Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
The people-search tool ClarityCheck says its reverse image search service is “private and secure”—but it left a database containing more than 9 million image files exposed.
A security researcher, Jeremiah Fowler, discovered that a people-finder service called ClarityCheck had exposed over 450 gigabytes of images containing faces of adults, teenagers, and children. These photos were stored in an unsecured Amazon S3 bucket, accessible via publicly available URLs. ClarityCheck, one of numerous online people-finder tools, claims to search the web, public records, and databases to identify individuals using phone numbers, email addresses, vehicle identification numbers, and names.
The company acknowledged the issue after WIRED contacted them in July, securing the data but denying it was "publicly exposed." Experts warn that accidental data exposures, especially of sensitive biometric data like face images, pose significant risks. ClarityCheck's website necessitates users to confirm they have permission to upload photos, yet Fowler contends many users were unaware their images were exposed due to the service's identification focus.
The company also misconfigured its APIs, allowing web users to reveal data by entering names, which WIRED reported after contacting the company and securing the URLs. Despite the exposure, ClarityCheck's spokesperson stated that the data were sourced from publicly available information and licensed third-party providers. The increasing automation of digital platforms collecting and analyzing sensitive data raises growing concerns about securing such information.
Written by urgent.news from Wired's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.