Urgent.News

What's breaking now, across thousands of outlets.

Editions

Tech

Reverse-lookup service exposed millions of photos of people’s faces

People-search tool ClarityCheck left database containing more than 9M image files exposed.

Reverse-lookup service exposed millions of photos of people’s faces

An independent security researcher discovered that a popular reverse-lookup service, ClarityCheck, had inadvertently exposed over 9 million images, including facial photographs of individuals, on an unsecured Amazon S3 bucket. The website had claimed that its reverse image search function was private and secure, but it appears the company neglected proper security measures.

In addition to the exposed images, the misconfiguration also led to the public disclosure of thousands of email addresses and phone numbers. The bulk of the images, numbering around 450 gigabytes, appeared to be profile pictures, screenshots, and photographs of adults, teenagers, and children. These files were organized in folders named "faces" and "profiles," making them easily accessible through a URL included in the company's publicly available website code.

ClarityCheck is just one of many people-finder tools that have emerged online in recent years, offering to search the web, public records, and other databases to identify individuals. The tool's services include searching phone numbers, email addresses, vehicle identification numbers, names, and even running a photo-search function to identify people in images and find their social media profiles quickly.

Written by urgent.news from Ars Technica's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at arstechnica.com →

More in Tech

Supply chain attack on arrayref (Rust blog)

The Rust blog reports on a malicious crate, called proc-macro1 , that was uploaded to the crates.io repository. Furthermore, we discovered that the popular arrayref crate had recently been republished…

More from Thursday 20 August →