Everyone Knows Your Face - ByteHaven - Where I ramble about bytes
ByteHaven - Where I ramble about bytes
Everyone Knows Your Face
Part of the ongoing Big Tech's War on Users series.
This week, within days of each other, Google and Meta both shipped facial recognition as the answer to trust online. Turns out you don't need a bar stool and a theme song for everybody to know your face anymore — you just need a Google Account or a Facebook profile. Google launched selfie video sign-in: record a short video of yourself once, and if you ever get locked out, a fresh selfie against that saved clip gets you back into your account. Meta launched Facebook Verified: hand over a facial-recognition selfie, get it checked against your existing profile photos, and earn a badge that tells other people you're a real human and not an AI-generated scammer.
Different problems on paper — account recovery versus catfish detection — but the same instinct underneath: when trust online breaks down, the reflexive fix at two of the biggest companies on the internet is the same sentence. Give us your face.
I'm not here to pretend either company invented villainy this week. Account recovery is a real problem, and so is the flood of AI-generated fake profiles both companies are actually responding to. What's worth sitting with is why this is the fix everyone reaches for now, whether it's even good at the job, and what it costs to hand over.
The Same Playbook, Twice
I've written this exact post before, about a different Google product wearing a different name. Back in April I covered YouTube's AI avatar feature — record a selfie, read a few prompts, and Google builds a photorealistic digital double of your face and voice for Shorts. Safe, consensual, deletable, they said. Underneath, Google was collecting a clean, user-verified biometric sample and tying it to the most complete identity profile a company has ever built on a person. Selfie sign-in is the same architecture moved from "fun creative toy" to "core account security" — a much quieter on-ramp to the same outcome, since nobody scrutinizes a security settings menu the way they scrutinize a flashy new AI feature.
The messaging matches too: encrypted at rest, deletable anytime, used only for sign-in — unless you opt in to something else. That "something else" isn't vague by accident. The Register got Google on record about what it actually covers: training Google's own facial recognition and age-estimation systems. So opting in doesn't just share your data — it makes your face training material for the next generation of the same verification tech.
Meta's version fits an even more specific playbook I mapped out in Always On. Always Watching.: whatever protects a company from liability ships loud, with a press release and a friendly free badge; whatever expands what it can collect ships quiet, opt-out, buried under a menu. Facebook Verified is textbook loud — free, publicized, framed entirely around protecting you from scammers. Meta is also careful to state, in its own announcement, exactly what the badge doesn't do: it confirms you're not an AI, not that you are who you claim to be. That's a narrower promise than most people will read into a "Verified" checkmark, and it's worth remembering exactly that specific, bounded claim the next time the feature quietly expands. It's probably not an accident that the free badge stays this narrow, either — Meta already has a paid tier, Meta Verified, sitting right next to it. Give away real identity verification for free and there's less reason for anyone to pay for the fuller version. Keep the free badge to "not an AI" instead, and the subscription still has somewhere to go — especially for the accounts Meta actually wants to keep invested in the platform: creators and public figures with an audience worth pulling in and keeping there.
Which it will, because Meta has a documented habit of doing exactly that. Ask how many times Meta has said a tool "only" does one narrow thing, and look at what happened to the Meta Pixel. It shipped as a simple ad-conversion tracker for website owners — see who clicked, measure a campaign, nothing more. It ended up embedded on hospital patient portals and telehealth checkout pages, and just over a week ago a federal judge forced Meta into discovery over Pixel code that fired on a prescription site before any consent screen even loaded, sending patient and prescription data back to Meta. That case is still active litigation in the same stretch of time Meta is asking people to hand it a facial-recognition selfie and trust the stated purpose. This is also the same company that has paid out over $2 billion across two separate biometric settlements — $650 million to Illinois in 2020, $1.4 billion to Texas in 2024 — for facial recognition it swore was limited, and that pulled facial-recognition code out of its smart glasses app under public pressure as recently as June. None of those settlements...