When someone uploads a photo to the people-search platform ClarityCheck, the website displays a clear message: “Your reverse image search is private and secure.” However, a new investigation found that more than 9 million image files—including photos of people’s faces—were publicly accessible through the website. A separate security misconfiguration also exposed users’ email addresses and phone numbers.
The exposed ClarityCheck database contained approximately 450 GB of images, including profile pictures, screenshots, and other photos that appeared to show adults, teenagers, and children, according to independent security researcher Jeremiah Fowler. The files were stored in an unsecured Amazon S3 bucket, organized into folders named “faces” and “profile.” Anyone who discovered the relevant URL could access the files online through information contained in ClarityCheck’s publicly available website code.
ClarityCheck is one of several people-search services that have emerged online in recent years. These platforms generally claim to search the web, public records, and other databases to identify individuals. According to ClarityCheck, users can search by phone number, email address, vehicle identification number, or name. The company’s reverse image search page also claims that users can “identify people in photos” and find social media profiles “in seconds.”
After WIRED contacted the company in July, ClarityCheck secured the large image database. Fowler said, however, that the files appeared to have been exposed for months and that his initial attempts to notify the company were unsuccessful. Data breaches can put all types of personal information at risk, but exposed facial images are particularly sensitive because biometric data is difficult—if not impossible—to change.
Fowler also noted that, although ClarityCheck asks users to confirm that they have permission to upload photos, the people depicted in those images may not have known that the company was storing their faces. The service is designed to identify other people, meaning users are unlikely to upload images solely to identify themselves or people they already know.
“If you’re trying to find out who someone is, they may not have permission or authorization, so people may not know that their images are being dumped into this public database,” Fowler told WIRED. “An AI bot can crawl through it, extract faces, and use them for training. There are a lot of pictures of kids in there.”
In a statement to WIRED, a ClarityCheck spokesperson acknowledged Fowler’s efforts to report the issue. “Once this matter was brought to the attention of the appropriate teams, we took immediate action to restrict access,” the spokesperson said.
The company disputed the characterization that the data had been “exposed,” stating that the “general public” had not accessed it. “It is not acceptable for data in temporary storage to be ‘publicly available,’ which implies massive public access,” the spokesperson said. “Access required knowledge of specific, unindexed URLs that could not be discovered through normal use of the ClarityCheck service or through general web searches.”
Data exposure is a concern not only for the security industry but also for the United States federal government. Data is generally considered compromised when it is accessible to unauthorized individuals, particularly over the open internet without authentication measures such as usernames and passwords. “Exposure is when personal or sensitive data is accessible, discoverable, or at risk of unauthorized access, whether or not someone else has taken it or misused it,” said Mark Beare, head of consumer products at security firm Malwarebytes. “Backups of publicly accessible databases, misconfigured storage buckets, and credentials residing within systems accessible to researchers are all at risk.”
Source: www.wired.com


