ClarityCheck said it has “improved” its security reporting procedures so that security researchers can contact the company more effectively in the future.
In addition to exposing facial data, ClarityCheck reportedly misconfigured an API that allowed users to manipulate website URLs and search for personal information by entering someone’s name. The issue could be exploited through any standard consumer web browser. Entering a name into certain URLs generated suggestions containing email addresses, physical addresses, and phone numbers associated with people who shared that name. After being contacted, ClarityCheck secured the affected URL. A company spokesperson said the information shown in its results is “obtained from public information and authorized third-party data providers.”
ClarityCheck’s reverse face search feature allows users to upload an image and receive a report showing where the image may appear online and who is pictured. A WIRED reporter tested the service with a photo of his own face. The website claimed to “scan for facial landmarks” and “map unique facial shapes” before comparing the image with other online photos. Its paid reports may include a person’s full name, address, location history, public appearances, photos, videos, social media profiles, and even “hidden dating profiles.” The report generated for the reporter included his name, biographical details, and links to multiple online photos.
Misconfigured databases and accidental data leaks are common online, but increasingly powerful digital platforms can make these incidents more damaging. Automated data-collection features can quickly gather, analyze, and expose sensitive personal information, creating significant privacy and cybersecurity risks.
“Because the model itself relies on the collection of sensitive data, any system that relies on sensitive personal information to authenticate individuals will continue to have these risks, even with enhanced data-minimization and security practices,” said Rebecca Williams, director of privacy and data governance strategies at the American Civil Liberties Union.
Fowler stressed that exposed personal data—including photos—is increasingly valuable to fraudsters and cybercriminals. “Let’s say I’m catfishing people in crime gear. I’ll scroll through all these photos and pick the 20 most attractive people and use their images and AI to create a persona,” Fowler said.
This story first appeared on WIRED.com.
Source: arstechnica.com


