Your Google Account holds a lot of valuable information, from cherished photos to important emails and documents.
Stuff like this is why I and many other people are going out of our way to make this no longer the case.If you have high level understanding of the tech behind it, this feels like a threat. But if you don't, this sounds like an honest message from someone who genuinely wants to protect you.
A regular user log into Google account and see their photos today. Tomorrow they log in and see the photos again. And they would assume this system will always work like this.
Verify identity to continue"
Whether this is a good method or not is a different discussion and I probably will not use this method
I suppose the kind of people making them just don't have a blog or something
Maybe next they'll get Chrome to automatically turn on your webcam, capture your face and say "Thanks for logging in!"
Also, doesn't this give law enforcement an easier avenue to compel access to someone's accounts?
Anyone opting into this feature is effectively giving any US law enforcement (including ICE, local law enforcement, etc) free reign over their data.
the risk we assess is that under some conditions the provider could block the account, and the user would remain locked out unless he had the ability to do camera-based verification, so camera-based verification becomes from just optional to substantially mandatory?
--
Edit: elsewhere it seems it is mandated:
> To help keep you and others safe online, you may need to complete additional steps to access certain services. This extra confirmation helps us verify that the account owner is a real person and that the account wasn't created or used by computer programs or bots for the purpose of abuse, like spamming
Plus,
> To take a selfie [for "selfie video verification"], you'll need a mobile device with a Camera app
for many, it's a no.
There's no reason to believe the mess couldn't get any deeper, so backing out now doesn't have to be useless.
Whenever I got an email from a company to my Gmail, I logged into my account with that company and made the change. After about 2 or 3 years, I had 99.99% switched over.
Fastmail has a fast bulk import tool, and also allows you to automatically import future emails as the arrive (which is how I got that remaining 0.01% that only emailed me once every 5 years).
I gave each company a (unique identifier)@mydomain so that I could catch when my email address was sold, shared, hacked, etc, which has happened. That also allows me to easily move away from Fastmail to another service provider that has a catchall ability anytime I need to, but hopefully will never need to.
Time to move the last few things I have out of Google (mostly shared documents). I’m glad I started this move several years ago.
The start of Google's "genitals DB".
If they force people to smile to log in, the whole population will be statistically happier*.
Maybe even happier enough to offset being violated like that.
No, it does not. I create an account only when I'm forced to, e.g. on Google-certified Android phones, where I keep all synchronization off.
I'm eagerly waiting for official GrapheneOS phones. Pixels are a no-go for me because of the price-to-perf/quality ratio.
PS. It takes about 50 minutes to hunt down and turn off hopefully all the data grabbing features on a Samsung Android phone. Madness!
I would absolutely delete/abandon my Google account before voluntarily giving them my facial data.
>Your selfie video is encrypted at rest
All data nowadays is encrypted at rest. That doesn't really matter since someone stealing a hard drive from Google with your information on it will never happen. The more likely risk is Google decrypts it and then sends it somewhere it shouldn't go and potentially trained into some AI system.
[deleted]
Emphasis on "totally".
But I guess Google coming out with a cloud-based FaceID clone was just a matter of time...
apart from using just a vastly larger amount of 2D photos and more precise PI techniques, instead of that stupid local-only, small-AI-based, 3D-scanning technique that falls back to passwords...
eh, I prefer Apple as my good cop ever since I can afford Apple devices
[deleted]
Zero chance I will your train your AI.
https://docs.cloud.google.com/recaptcha/docs/hand-gesture-ve...
"Google analyzes one or more videos of a user's hand as they perform various actions or gestures. The video is processed to extract hand landmark data, which includes 21 hand-knuckle coordinates."
[dead]
/s
Like
If anything asked me for a selfie I'd close it and not go back. I just. No lmao absolutely not; go heck yourselves.
i just... god no. holy heck.
It's probably mandated (see mine at https://news.ycombinator.com/item?id=49033329)
A week later I get a notification “hey do you want to upload this photograph of a restaurant you took at location x?”. So Google Maps was busy rifling through my photos while I was going about my day-to-day business.
Creepy, gross and repulsive.
At best, you've identified LLM use. At worst, you've insulted a human writer. Either way, you've derailed the conversation away from the topic at hand.
the question I asked in my comment isn't rhetorical, by the way: I genuinely think it's a pattern, and I want to look into it a bit deeper
oh and for the record, I don't suggest you disregard the article. it raises valid points and I agree with it. go read it!
(Currently on an old Vivaldi version that still allows manifest v2.. I guess I'm asking to be pwned)
accounts.google.com/gsi/*
Put that in your config and enjoy.
@-moz-document regexp(".") { / Insert code here... */ #credential_picker_container { width: fit-content !important; height: fit-content !important; } iframe[src^="https://accounts.google.com/gsi/iframe/select"] { width: 10px !important; height: 10px !important; border-radius: 50% !important; background-color:blue !important; } iframe[src^="https://accounts.google.com/gsi/iframe/select"]:hover { width: 300px !important; height: 300px !important; border-radius: 0 !important; } }
If a journalist or activist don’t use face or fingerprints to unlock devices.
It does.
We are gong to reach a state of total digital surveillance without regulation at this point.
(The further issue is that bad regulators are posing the basis for future worse regulators.)
[deleted]
I think it would be nice to applaud or support people who think this way.
Instead of ridiculing these folks, or using semi-apologist "you're not the target market" type comments, it would be nice to say "good for you" or support them in some other way.
Just happened to me. They "confirmed" it was me by getting a phone number they'd never seen before, that didn't belong to the false name on the account, and that I'd refused to give them for like 20 years. If anything, the fact that I eventually agreed to give them a phone number under duress was evidence that it wasn't me.
> despite logging in literally dozens of times.
Despite logging in literally thousands of times. I went in and deleted almost everything. Email now considered harmful. I'll feel better once they're locking me out of an empty account.
The problem is that everything in life requires a persistent email address, and hates email addresses that aren't on a whitelisted domain. The choice is between having some major provider, or not being able to pay your taxes online or log into your health insurance website. The fence is closing.
[deleted]
But there is a juridical mess, already evident in matters like the eu's "ChatControl" laws (exemption to national rules about privacy for communication providers).