Reverse-Lookup Service Exposed Millions of Photos of People's Faces (wired.com) 17
Security researcher Jeremiah Fowler found that people-search service ClarityCheck left more than 9 million image files accessible in an unsecured Amazon S3 bucket, despite advertising its reverse-image search as "private and secure." A separate misconfiguration also exposed email addresses, phone numbers, and other personal information. Wired reports: Overall, according to findings from independent security researcher Jeremiah Fowler, the exposed ClarityCheck database contained roughly 450 GB of images, including what appeared to be profile images, screenshots, and other photographs of adults, teenagers, and children. All of the images were stored in an unsecured Amazon S3 bucket, with files in folders named "faces" and "profiles," which could be accessed by anyone online through a URL included in the company's publicly available website code.
ClarityCheck is one of a number of so-called people-finder tools that have appeared online in recent years. These websites broadly claim to be able to search the web, public records, and other databases to identify individuals. ClarityCheck's website says it can run searches on phone numbers, email addresses, vehicle identification numbers, and names. Its photo-search page says it can help "identify anyone in a photo" and find social media profiles "in seconds." While ClarityCheck secured the giant image database after WIRED contacted the company in July, Fowler warns that it was seemingly exposed for months, and his initial efforts to flag the problem to the company were unsuccessful. Accidental data exposures create risk for any personal information, but particularly for sensitive and unchangeable biometric data like face images.
[...] In addition to the face data, ClarityCheck had also misconfigured its APIs such that its website URLs could be manipulated to reveal data about people simply by entering names; anyone using any consumer browser could have done this. Entering a name into one of the URLs would return multiple potential email addresses, physical addresses, and phone numbers for people with that name. After WIRED contacted the company, the URLs were secured. The ClarityCheck spokesperson said in the statement that the details displayed were "sourced from publicly available information and licensed third-party data providers." A spokesperson for ClarityCheck said in a statement: "Once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access." The company disputed any characterization that the data was "exposed," saying that an "ordinary member of the public" would not have come across it.
"We do not accept that data in the temporary storage location was 'publicly exposed,' which implies large-scale public access," the spokesperson says. "Access required knowledge of a specific, unindexed URL that was not discoverable through ordinary use of the ClarityCheck service or a general web search."
ClarityCheck is one of a number of so-called people-finder tools that have appeared online in recent years. These websites broadly claim to be able to search the web, public records, and other databases to identify individuals. ClarityCheck's website says it can run searches on phone numbers, email addresses, vehicle identification numbers, and names. Its photo-search page says it can help "identify anyone in a photo" and find social media profiles "in seconds." While ClarityCheck secured the giant image database after WIRED contacted the company in July, Fowler warns that it was seemingly exposed for months, and his initial efforts to flag the problem to the company were unsuccessful. Accidental data exposures create risk for any personal information, but particularly for sensitive and unchangeable biometric data like face images.
[...] In addition to the face data, ClarityCheck had also misconfigured its APIs such that its website URLs could be manipulated to reveal data about people simply by entering names; anyone using any consumer browser could have done this. Entering a name into one of the URLs would return multiple potential email addresses, physical addresses, and phone numbers for people with that name. After WIRED contacted the company, the URLs were secured. The ClarityCheck spokesperson said in the statement that the details displayed were "sourced from publicly available information and licensed third-party data providers." A spokesperson for ClarityCheck said in a statement: "Once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access." The company disputed any characterization that the data was "exposed," saying that an "ordinary member of the public" would not have come across it.
"We do not accept that data in the temporary storage location was 'publicly exposed,' which implies large-scale public access," the spokesperson says. "Access required knowledge of a specific, unindexed URL that was not discoverable through ordinary use of the ClarityCheck service or a general web search."
security (Score:2)
Tied to names or not ? (Score:2)
If they are not, this is not important. Anyone who leaves their basement exposes their face to being photographed.
It would be good if the summary had mentioned it.
Re: (Score:3)
The fact that this type of event is more or less normalized is the real problem.
Re:Tied to names or not ? (Score:4, Funny)
> Anyone who leaves their basement...
Whew!
Re: (Score:2)
Those energy drinks are not helping you.
We do not accept your lack of acceptance (Score:2)
The company disputed any characterization that the data was "exposed," saying that an "ordinary member of the public" would not have come across it.
Well then, it's a good thing only "ordinary members of the public" would ever dream of trying to crack your service to provide unintended access! Those pesky Russian hackers would never dream of using means "not discoverable through ordinary use", right?
Heh (Score:2)
Then I suggest demonstrating your sincerity. Dump your intimate photos and PII in your temporary storage location.
Re: (Score:2)
Simple dishonest denial after getting caught doing something completely incompetent.
Collecting photos of random children? (Score:3)
Millions of photos of children? Why would they want that?
Re: Collecting photos of random children? (Score:2)
Worry about real problems
What difference does it make? (Score:3)
Whether this site was insecure or not matters not at all. If I can just pay for access then it's no different then if access was free. The end results are precisely the same for privacy. These assholes very likely just bought up a shit ton of personal data congregated by Meta and the like.
So ohh my, the site that lets people look people up was insecure. The fact the site exist at all is the actual problem.
Accidental data exposure? (Score:1)
A fun 2026 game show (Score:2)
AI = Actually Indian contractors
AI = some vibe coding idiot who has no idea what they're doing
It only takes one person (Score:3)
yayyy (Score:2)
we are back o using obscurity as security. cloud great because you can fire your resources and it will be cheaper ,argument for AI is also back.
They're all the same (Score:2)
These privacy rapists are all the same!
Classical gross incompetence (Score:2)
I mean, leaving an S3 bucked unsecured in 2026? You have to live under a rock with regards to security to screw up this badly. Well, obviously the industry cannot do it. Time to regulate and punish.