Rendered at 09:10:10 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
trollbridge 12 hours ago [-]
Your Google Account holds a lot of valuable information, from cherished photos to important emails and documents.
Stuff like this is why I and many other people are going out of our way to make this no longer the case.
zzyzxd 11 hours ago [-]
It's funny because different people would interpret this sentence differently.
If you have high level understanding of the tech behind it, this feels like a threat. But if you don't, this sounds like an honest message from someone who genuinely wants to protect you.
A regular user log into Google account and see their photos today. Tomorrow they log in and see the photos again. And they would assume this system will always work like this.
dingaling 12 hours ago [-]
"Be a shame if you couldn't access them any more...
Verify identity to continue"
Rebelgecko 6 hours ago [-]
Drink verification can
Haranrk 2 hours ago [-]
I’m not sure I understand why this particular line bothers you. They seem to just be emphasising that your Google account has a lot of information and therefore they are providing another way to secure it?
Whether this is a good method or not is a different discussion and I probably will not use this method
samrus 1 hours ago [-]
It sounds like extortion. Give us your face. It'd be a shame if something happens to all that data
tintor 12 hours ago [-]
Moved all of my cherished photos out of my Google Account.
Cider9986 12 hours ago [-]
>If you've violated a Google policy, we may save your selfie video for a longer period of time to enforce our policies.
Yes— they spy on every pic and text upload. They literally are big brother.
sixothree 3 hours ago [-]
I uploaded a picture to Google Maps once. They told me they needed to access my photos to be able to upload the picture.
A week later I get a notification “hey do you want to upload this photograph of a restaurant you took at location x?”. So Google Maps was busy rifling through my photos while I was going about my day-to-day business.
Creepy, gross and repulsive.
Cider9986 3 hours ago [-]
GrapheneOS has storage scopes which make the app think it has full folder/file access but in reality you can choose the exact files or folders to give access. It helps keep invasive apps in line.
why are so many websites called title-of-the-article-dot-com ai-generated?
I suppose the kind of people making them just don't have a blog or something
hogwasher 6 hours ago [-]
why are so many people so comfortable making this assumption, based on writing style or a checklist of supposed tells or notoriously unreliable detectors, and making kneejerk accusations like they can do no harm and are already settled fact? It's one thing to feel suspicious or disregard the article yourself, but being so incautious about making public accusations without solid evidence is another.
At best, you've identified LLM use. At worst, you've insulted a human writer. Either way, you've derailed the conversation away from the topic at hand.
pillmillipedes 1 hours ago [-]
worst case, it's not generated and they just used ai for editing without realizing it has such a distinct style. that might be the case here: in the couple of paragraphs around the "I am but one" heading the writing style seems (to me) different (more human-ish?) compared to the style at the beginning.
unfortunately I also think they're quite bad, so I'm not sure what the moral here is for the author (who, true to their word, has elected to stay anonymous).
the question I asked in my comment isn't rhetorical, by the way: I genuinely think it's a pattern, and I want to look into it a bit deeper
oh and for the record, I don't suggest you disregard the article. it raises valid points and I agree with it. go read it!
notaigenerated 11 hours ago [-]
this should be the top comment
pudgywalsh 13 hours ago [-]
I'm waiting for the new killer feature where "Sign In With Google" popup overlay dialogs go away forever and never come back.
netsharc 12 hours ago [-]
Fucking hell, they modified Chrome/ium to pop up an application dialog (it's not just somr HTML inside the web page) to "log-in using Google".. fuck Google!
Maybe next they'll get Chrome to automatically turn on your webcam, capture your face and say "Thanks for logging in!"
ThePowerOfFuet 12 hours ago [-]
So don't use Chrome/Chromium. The web is so much better with uBlock Origin anyway!!
netsharc 11 hours ago [-]
I use Vivaldi, sadly it's based on Chromium and has quite a bit of the stinky parts...
(Currently on an old Vivaldi version that still allows manifest v2.. I guess I'm asking to be pwned)
giantrobot 8 hours ago [-]
Drink your verification can.
cadamsdotcom 11 hours ago [-]
Ironically it was DuckDuckGo's AI that gave me the magic string for uBlock origin:
accounts.google.com/gsi/*
Put that in your config and enjoy.
ButlerianJihad 12 hours ago [-]
Guess what, there are browser settings for that!
ThePowerOfFuet 12 hours ago [-]
Not in Firefox there isn't. It's part of the website.
sgc 11 hours ago [-]
I use a 30-seconds-of-work horribly-hacked Stylus setting to make it a blue dot that can expand on hover:
I would love to know how they are going to handle deepfakes.
Also, doesn't this give law enforcement an easier avenue to compel access to someone's accounts?
free_bip 10 hours ago [-]
Yes it does. Biometric information (e.g a picture of your face) is famously not nearly as protected under the 4th amendment compared to things like passwords.
Anyone opting into this feature is effectively giving any US law enforcement (including ICE, local law enforcement, etc) free reign over their data.
fsuts 3 hours ago [-]
Not just USA, same in many other countries too.
If a journalist or activist don’t use face or fingerprints to unlock devices.
EmbarrassedHelp 11 hours ago [-]
> Also, doesn't this give law enforcement an easier avenue to compel access to someone's accounts?
It does.
xnx 12 hours ago [-]
If there were a Doomsday Clock for how close we are to "please drink verification can" (https://files.catbox.moe/eqg0b2.png), scientists would now move it to 3 minutes to midnight.
bombcar 12 hours ago [-]
We're zero minutes away from "some scammer said they were google and I had to show them my butthole to login".
The fact that most people will love this is depressing.
PradeetPatel 11 hours ago [-]
Can you please explain why it is depressing? This feature is widely celebrated in the accessibility user groups in India, since the traditional sign-in methods have been proven to be a major friction point for users with special needs.
swat535 10 hours ago [-]
The same reason age identity verification is getting a lot of push back..? This is dystopian on another level.
We are gong to reach a state of total digital surveillance without regulation at this point.
jryle70 4 hours ago [-]
Then regulate. The feature itself is useful, not depressing.
mdp2021 18 minutes ago [-]
The current issue is in the category "action from bad regulators is worse than no action".
(The further issue is that bad regulators are posing the basis for future worse regulators.)
M95D 2 hours ago [-]
At this point all govs would just regulate it to mandatory.
10 hours ago [-]
m463 12 hours ago [-]
I wonder. I know a lot of people who hate this kind of thing, but because they don't want to be "tinfoil hat oddballs" they just keep quiet.
I think it would be nice to applaud or support people who think this way.
Instead of ridiculing these folks, or using semi-apologist "you're not the target market" type comments, it would be nice to say "good for you" or support them in some other way.
neuralkoi 4 hours ago [-]
Every time Google comes out with a new "feature" like this, it reminds me to resume my de-Googling journey with reinforced vigor. Drive and Photos are low-hanging fruit. GMail and YouTube will be more difficult.
dawnerd 2 hours ago [-]
I have a burner account just for YouTube. If they want to ban me I’ll just get the content without paying for premium.
muppetman 12 hours ago [-]
Google already have 5,000 odd photos of me anyway in Google photos. I'm screwed either way.
wegwerf17377382 11 hours ago [-]
That attitude is exactly what got you into that mess.
There's no reason to believe the mess couldn't get any deeper, so backing out now doesn't have to be useless.
muppetman 11 hours ago [-]
Of course. I wish that Immich had existed when I started using Google Photos, but it didn't. And I'd just had my first child so I really wanted to ensure I didn't lose any memories.
These days I run the two in parallel.
canada_dry 11 hours ago [-]
Plus friends and family inadvertently give Google/Facebook (etc) your personal info via tagged photos, contacts, DMs without your consent and they gather/link/sell this collateral info to the highest bidder without anyone being the wiser.
arm32 13 hours ago [-]
Respectfully, John and Claire, what do they have you guys doing? Please blink twice in your selfies if you're okay.
wafflemaker 4 hours ago [-]
Look at the positive!
If they force people to smile to log in, the whole population will be statistically happier*.
Maybe even happier enough to offset being violated like that.
That's Google in a nutshell - "the more personal data you give us, the more access you can have to Google services".
LorenDB 12 hours ago [-]
Certainly this will never go wrong in any possible way.
iamnothere 10 hours ago [-]
I guess next this will be required for new account setup, then to retain access to your existing account.
Time to move the last few things I have out of Google (mostly shared documents). I’m glad I started this move several years ago.
stevenalowe 7 hours ago [-]
Introducing...a feature no one actually wants, that opens a brand new security attack surface. Much wow.
gitowiec 12 hours ago [-]
I happily will provide my selfie with one brown eye and round pale face
praet 13 hours ago [-]
April fools?
fhn 13 hours ago [-]
Not for google. They'll want your family member photos next
FireInsight 12 hours ago [-]
They already have them, on Google Photos.
fhn 13 hours ago [-]
Next on Google's list, blood draw for sign-in.
cousinbryce 13 hours ago [-]
I’d be willing to provide a stool sample
tiffanyh 11 hours ago [-]
Is this basically “Video KYC” as required in some countries to open a bank account?
altairprime 7 hours ago [-]
No government has yet regulated online services to require financial KYC compliance afaik, other than banking services which are already covered by ‘banking’. To the best of my understanding, the regulations about age verification don’t tend to mandate forever storage of the identity data, only storage of the verification outcome — even if business misrepresent that in order to harvest, train, aggregate, resell. (Whatever China is doing is not KYC: the government performs the Know verb in those cases, rather than the business.)
subscribed 10 hours ago [-]
KYC for financial institutions is orthogonal and stems from different laws.
srameshc 11 hours ago [-]
Sounds like a bad idea on so many layers. I don't want to give more selfies for training, feels like a disaster about to happen
schaefer 11 hours ago [-]
If only they wouldn't be evil...
ugh.
superkuh 12 hours ago [-]
Meanwhile google has been locking out and closing the gmail accounts of people, myself included, that signed up before a phone number was required. If you don't log into your account for ~a year or so they will lock it and demand you log in. Which you can do, and you can even input the 2FA code, but it still won't let you log in because it says "there's not enough information to prove this is your account" despite having all the information ever associated with it. The only way to prevent deletion is to add a completely new, never before there phone number. I couldn't do that so they deleted mine saying I never logged in despite logging in literally dozens of times.
pessimizer 11 hours ago [-]
> The only way to prevent deletion is to add a completely new, never before there phone number.
Just happened to me. They "confirmed" it was me by getting a phone number they'd never seen before, that didn't belong to the false name on the account, and that I'd refused to give them for like 20 years. If anything, the fact that I eventually agreed to give them a phone number under duress was evidence that it wasn't me.
> despite logging in literally dozens of times.
Despite logging in literally thousands of times. I went in and deleted almost everything. Email now considered harmful. I'll feel better once they're locking me out of an empty account.
The problem is that everything in life requires a persistent email address, and hates email addresses that aren't on a whitelisted domain. The choice is between having some major provider, or not being able to pay your taxes online or log into your health insurance website. The fence is closing.
angoragoats 11 hours ago [-]
I am surprised and encouraged by the fact that almost all of the comments here are negative!
I would absolutely delete/abandon my Google account before voluntarily giving them my facial data.
charcircuit 12 hours ago [-]
This already exists and is called FaceID and doesn't have the same privacy risks since the face check is done locally to allow the user to use the passkey to authenticate.
>Your selfie video is encrypted at rest
All data nowadays is encrypted at rest. That doesn't really matter since someone stealing a hard drive from Google with your information on it will never happen. The more likely risk is Google decrypts it and then sends it somewhere it shouldn't go and potentially trained into some AI system.
ProfessorLayton 12 hours ago [-]
This seems like a terrible idea because deepfakes are getting better and better, even with them mentioning them and handwaving concerns away.
lardosaurusrex 3 hours ago [-]
Just ban me at that point lmfao.
Like
If anything asked me for a selfie I'd close it and not go back. I just. No lmao absolutely not; go heck yourselves.
i just... god no. holy heck.
newswangerd 11 hours ago [-]
I had to double check that today isn’t April 1st
aeve890 3 hours ago [-]
I know right? And the obnoxious music in the video like something so wonderful and worthy of celebration what the actual fuck
nicce 11 hours ago [-]
I thought it is already April Fools for a while...
navs 10 hours ago [-]
If this means that Google will do eventually do age verification then I think I trust them more than I trust Persona.
moritzwarhier 13 hours ago [-]
This sounds... totally normal.
Emphasis on "totally".
But I guess Google coming out with a cloud-based FaceID clone was just a matter of time...
apart from using just a vastly larger amount of 2D photos and more precise PI techniques, instead of that stupid local-only, small-AI-based, 3D-scanning technique that falls back to passwords...
eh, I prefer Apple as my good cop ever since I can afford Apple devices
Cider9986 12 hours ago [-]
Face ID is private on device. This is stored by Google and they will keep it longer if you "violate their policies".
12 hours ago [-]
preg_match 4 hours ago [-]
The main threat, and this covers Face ID, is that law enforcement and ICE have a much easier time compelling these auth methods. The legal bar is much, much lower than passwords. You should always turn Face ID off when traveling, and ideally power off the phone.
12 hours ago [-]
kotaKat 12 hours ago [-]
I'm surprised how fast this came from the whole "give us your hand" bullshit with reCaptcha not being that long ago.
"Google analyzes one or more videos of a user's hand as they perform various actions or gestures. The video is processed to extract hand landmark data, which includes 21 hand-knuckle coordinates."
guessmyname 12 hours ago [-]
leet-stick-7299 11 hours ago [-]
Thats gona go well in history.
ikiris 11 hours ago [-]
Wow this is a terrible idea. I used to really respect the security and identity team what happened?
Qision 11 hours ago [-]
Next step is to require the full transcript of your genome!
/s
fjlunky 8 hours ago [-]
Funnily enough they already have that since it was _emailed_ to me.
If you have high level understanding of the tech behind it, this feels like a threat. But if you don't, this sounds like an honest message from someone who genuinely wants to protect you.
A regular user log into Google account and see their photos today. Tomorrow they log in and see the photos again. And they would assume this system will always work like this.
Verify identity to continue"
Whether this is a good method or not is a different discussion and I probably will not use this method
https://support.google.com/accounts/answer/16675622
A week later I get a notification “hey do you want to upload this photograph of a restaurant you took at location x?”. So Google Maps was busy rifling through my photos while I was going about my day-to-day business.
Creepy, gross and repulsive.
I suppose the kind of people making them just don't have a blog or something
At best, you've identified LLM use. At worst, you've insulted a human writer. Either way, you've derailed the conversation away from the topic at hand.
the question I asked in my comment isn't rhetorical, by the way: I genuinely think it's a pattern, and I want to look into it a bit deeper
oh and for the record, I don't suggest you disregard the article. it raises valid points and I agree with it. go read it!
Maybe next they'll get Chrome to automatically turn on your webcam, capture your face and say "Thanks for logging in!"
(Currently on an old Vivaldi version that still allows manifest v2.. I guess I'm asking to be pwned)
accounts.google.com/gsi/*
Put that in your config and enjoy.
@-moz-document regexp(".") { / Insert code here... */ #credential_picker_container { width: fit-content !important; height: fit-content !important; } iframe[src^="https://accounts.google.com/gsi/iframe/select"] { width: 10px !important; height: 10px !important; border-radius: 50% !important; background-color:blue !important; } iframe[src^="https://accounts.google.com/gsi/iframe/select"]:hover { width: 300px !important; height: 300px !important; border-radius: 0 !important; } }
https://addons.mozilla.org/en-US/firefox/addon/styl-us/
Also, doesn't this give law enforcement an easier avenue to compel access to someone's accounts?
Anyone opting into this feature is effectively giving any US law enforcement (including ICE, local law enforcement, etc) free reign over their data.
If a journalist or activist don’t use face or fingerprints to unlock devices.
It does.
https://news.ycombinator.com/item?id=49028284
We are gong to reach a state of total digital surveillance without regulation at this point.
(The further issue is that bad regulators are posing the basis for future worse regulators.)
I think it would be nice to applaud or support people who think this way.
Instead of ridiculing these folks, or using semi-apologist "you're not the target market" type comments, it would be nice to say "good for you" or support them in some other way.
There's no reason to believe the mess couldn't get any deeper, so backing out now doesn't have to be useless.
If they force people to smile to log in, the whole population will be statistically happier*.
Maybe even happier enough to offset being violated like that.
*: https://www.nature.com/articles/s41562-022-01458-9
Time to move the last few things I have out of Google (mostly shared documents). I’m glad I started this move several years ago.
Just happened to me. They "confirmed" it was me by getting a phone number they'd never seen before, that didn't belong to the false name on the account, and that I'd refused to give them for like 20 years. If anything, the fact that I eventually agreed to give them a phone number under duress was evidence that it wasn't me.
> despite logging in literally dozens of times.
Despite logging in literally thousands of times. I went in and deleted almost everything. Email now considered harmful. I'll feel better once they're locking me out of an empty account.
The problem is that everything in life requires a persistent email address, and hates email addresses that aren't on a whitelisted domain. The choice is between having some major provider, or not being able to pay your taxes online or log into your health insurance website. The fence is closing.
I would absolutely delete/abandon my Google account before voluntarily giving them my facial data.
>Your selfie video is encrypted at rest
All data nowadays is encrypted at rest. That doesn't really matter since someone stealing a hard drive from Google with your information on it will never happen. The more likely risk is Google decrypts it and then sends it somewhere it shouldn't go and potentially trained into some AI system.
Like
If anything asked me for a selfie I'd close it and not go back. I just. No lmao absolutely not; go heck yourselves.
i just... god no. holy heck.
Emphasis on "totally".
But I guess Google coming out with a cloud-based FaceID clone was just a matter of time...
apart from using just a vastly larger amount of 2D photos and more precise PI techniques, instead of that stupid local-only, small-AI-based, 3D-scanning technique that falls back to passwords...
eh, I prefer Apple as my good cop ever since I can afford Apple devices
https://docs.cloud.google.com/recaptcha/docs/hand-gesture-ve...
"Google analyzes one or more videos of a user's hand as they perform various actions or gestures. The video is processed to extract hand landmark data, which includes 21 hand-knuckle coordinates."
/s