The wrong question at the wrong time
You open an app to order a takeaway or rent a bicycle. Before you can proceed, it asks you to take a selfie and a picture of your driving licence. The request feels jarring. The service does not need to know your legal name or see your face to let you hire a bike. It only needs to be sure you are the same person who registered the account and will pay the bill. This confusion between two distinct processes—authentication and identity proofing—is the root of much unnecessary risk online.
Authentication answers the question, “Are you the same person who was here before?” It is about continuity of access. Identity proofing answers, “Who are you in the real world?” It ties your digital account to a state-issued credential like a passport. Most daily interactions require only authentication. Demanding proof of legal identity for routine access is like a coffee shop asking for your birth certificate to honour your loyalty card. It is a disproportionate demand that hands over sensitive, immutable data where a simple, secure check would suffice.
The default has become the face scan. It is presented as a smooth, modern solution. The reality is that you are often handing your biometric template to an organisation with unclear security practices, for a purpose that does not require it. You cannot change your face if that data is breached. The systems that check ‘liveness’ can sometimes be fooled. You are centralising a high-value target. This essay argues that you should resist this drift. Use strong cryptographic methods for authentication and confine rigorous identity proofing to the few situations that legally demand it.
Authentication: proving you are the same person
For the vast majority of your online accounts, the service’s sole security requirement is to ensure that the person logging in today is the same person who created the account. This is the problem of authentication. The best modern solution is cryptographic, not biometric.
Passkeys are the strongest widely available option for this. A passkey is a cryptographic credential tied to a specific device or security key. When you register, your device generates a unique cryptographic key pair. The public key is stored by the service; the private key never leaves your device. To sign in, your device proves possession of the private key. There is no password to phish, steal, or breach from a server database. It authenticates you as the same person without revealing anything about your real-world identity. For a deeper technical breakdown of how they work beyond the marketing hype, you can read my analysis on passkeys without the marketing.
For the highest-value accounts, a dedicated hardware security key is the gold standard. It is a physical device you plug in or tap. The private key is generated on and confined to the key itself. It provides the same cryptographic guarantee as a passkey but with stronger physical separation, making it resistant to certain advanced attacks that might compromise a device’s built-in secure element.
The principle is simple: for everyday access, use something you have (a cryptographic key) instead of, or in addition to, something you know (a password). This method is private, secure, and does not leak personal information. It solves the authentication problem without creating an identity problem.
Identity proofing: when you must prove who you are
Some interactions legally require you to prove your real-world identity. Opening a bank account, registering a company, or accessing certain government benefits are clear examples. Here, the service has a legitimate need to know who you are, often to comply with regulations like anti-money laundering rules. This is identity proofing.
Even in these cases, a face scan is not the only, nor always the best, option. Several other pathways exist, each with different privacy trade-offs.
The most private method is an in-person document check. You present your physical ID to a trained person at a bank branch or post office. Your document is verified, but no digital copy of your face or ID is necessarily stored by the service provider. The verification is an event, not a data harvest.
In some countries, bank-based verification is an option. You log into your online banking service, which acts as a trusted intermediary to confirm your identity to the requesting service. The new service never sees your banking details, only a confirmation. This leverages an existing, regulated trust relationship.
A growing number of nations offer government-issued digital identity credentials. These range from smart national ID cards with digital certificates to dedicated mobile apps. The idea is that you prove your identity once to the state, and then can use that credential to log into other services privately. The service you access learns only the specific attribute it needs (e.g., “over 18”), not your full identity details. While powerful, this centralises immense trust in the state, a significant trade-off you must consider.
Why the face scan is a poor default
The rush to adopt face scans as a universal proofing tool is a security and privacy misstep. Its flaws are fundamental.
First, biometrics are identifiers, not secrets. You cannot change your face. If the biometric template derived from your selfie is stolen from a company’s database, it is compromised forever. You cannot rotate it like a password. It becomes a permanent key to your identity, useful to attackers for impersonation elsewhere.
Second, liveness detection is an arms race. Systems that ask you to blink or turn your head are trying to defeat photo or video replays. This technology is imperfect and constantly being challenged by sophisticated spoofs, including high-quality deepfakes. A successful bypass grants an attacker a verified identity.
Third, it creates a toxic data honeypot. A centralised database linking millions of faces to names, IDs, and other personal data is a catastrophic breach waiting to happen. The damage from such a leak would be irreversible on an individual and societal scale. The face is becoming the ultimate password, with all the risks that entails, as explored in the face is the password now.
Finally, and most critically, it normalises excessive data collection. When a video game store or food delivery app demands a face scan, it trains you to accept this invasive request as routine. It erodes the boundary between necessary proofing and gratuitous surveillance.
Questions to ask before you upload an ID
When a service insists on an identity document, do not proceed automatically. Pause and interrogate the request. Your questions should determine if the proofing is legitimate and how it will be handled.
Ask yourself: Is this legally required? Does a law or regulation mandate that this specific service collects this specific proof of identity for this specific action? If the answer is unclear, assume it is not required until proven otherwise.
Ask the service: What is the legal basis for this collection? Under which law or regulation are you operating? They should be able to cite it. If they cannot, or cite only their “terms of service,” that is a red flag.
Ask them: How will my data be stored and protected? Will the image of my ID and face be stored? If so, for how long? Is it encrypted at rest? Who has access? A reputable organisation should have clear, accessible answers in a privacy notice.
Ask: What are the alternatives? Can I verify in person? Can I use a bank-based method or a government digital ID? The presence of alternatives is a sign of thoughtful design. Its absence suggests a lazy or data-hungry approach.
Your decision to proceed should be based on the necessity of the service and the credibility of the provider’s answers. For non-essential services making vague demands, the correct answer is often to walk away.
What to do when a service insists on a selfie
You may encounter a service you genuinely need that will not proceed without a selfie or ID scan. You have a hierarchy of options, from pushback to controlled compliance.
First, challenge the request. Contact customer support. Ask, politely but firmly, why a face scan is needed for a service that only requires authentication. Ask if you can use a strong passkey or hardware key instead. Sometimes, the demand is enforced by an automated system but can be overridden by a human. You will not know unless you ask.
Second, seek an alternative service. Competition is a powerful tool. Look for a competitor that offers a similar service without biometric hoops. Your choice to take your business elsewhere is the strongest market signal you can send.
Third, if you must comply, contain the exposure. Use a dedicated email alias for that account. Do not reuse any password. Scrutinise and lock down the account’s recovery options, as these are often the weakest link after a strong login method. A guide on how to do this is available in my piece on how to audit your account recovery options.
Finally, consider the long-term implications of normalising this for minor services. The creep of identity proofing into everyday life is a gateway to more pervasive tracking and control, a theme also relevant to debates around age verification and the identity trap. Your resistance, even in small acts of refusal or questioning, helps defend a sensible boundary.
Questions people ask
Is giving my face scan to a big tech company safe?
No data handover is completely safe, but scale is not a guarantee of security. A large tech company may have better security engineers than a startup, but it also presents a far more attractive and valuable target for attackers. The real issue is permanence. A breached password can be changed; a breached face template cannot. You must trust the company’s security for the rest of your life, a trust that history suggests is often misplaced.
Can I be forced to use a face scan for my job?
This depends on your jurisdiction’s employment and data protection laws. An employer can typically mandate authentication methods for accessing work systems. However, mandating biometric identity proofing for routine access may be disproportionate and legally challengeable. You should ask for the specific risk assessment that justifies the collection of such high-impact biometric data over alternative, less invasive methods like a hardware token.
What is the difference between a face scan for unlocking my phone and one for a website?
The difference is local processing versus remote storage. When you unlock your phone, the face data is processed and stored securely on the device itself. It is not sent to a server. A website’s face scan, however, transmits data derived from your face to the company’s servers for verification and likely storage. The former is a local authentication tool; the latter is a remote identity proofing and data collection exercise.
Are digital government IDs a privacy improvement over face scans?
They can be, if designed with privacy principles. A well-designed government digital ID system allows you to prove specific attributes (like your age) without revealing your full identity. This is called selective disclosure. It is fundamentally different from sending a copy of your passport and a selfie to every service. However, it does place ultimate trust in the government as the identity provider, which carries its own political and surveillance risks that vary by nation.
Close
The conflation of authentication with identity proofing is not a technical oversight; it is a choice that serves data collection interests more than security. You have the tools and the right to push back. For most logins, demand and use proper cryptographic authentication like passkeys. For the rare cases that require proofing, question the method, duration, and legal basis. Prefer in-person checks or privacy-preserving digital credentials where they exist.
Your face is not a convenient login token. It is an immutable part of your identity. Treat it with the gravity it deserves, and reserve its use for situations that truly warrant that level of trust and risk. By understanding the distinction and acting on it, you protect not just your own security, but you also help stem the tide towards a biometric panopticon dressed up as convenience.