People-search site ClarityCheck left 9 million face photos publicly exposed
ClarityCheck, a people-search website that promises users their reverse image searches are "private and secure," left more than 9 million image files openly accessible on the internet, according to research by independent security researcher Jeremiah Fowler. The exposed Amazon S3 bucket contained roughly 450 GB of data stored in folders labeled "faces" and "profiles," reachable by anyone who knew the URL embedded in the company's own publicly available website code. A second misconfiguration separately exposed users' email addresses and phone numbers. The images included photographs of adults, teenagers, and children, sensitive biometric data that, unlike a password, cannot simply be changed if it falls into the wrong hands.
The exposure is especially troubling given what ClarityCheck is designed to do. The service explicitly markets itself as a tool to identify strangers from photos and find their social media profiles in seconds, meaning the people whose faces ended up in the database likely never knew they were there and almost certainly never consented to it. Fowler warns the bucket appeared to have been exposed for months before it was secured, and his initial attempts to alert the company went nowhere. He also flagged that an automated bot could have crawled the database, harvested the face images, and used them to train AI models. ClarityCheck disputes the word "exposed," arguing that finding the URL required specific knowledge not available through ordinary browsing, and has since secured the database.
No comments:
Post a Comment