The Login Screen Is Becoming an Identity System

Person holding a smartphone, representing the personal device as a modern digital identity key
Source: Pexels.

The most interesting information-technology story this week was not a new device or an AI release. It was the quiet expansion of what software is willing to call identity. Google now lets eligible users prepare a selfie video as a recovery method for their accounts. Facebook is adding free seller verification to a dedicated Marketplace app. And a US border-search case reported by TechCrunch put the unsettling opposite case on display: a password is not merely a way in; it is also a pressure point when somebody else wants in.

These are very different products and circumstances, but together they suggest a shift I think we should take seriously. Identity is ceasing to be a login screen at the edge of a service. It is becoming a continuous product decision—one that shapes recovery, trust, fraud prevention, marketplace participation, and personal safety.

Passwords were attractive because they created a clean fiction. A secret string could stand in for a person, and systems could treat successful entry as the end of the question. That fiction has been deteriorating for years. Passwords are phished, reset, reused, disclosed, and coerced. Two-factor authentication and passkeys improved matters, but they did not remove the more basic problem: people lose phones, change devices, travel, get locked out, and sometimes face a context in which revealing a credential is not a free choice.

Google’s new selfie-video option is a practical response to the first half of that problem. As the company explains, a user records a short guided video in advance, then can use another guided selfie to regain access later. The company says the stored video is encrypted, optional, deletable, and used for sign-in unless the user opts into additional uses. Ars Technica’s coverage adds an important boundary: the feature is not available for Advanced Protection accounts. That detail is more illuminating than any launch slogan. It shows that the industry does not regard facial verification as a universal replacement for stronger account controls. It is a recovery tool with a particular trade-off: easier access in exchange for storing a more permanent kind of personal signal.

That trade-off is not merely about privacy. Biometric data changes the failure mode. A leaked password can be changed. A compromised recovery email can be replaced. A face cannot be reissued. Google says its flows use liveness checks and defenses against impersonation, but the need for those layers tells us what has changed: identity systems now have to judge whether the evidence came from a live person, a recording, a synthetic video, or an attacker who has learned the choreography.

The same move from credential to judgment appears in commerce. TechCrunch reported that Facebook is launching a separate Marketplace app for sellers and adding a free verification system. On its face, this is a feature for people trying to sell a sofa or run a small online business. In practice, it is an acknowledgement that a marketplace is only as useful as its ability to tell a plausible seller from a fraudulent one. Platforms once tried to treat identity checks as an unpleasant compliance cost. They are increasingly becoming a visible part of the product—the thing a participant receives in return for giving the platform better evidence about who they are.

Then there is the darker edge. TechCrunch’s report on an allegation involving a “duress” password during a border search is a reminder that a credential can be designed not only for convenience but for hostile conditions. Whether a particular claim is proved in court is separate from the larger lesson. Security design has usually imagined an attacker at a distance: a phishing email, a malware implant, a breached database. People also encounter threats while standing in front of someone with legal authority, physical control of a device, or the ability to make refusing costly. A serious account-security model has to acknowledge that environment too.

This is why authentication can no longer be evaluated just by asking whether it blocks strangers. We should ask a wider set of questions. Can I recover my account when ordinary factors fail? What irreversible information must I hand over to gain that convenience? Can the service explain which signals it uses and let me remove them? Does verification make a platform safer without turning participation into surveillance? What happens when a user is under pressure?

There is no perfect answer. A system that asks for very little evidence may be easy to abuse. A system that demands too much evidence may exclude people or build a permanent identification database. The right design is not a single strongest factor. It is a set of options, clear boundaries, and a way to step back when the context changes. Google’s recovery flow, marketplace verification, passkeys, recovery contacts, and device protections all belong in that larger design conversation.

The main IT story, then, is that trust is moving closer to the user experience. It is no longer enough for platforms to hide identity decisions in a security team’s backend. The way you prove that you are you—and the way a service decides to believe you—is becoming one of the most consequential interfaces in technology. We should treat it with the same skepticism and care we bring to any other product surface.

References