If there were a Doomsday Clock for how close we are to "please drink verification can" (https://files.catbox.moe/eqg0b2.png), scientists would now move it to 3 minutes to midnight.
It's funny because different people would interpret this sentence differently.
If you have high level understanding of the tech behind it, this feels like a threat. But if you don't, this sounds like an honest message from someone who genuinely wants to protect you.
A regular user log into Google account and see their photos today. Tomorrow they log in and see the photos again. And they would assume this system will always work like this.
Fucking hell, they modified Chrome/ium to pop up an application dialog (it's not just somr HTML inside the web page) to "log-in using Google".. fuck Google!
Maybe next they'll get Chrome to automatically turn on your webcam, capture your face and say "Thanks for logging in!"
Plus friends and family inadvertently give Google/Facebook (etc) your personal info via tagged photos, contacts, DMs without your consent and they gather/link/sell this collateral info to the highest bidder without anyone being the wiser.
Of course. I wish that Immich had existed when I started using Google Photos, but it didn't. And I'd just had my first child so I really wanted to ensure I didn't lose any memories.
These days I run the two in parallel.
I wonder. I know a lot of people who hate this kind of thing, but because they don't want to be "tinfoil hat oddballs" they just keep quiet.
I think it would be nice to applaud or support people who think this way.
Instead of ridiculing these folks, or using semi-apologist "you're not the target market" type comments, it would be nice to say "good for you" or support them in some other way.
This already exists and is called FaceID and doesn't have the same privacy risks since the face check is done locally to allow the user to use the passkey to authenticate.
>Your selfie video is encrypted at rest
All data nowadays is encrypted at rest. That doesn't really matter since someone stealing a hard drive from Google with your information on it will never happen. The more likely risk is Google decrypts it and then sends it somewhere it shouldn't go and potentially trained into some AI system.
Meanwhile google has been locking out and closing the gmail accounts of people, myself included, that signed up before a phone number was required. If you don't log into your account for ~a year or so they will lock it and demand you log in. Which you can do, and you can even input the 2FA code, but it still won't let you log in because it says "there's not enough information to prove this is your account" despite having all the information ever associated with it. The only way to prevent deletion is to add a completely new, never before there phone number. I couldn't do that so they deleted mine saying I never logged in despite logging in literally dozens of times.
> The only way to prevent deletion is to add a completely new, never before there phone number.
Just happened to me. They "confirmed" it was me by getting a phone number they'd never seen before, that didn't belong to the false name on the account, and that I'd refused to give them for like 20 years. If anything, the fact that I eventually agreed to give them a phone number under duress was evidence that it wasn't me.
> despite logging in literally dozens of times.
Despite logging in literally thousands of times. I went in and deleted almost everything. Email now considered harmful. I'll feel better once they're locking me out of an empty account.
The problem is that everything in life requires a persistent email address, and hates email addresses that aren't on a whitelisted domain. The choice is between having some major provider, or not being able to pay your taxes online or log into your health insurance website. The fence is closing.
But I guess Google coming out with a cloud-based FaceID clone was just a matter of time...
apart from using just a vastly larger amount of 2D photos and more precise PI techniques, instead of that stupid local-only, small-AI-based, 3D-scanning technique that falls back to passwords...
eh, I prefer Apple as my good cop ever since I can afford Apple devices
"Google analyzes one or more videos of a user's hand as they perform various actions or gestures. The video is processed to extract hand landmark data, which includes 21 hand-knuckle coordinates."
If there were a Doomsday Clock for how close we are to "please drink verification can" (https://files.catbox.moe/eqg0b2.png), scientists would now move it to 3 minutes to midnight.
We're zero minutes away from "some scammer said they were google and I had to show them my butthole to login".
Scammer?
https://news.ycombinator.com/item?id=49028284
It's funny because different people would interpret this sentence differently.
If you have high level understanding of the tech behind it, this feels like a threat. But if you don't, this sounds like an honest message from someone who genuinely wants to protect you.
A regular user log into Google account and see their photos today. Tomorrow they log in and see the photos again. And they would assume this system will always work like this.
"Be a shame if you couldn't access them any more...
Verify identity to continue"
Moved all of my cherished photos out of my Google Account.
https://nevergivethemyourface.com/
this should be the top comment
>If you've violated a Google policy, we may save your selfie video for a longer period of time to enforce our policies.
I had to double check that today isn’t April 1st
I would love to know how they are going to handle deepfakes.
Also, doesn't this give law enforcement an easier avenue to compel access to someone's accounts?
> Also, doesn't this give law enforcement an easier avenue to compel access to someone's accounts?
It does.
I'm waiting for the new killer feature where "Sign In With Google" popup overlay dialogs go away forever and never come back.
Ironically it was DuckDuckGo's AI that gave me the magic string for uBlock origin:
accounts.google.com/gsi/*
Put that in your config and enjoy.
Fucking hell, they modified Chrome/ium to pop up an application dialog (it's not just somr HTML inside the web page) to "log-in using Google".. fuck Google!
Maybe next they'll get Chrome to automatically turn on your webcam, capture your face and say "Thanks for logging in!"
So don't use Chrome/Chromium. The web is so much better with uBlock Origin anyway!!
I use Vivaldi, sadly it's based on Chromium and has quite a bit of the stinky parts...
(Currently on an old Vivaldi version that still allows manifest v2.. I guess I'm asking to be pwned)
Guess what, there are browser settings for that!
Not in Firefox there isn't. It's part of the website.
I use a 30-seconds-of-work horribly-hacked Stylus setting to make it a blue dot that can expand on hover:
@-moz-document regexp(".") { / Insert code here... */ #credential_picker_container { width: fit-content !important; height: fit-content !important; } iframe[src^="https://accounts.google.com/gsi/iframe/select"] { width: 10px !important; height: 10px !important; border-radius: 50% !important; background-color:blue !important; } iframe[src^="https://accounts.google.com/gsi/iframe/select"]:hover { width: 300px !important; height: 300px !important; border-radius: 0 !important; } }
Google already have 5,000 odd photos of me anyway in Google photos. I'm screwed either way.
Plus friends and family inadvertently give Google/Facebook (etc) your personal info via tagged photos, contacts, DMs without your consent and they gather/link/sell this collateral info to the highest bidder without anyone being the wiser.
That attitude is exactly what got you into that mess.
There's no reason to believe the mess couldn't get any deeper, so backing out now doesn't have to be useless.
Of course. I wish that Immich had existed when I started using Google Photos, but it didn't. And I'd just had my first child so I really wanted to ensure I didn't lose any memories. These days I run the two in parallel.
Is this basically “Video KYC” as required in some countries to open a bank account?
The fact that most people will love this is depressing.
I wonder. I know a lot of people who hate this kind of thing, but because they don't want to be "tinfoil hat oddballs" they just keep quiet.
I think it would be nice to applaud or support people who think this way.
Instead of ridiculing these folks, or using semi-apologist "you're not the target market" type comments, it would be nice to say "good for you" or support them in some other way.
I am surprised and encouraged by the fact that almost all of the comments here are negative!
I would absolutely delete/abandon my Google account before voluntarily giving them my facial data.
Sounds like a bad idea on so many layers. I don't want to give more selfies for training, feels like a disaster about to happen
Respectfully, John and Claire, what do they have you guys doing? Please blink twice in your selfies if you're okay.
That's Google in a nutshell - "the more personal data you give us, the more access you can have to Google services".
Certainly this will never go wrong in any possible way.
Thats gona go well in history.
Next on Google's list, blood draw for sign-in.
I’d be willing to provide a stool sample
If only they wouldn't be evil... ugh.
I thought it is already April Fools for a while...
This already exists and is called FaceID and doesn't have the same privacy risks since the face check is done locally to allow the user to use the passkey to authenticate.
>Your selfie video is encrypted at rest
All data nowadays is encrypted at rest. That doesn't really matter since someone stealing a hard drive from Google with your information on it will never happen. The more likely risk is Google decrypts it and then sends it somewhere it shouldn't go and potentially trained into some AI system.
I happily will provide my selfie with one brown eye and round pale face
April fools?
Not for google. They'll want your family member photos next
They already have them, on Google Photos.
Meanwhile google has been locking out and closing the gmail accounts of people, myself included, that signed up before a phone number was required. If you don't log into your account for ~a year or so they will lock it and demand you log in. Which you can do, and you can even input the 2FA code, but it still won't let you log in because it says "there's not enough information to prove this is your account" despite having all the information ever associated with it. The only way to prevent deletion is to add a completely new, never before there phone number. I couldn't do that so they deleted mine saying I never logged in despite logging in literally dozens of times.
> The only way to prevent deletion is to add a completely new, never before there phone number.
Just happened to me. They "confirmed" it was me by getting a phone number they'd never seen before, that didn't belong to the false name on the account, and that I'd refused to give them for like 20 years. If anything, the fact that I eventually agreed to give them a phone number under duress was evidence that it wasn't me.
> despite logging in literally dozens of times.
Despite logging in literally thousands of times. I went in and deleted almost everything. Email now considered harmful. I'll feel better once they're locking me out of an empty account.
The problem is that everything in life requires a persistent email address, and hates email addresses that aren't on a whitelisted domain. The choice is between having some major provider, or not being able to pay your taxes online or log into your health insurance website. The fence is closing.
This seems like a terrible idea because deepfakes are getting better and better, even with them mentioning them and handwaving concerns away.
This sounds... totally normal.
Emphasis on "totally".
But I guess Google coming out with a cloud-based FaceID clone was just a matter of time...
apart from using just a vastly larger amount of 2D photos and more precise PI techniques, instead of that stupid local-only, small-AI-based, 3D-scanning technique that falls back to passwords...
eh, I prefer Apple as my good cop ever since I can afford Apple devices
Face ID is private on device. This is stored by Google and they will keep it longer if you "violate their policies".
Wow this is a terrible idea. I used to really respect the security and identity team what happened?
I'm surprised how fast this came from the whole "give us your hand" bullshit with reCaptcha not being that long ago.
https://docs.cloud.google.com/recaptcha/docs/hand-gesture-ve...
"Google analyzes one or more videos of a user's hand as they perform various actions or gestures. The video is processed to extract hand landmark data, which includes 21 hand-knuckle coordinates."
Next step is to require the full transcript of your genome!
/s