Urgent.News

What's breaking now, across thousands of outlets.

Editions

Tech

Reverse-Lookup Service Exposed Millions of Photos of People's Faces

Security researcher Jeremiah Fowler found that people-search service ClarityCheck left more than 9 million image files accessible in an unsecured Amazon S3 bucket, despite advertising its reverse-image search as "private and secure." A separate misconfiguration also exposed email addresses, phone numbers, and other personal information. Wired reports: Overall, according to findings from…

Security researcher Jeremiah Fowler discovered that people-search service ClarityCheck had left over 9 million image files unprotected in an Amazon S3 bucket, contradicting the company's claims of privacy and security. The exposed database, totaling approximately 450 GB of images, included profile pictures, screenshots, and photographs of individuals ranging from adults to children. These files were stored in an unsecured bucket, accessible via URLs embedded in the company's publicly accessible website code.

ClarityCheck, one of many online people-finder tools, advertised its ability to search the web, public records, and databases to identify individuals. The company's website claimed the service could identify people in photos and locate their social media profiles. Despite securing the image database after Wired contacted the company in July, Fowler claimed the issue had been exposed for months, and his attempts to alert the company were unsuccessful.

Beyond the exposed images, ClarityCheck also misconfigured its APIs, allowing anyone to view sensitive personal information by manipulating website URLs with names. Entering a name in these URLs would display multiple potential email addresses, physical addresses, and phone numbers for people with that name. After Wired's intervention, the problematic URLs were remedied.

ClarityCheck's spokesperson stated that the displayed details were sourced from publicly available information and licensed third-party data providers. However, the spokesperson denied that the data was "exposed," arguing that an ordinary member of the public would not have discovered it. They emphasized that access required knowledge of a specific, unindexed URL, not accessible through regular use of the ClarityCheck service or general web searches.

Written by urgent.news from Slashdot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at yro.slashdot.org →

More in Tech

More from Thursday 20 August →