely out of luck if you ever lose access. So whether you’re conducting business from an individual account or using an individual account alongside a Workspace-connected company sign-in, it’s something to consider for that part of your online identity.

The only other noteworthy asterisk is that selfie sign-ins won’t work with accounts where Advanced Protection is enabled. Advanced Protection is an extra-heightened form of Google account security created for people in the public eye or otherwise at an elevated risk of a targeted attack, and so it deliberately makes it much more difficult to get into an account in ways that go above and beyond what’s necessary for most ordinary organisms. If you have Advanced Protection on for your Google account, selfie sign-in won’t be available for you.

But for the rest of us, it’s a powerful new path that could prevent an unthinkable nightmare — and all you’ve gotta do is take two minutes to set it up now and then hopefully forget all about it.

Got Android? Check out my free Android Intelligence newsletter to get an exceptional new tip in your inbox every Friday.

Kategorie: Hacking & Security

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

The Hacker News - 5 Srpen, 2026 - 11:23
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as ofRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Ostuda Xboxu One může Microsoftu pomoci v další bitvě s PlayStationem. Převod disků do digitálu se rýsoval již před 13 lety

Živě.cz - 5 Srpen, 2026 - 10:45
Před 13 lety chtěl Microsoft zabránit bazarovému prodeji her. • Po velké kritice tuto technologii rychle zrušil. • Nyní ji ale vytáhne jako vítězný triumf.
Kategorie: IT News

Výrobci: GeForce RTX 5000 zdraží o 20-30 %, zastavili jsme dodávky levných karet

CD-R server - 5 Srpen, 2026 - 10:00
V kontextu zdražení grafických karet společnosti Nvidia vyšlo na povrch několik zajímavých informací. Zdražení bude spíš výraznější a výrobci jej využijí i k výhodnějšímu zpeněžení skladových zásob…
Kategorie: IT News

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

The Hacker News - 5 Srpen, 2026 - 09:53
An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK's AI Security Institute. When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and posted from a second account it controlled to vouch forSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The Hacker News - 5 Srpen, 2026 - 09:40
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows - CVE-2026-9198 (CVSS score: 9.8) - A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Srovnávací test dvoudiskových NASů. Tradičním značkám šlape na paty levný vyzyvatel z Amazonu

Živě.cz - 5 Srpen, 2026 - 08:45
Dvoudisková síťová úložiště jsou ideální pro použití v domácnosti. Jejich ceny jsou hluboko pod 10 tisíci a nevyžadují ani vysokou investici do samotných disků. Přitom nabízí rychlá 2,5Gb/s rozhraní a výkonné procesory.
Kategorie: IT News

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

The Hacker News - 5 Srpen, 2026 - 07:47
Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, aRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Malý sodíkem chlazený reaktor ARC 100 míří k prvnímu nasazení. Nabídne výkon 100 MW a staví na osvědčeném konceptu

Živě.cz - 5 Srpen, 2026 - 07:45
Americká firma plánuje v roce 2029 spuštění nového modulárního reaktoru • Reaktor využívá tekutý sodík a navazuje na prověřený historický koncept • Zařízení posílí vývoz technologií a zajistí stabilní elektřinu pro datacentra
Kategorie: IT News

Herní výkon Zen 6 bude 15-18 % nad Zen 5, na úrovni Zen 5 X3D

CD-R server - 5 Srpen, 2026 - 07:40
S příchodem informací o herním výkonu Zen 6 nastává čas se také zastavit nad herním výkonem Zen 6 s X3D. Dosavadní indicie totiž naznačují, že nárůst výkonu s X3D by mohl být nižší než u Zen 5…
Kategorie: IT News

AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project

The Register - Anti-Virus - 5 Srpen, 2026 - 03:55
The UK’s AI Security Institute has observed AI models performing what it calls “unsanctioned action” 19 times during security tests. The Institute (AISI) revealed the incidents in a Tuesday post and technical report that details tests it conducted to see if AI models can solve a cyber security challenge. “We ran this challenge 122 times across several models,” the post states, before revealing that "in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations.” GitHub was the target of the tests. The org found 19 unsanctioned actions in all, 15 of them conducted by Anthropic's Mythos 5, and the other pair perpetrated by OpenAI's GPT-5.6-Sol. “In the most serious case, an agent tried to insert malicious code into an open-source project, the post states. “In an attempt to get the code approved, the agent engaged in social engineering – creating fake online identities and using them to pressure the project's maintainer to approve the code.” Thankfully, a human maintainer “caught and refused to approve the malicious code.” Other actions AI took during the test included: Attempts to deceive and target real people, by contacting them directly and “sending messages and files through an online file-transfer service to persuade them, or their own AI coding tools, to run malicious code. Some messages carried harmful payloads, and some were attempts at social engineering; targeted at real people – something we’ve never previously observed.” Attempts to plant and prompt-inject malicious code. The agent tried to insert malicious instructions where it reasoned that other automated AI systems might pick them up and execute them. Collaboration between independent agents being assessed simultaneously. One agent left public messages on GitHub offering collaboration with other agents working on the same challenge. It also provided instructions to reuse accounts and artefacts it had left behind, which were discovered and used by subsequent agents. The Institute rated the tests “the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real-world.” That’s scary, but the news isn’t all bad because AISI allowed the models it tested to access the internet and turned off guardrails, conditions it notes do not reflect the way AI model operators make their wares available to the public. The outfit’s findings therefore represent a very different outcome compared to the situation when OpenAI agents discovered and exploited a zero-day to reach the internet during a test set up to take place in sandbox. “This incident should be interpreted with caution and nuance,” the outfit advises. “To some degree, our evaluation design choices and specific configurations enabled the behaviour. Nonetheless, the activity undertaken by the agent show signs of novel, potentially deceptive behaviours, and were to an extent and severity we did not anticipate.” AISI can’t say if the results it observed suggest AI will take similar actions under different circumstances. “We cannot yet be certain when the agent understood it was taking real world action, or to what extent it believed it was in a fictional test scenario,” the post adds. “Our analysis so far presents a mixed picture and is ongoing.” “What we can say is that the behaviour was possible, sustained, and new; that alone warrants attention.” AISI thinks its findings represent “a shift in the risk landscape.” “Harm may arise not only when people deliberately misuse publicly available models, but when capable agents operating in an internal research or privileged-access setting take unintended action beyond their authorised scope,” it wrote. It doesn’t have advice on how to cope with this sort of thing, other than to endorse its own mission. “Incidents of this kind reflect the speed at which AI is developing,” the post concludes. “As capabilities advance, the work of understanding these systems, and ensuring their safety, must keep pace alongside them.” ®
Kategorie: Viry a Červi

OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

Bleeping Computer - 5 Srpen, 2026 - 01:39
OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people outside the intended testing boundaries. [...]
Kategorie: Hacking & Security

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

Bleeping Computer - 5 Srpen, 2026 - 00:18
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]
Kategorie: Hacking & Security

Direct Fidoo Multibanking: Všechny firemní účty na jednom místě. První start se docela povedl (TEST)

Lupa.cz - články - 5 Srpen, 2026 - 00:00
Spravujete účty u několika bank nebo vedle živnosti provozujete také s. r. o.? Direct Fidoo Multibanking je dokáže spojit do jednoho přehledu a na jednom místě zobrazit zůstatky, transakce i základní vývoj cash flow. V praktickém testu nás potěšilo přehledné rozhraní, narazili jsme ale také na pomalejší aktualizaci dat, nejasná chybová hlášení a dosud omezenou automatickou kategorizaci.
Kategorie: IT News

Softwarová sklizeň (5. 8. 2026): bezpečnostní laboratoř za pár sekund

ROOT.cz - 5 Srpen, 2026 - 00:00
Vyměníme verze JDK jedním kliknutím, nacpeme si do jedné binárky desítku vývojářských nástrojů od hashů po ASCII art, vypíšeme si rozšíření RISC-V procesoru ve stylu neofetche a nakonec si zahrajeme Doom v Malování.
Kategorie: GNU/Linux & BSD

Pády Battlefield 6 s GeForce vyřešeny, netýkaly se jen vodní hladiny na RTX 5000

CD-R server - 5 Srpen, 2026 - 00:00
Po třech měsících přichází řešení na nestabilitu Battlefield 6 v kombinaci s GeForce RTX, zejména řadou 5000. DICE uvádí, že situací, ve kterých docházelo k pádům ovladače, bylo více než se uvádělo…
Kategorie: IT News

Lidé preferují povídky od AI. Zvlášť, když si myslí, že je napsal člověk

OSEL.cz - 5 Srpen, 2026 - 00:00
Výzkum obliby lidských a AI povídek naplno obnažil rozporuplný postoj dnešní společnosti k umělým inteligencím. Lidé považují povídky od AI za kvalitnější a také je víc zaujmou. Ale hodnotí AI povídky ještě mnohem lépe, když jim namluvíte, že jsou od lidských autorů. Co to tohle asi udělá s literaturou.
Kategorie: Věda a technika

Jak udržet Zemi obyvatelnou, až Slunce zemře?

OSEL.cz - 5 Srpen, 2026 - 00:00
Slunce tu nebude věčně. Co bychom měli dělat, až spálí své hvězdné palivo, a my tady ještě budeme? Nebo nějaké podobné druhy? Gabriel Harry navrhuje zůstat na Zemi a snažit se ji co nejlépe ochránit před červeným obrem, do něhož se Slunce promění. Vyhořelé Slunce by podle něj nahradili plynní obři Sluneční soustavy, jejichž vodík a helium bychom spalovali ve fúzních reaktorech.
Kategorie: Věda a technika

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

Bleeping Computer - 4 Srpen, 2026 - 23:45
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. [...]
Kategorie: Hacking & Security
Syndikovat obsah