Google recently introduced a new way for people to regain access to their Google Accounts: look into a camera, record a short selfie video, follow a few guided head movements to demonstrate liveness, and later use another live selfie to prove that the person trying to access the account is the same person who enrolled.
Today, Google is primarily positioning this as an account recovery and additional verification capability, not as a replacement for every password, passkey or MFA transaction. But I think the more interesting story is what it says about where authentication is going.
The identity gap
For decades, the identity industry has focused on authenticating credentials. Passwords prove that someone knows a secret, phones, security keys and OTP tokens prove that someone possesses a device, and passkeys prove control of a cryptographic key.
All of these technologies can make authentication substantially stronger. But none of them, by themselves, answer the most fundamental question:
Is the person using the credential actually the person who is supposed to be using it?
From authenticating credentials to authenticating people
Google's move is an important validation of live biometrics as part of mainstream digital identity. A live biometric is fundamentally different from another possession factor. It can directly test whether the human being who enrolled is physically present again at the moment access is requested.
That distinction is becoming increasingly important. Passwords can be phished., tokens can be stolen, and sessions can be hijacked. Push notifications can be socially engineered, credentials are easily shared, and generative AI has made it significantly easier to impersonate another person during remote interactions.
The authentication industry has spent years making credentials harder to steal. The next phase is making the human behind the credential verifiable.
That requires two things
First, establish who the person really is. That can involve a government-issued identity document, authoritative data sources, document validation, liveness detection and a biometric comparison.
Then make that verified identity reusable. When the person returns tomorrow, next month or at a high-risk moment, don't simply ask whether they know a password or possess a device. Reverify that the same live human is present.
That is where biometrics become much more than a convenient way to unlock a phone.
This is the model 1Kosmos has been building for years
At 1Kosmos, we call our facial biometric capability LiveID. The concept is simple: verify the person, not just the credential.
A person can establish an identity, enroll a LiveID and then use their face again when an organization needs to know that the same real person is present. LiveID performs liveness detection before biometric matching, then compares the live biometric with the person's enrolled biometric.
That allows organizations to use identity as part of authentication, passwordless access, account recovery, sensitive transactions and step-up verification.
And this is not theoretical. Customers are already putting this model into production in very different environments.
What does this look like in the real world?
Our customers use LiveID in very different settings, but the goal is always to confirm the right person is present. A few examples:
Frontline workers
A global apparel company with some of the best-known retail brands in the world uses LiveID for frontline retail associates.
Instead of relying on a worker remembering another password or reaching for a personal phone to retrieve an MFA code, the associate can use a camera at the workstation to authenticate with LiveID in seconds. Look at the camera. Establish that a real person is present. Match that person to the enrolled identity. Provide access.
That is a fundamentally different experience from legacy authentication. When compared to username + password, the operational cost savings are tremendous (oh yeah, there's the password remediation too). It is rare for a more secure authentication process to provide a better user experience.
Know Your Employee
We are also seeing organizations rethink the entire hiring process.
Hiring fraud has exposed a major weakness in traditional HR systems: the person who submits an application, the person who appears in a video interview and the person who eventually receives corporate credentials do not necessarily have to be the same human being.
Our Know Your Employee model creates an identity thread through that entire journey:
Applicant: establish and verify the person's identity
Interview: use LiveID to reverify the same person
Offer: confirm identity again when appropriate
Onboarding: bind the verified employee to the enterprise identity
Day 0: use LiveID for passwordless access
Ongoing employment: use biometric or continuous authentication when the risk requires it
Instead of treating hiring, onboarding and authentication as unrelated events, the organization can maintain identity continuity from applicant to employee. The question changes from "Does this person have the right login?" to "Is this the same verified human we hired?"
Third-party logistics
The same principle is moving into the physical world. At one of the world's largest home-improvement retailers, 1Kosmos identity verification is being used to verify third-party logistics drivers arriving at distribution locations to pick up merchandise for delivery.
The identity problem is straightforward: knowing that a logistics company assigned a driver is different from knowing who physically arrived to take possession of merchandise and potentially deliver it to a customer's home.
The workflow can establish a driver's identity at the initial interaction and reverify that identity on subsequent visits. This is identity becoming reusable operational infrastructure, not simply an onboarding check.
Critical systems and account recovery
Enterprises can apply the same concept when someone calls a service desk, performs a password reset or needs access to a sensitive application. Instead of asking knowledge-based questions or trusting possession of another credential, LiveID can be invoked as a step-up factor and require the actual enrolled person to be present.
Biometrics also require a different privacy architecture
There is a legitimate concern whenever an organization starts talking about facial biometrics: What happens to my face?
Google says its enrolled selfie video is securely stored, encrypted at rest and controlled by the user. At 1Kosmos, we took a different architectural approach because enterprises have stringent privacy, regulatory and data-protection requirements.
LiveID does not store the raw facial image as the authentication credential. During enrollment, the biometric is converted on the device into an encrypted mathematical vector. That encrypted representation is what is stored and later used for one-to-one matching. The goal is to get the security value of biometrics without creating a repository of facial photographs.
That distinction matters as biometric authentication becomes more common. Adoption will lean on whether organizations can deploy it with appropriate consent, data protection, residency, retention and privacy controls, not just whether the technology works.
Google is helping move the market
Google's new selfie capability is only one step. It is currently focused heavily on account recovery, and Google Workspace accounts are not yet eligible. I do not expect every authentication transaction to suddenly become a facial scan.
But the direction is significant, because one of the largest technology companies in the world is teaching consumers a new security behavior:
Look into the camera
Prove that you are live
Confirm that you are the person who enrolled
Get access
That makes the concept of biometric re-verification much more familiar. 1Kosmos has been applying that model to workforce and customer identity for years.
The opportunity now is bigger than passwordless authentication. It is the transition from credential-based authentication to identity-backed authentication. Verify a real person, bind that person to an identity, protect the biometric. Then allow the organization to reverify that same human whenever the risk requires it.
Google's selfie video is an early sign that this model is moving into the mainstream. For enterprises dealing with employees, customers, contractors, frontline workers and increasingly sophisticated impersonation attacks, the journey has already begun.
Read Google’s original announcement: Introducing selfie for sign-in
Google recently introduced a new way for people to regain access to their Google Accounts: look into a camera, record a short selfie video, follow a few guided head movements to demonstrate liveness, and later use another live selfie to prove that the person trying to access the account is the same person who enrolled.
Today, Google is primarily positioning this as an account recovery and additional verification capability, not as a replacement for every password, passkey or MFA transaction. But I think the more interesting story is what it says about where authentication is going.
The identity gap
For decades, the identity industry has focused on authenticating credentials. Passwords prove that someone knows a secret, phones, security keys and OTP tokens prove that someone possesses a device, and passkeys prove control of a cryptographic key.
All of these technologies can make authentication substantially stronger. But none of them, by themselves, answer the most fundamental question:
Is the person using the credential actually the person who is supposed to be using it?
From authenticating credentials to authenticating people
Google's move is an important validation of live biometrics as part of mainstream digital identity. A live biometric is fundamentally different from another possession factor. It can directly test whether the human being who enrolled is physically present again at the moment access is requested.
That distinction is becoming increasingly important. Passwords can be phished., tokens can be stolen, and sessions can be hijacked. Push notifications can be socially engineered, credentials are easily shared, and generative AI has made it significantly easier to impersonate another person during remote interactions.
The authentication industry has spent years making credentials harder to steal. The next phase is making the human behind the credential verifiable.
That requires two things
First, establish who the person really is. That can involve a government-issued identity document, authoritative data sources, document validation, liveness detection and a biometric comparison.
Then make that verified identity reusable. When the person returns tomorrow, next month or at a high-risk moment, don't simply ask whether they know a password or possess a device. Reverify that the same live human is present.
That is where biometrics become much more than a convenient way to unlock a phone.
This is the model 1Kosmos has been building for years
At 1Kosmos, we call our facial biometric capability LiveID. The concept is simple: verify the person, not just the credential.
A person can establish an identity, enroll a LiveID and then use their face again when an organization needs to know that the same real person is present. LiveID performs liveness detection before biometric matching, then compares the live biometric with the person's enrolled biometric.
That allows organizations to use identity as part of authentication, passwordless access, account recovery, sensitive transactions and step-up verification.
And this is not theoretical. Customers are already putting this model into production in very different environments.
What does this look like in the real world?
Our customers use LiveID in very different settings, but the goal is always to confirm the right person is present. A few examples:
Frontline workers
A global apparel company with some of the best-known retail brands in the world uses LiveID for frontline retail associates.
Instead of relying on a worker remembering another password or reaching for a personal phone to retrieve an MFA code, the associate can use a camera at the workstation to authenticate with LiveID in seconds. Look at the camera. Establish that a real person is present. Match that person to the enrolled identity. Provide access.
That is a fundamentally different experience from legacy authentication. When compared to username + password, the operational cost savings are tremendous (oh yeah, there's the password remediation too). It is rare for a more secure authentication process to provide a better user experience.
Know Your Employee
We are also seeing organizations rethink the entire hiring process.
Hiring fraud has exposed a major weakness in traditional HR systems: the person who submits an application, the person who appears in a video interview and the person who eventually receives corporate credentials do not necessarily have to be the same human being.
Our Know Your Employee model creates an identity thread through that entire journey:
Applicant: establish and verify the person's identity
Interview: use LiveID to reverify the same person
Offer: confirm identity again when appropriate
Onboarding: bind the verified employee to the enterprise identity
Day 0: use LiveID for passwordless access
Ongoing employment: use biometric or continuous authentication when the risk requires it
Instead of treating hiring, onboarding and authentication as unrelated events, the organization can maintain identity continuity from applicant to employee. The question changes from "Does this person have the right login?" to "Is this the same verified human we hired?"
Third-party logistics
The same principle is moving into the physical world. At one of the world's largest home-improvement retailers, 1Kosmos identity verification is being used to verify third-party logistics drivers arriving at distribution locations to pick up merchandise for delivery.
The identity problem is straightforward: knowing that a logistics company assigned a driver is different from knowing who physically arrived to take possession of merchandise and potentially deliver it to a customer's home.
The workflow can establish a driver's identity at the initial interaction and reverify that identity on subsequent visits. This is identity becoming reusable operational infrastructure, not simply an onboarding check.
Critical systems and account recovery
Enterprises can apply the same concept when someone calls a service desk, performs a password reset or needs access to a sensitive application. Instead of asking knowledge-based questions or trusting possession of another credential, LiveID can be invoked as a step-up factor and require the actual enrolled person to be present.
Biometrics also require a different privacy architecture
There is a legitimate concern whenever an organization starts talking about facial biometrics: What happens to my face?
Google says its enrolled selfie video is securely stored, encrypted at rest and controlled by the user. At 1Kosmos, we took a different architectural approach because enterprises have stringent privacy, regulatory and data-protection requirements.
LiveID does not store the raw facial image as the authentication credential. During enrollment, the biometric is converted on the device into an encrypted mathematical vector. That encrypted representation is what is stored and later used for one-to-one matching. The goal is to get the security value of biometrics without creating a repository of facial photographs.
That distinction matters as biometric authentication becomes more common. Adoption will lean on whether organizations can deploy it with appropriate consent, data protection, residency, retention and privacy controls, not just whether the technology works.
Google is helping move the market
Google's new selfie capability is only one step. It is currently focused heavily on account recovery, and Google Workspace accounts are not yet eligible. I do not expect every authentication transaction to suddenly become a facial scan.
But the direction is significant, because one of the largest technology companies in the world is teaching consumers a new security behavior:
Look into the camera
Prove that you are live
Confirm that you are the person who enrolled
Get access
That makes the concept of biometric re-verification much more familiar. 1Kosmos has been applying that model to workforce and customer identity for years.
The opportunity now is bigger than passwordless authentication. It is the transition from credential-based authentication to identity-backed authentication. Verify a real person, bind that person to an identity, protect the biometric. Then allow the organization to reverify that same human whenever the risk requires it.
Google's selfie video is an early sign that this model is moving into the mainstream. For enterprises dealing with employees, customers, contractors, frontline workers and increasingly sophisticated impersonation attacks, the journey has already begun.
Read Google’s original announcement: Introducing selfie for sign-in
About the author

Mike Engle
Co-Founder and CSO
Mike is the CSO and a co-founder of 1Kosmos with deep expertise in information security, product development, and business development across Fortune 100 financial institutions and early-stage startups.
The latest in identity security.
Enter our orbit.
The latest in identity security.
Enter our orbit.
The latest in identity security.





