Reverse-Lookup Site Leaked Millions of Face Photos

▼ Summary
– ClarityCheck, a people-search tool claiming private reverse image searches, exposed over 9 million image files, including faces, plus email addresses and phone numbers due to misconfigured Amazon S3 storage.
– Security researcher Jeremiah Fowler found roughly 450 GB of unsecured images in folders named “faces” and “profiles,” accessible via a URL in the company’s public website code, including photos of adults, teenagers, and children.
– ClarityCheck is a people-finder service that identifies individuals from photos, phone numbers, or emails, but users may upload images without the subjects’ knowledge or consent.
– The database was exposed for months before Fowler’s July contact prompted ClarityCheck to restrict access, though his earlier alerts went unaddressed.
– ClarityCheck disputes the “exposed” label, claiming the data required a specific, unindexed URL, but security experts and US federal guidance define exposure as any unauthorized access risk, regardless of whether misuse occurred.
ClarityCheck, a reverse image search tool that brands itself as private and secure, has been found to have left more than 9 million image files, including close-up photos of people’s faces, openly accessible on the internet. A separate configuration flaw also exposed users’ email addresses and phone numbers, according to new research.
Independent security researcher Jeremiah Fowler uncovered the issue, revealing that the exposed ClarityCheck database held roughly 450 GB of images. These included what appeared to be profile pictures, screenshots, and photographs of adults, teenagers, and children. All of the files sat in an unsecured Amazon S3 bucket, organized in folders labeled “faces” and “profiles.” Anyone with the right URL, which was embedded in the company’s own publicly viewable website code, could access them without any password or authentication.
ClarityCheck is part of a growing wave of people-finder services that claim to pull from public records, web searches, and other sources to help identify individuals. The platform advertises searches by phone number, email address, vehicle identification number, and name. Its photo-search feature promises to “identify anyone in a photo” and locate social media profiles “in seconds.”
The company did lock down the massive image database after WIRED reached out in July, but Fowler warns the data was likely exposed for months. His earlier attempts to notify ClarityCheck about the problem went unanswered. Accidental data leaks are risky for any type of personal information, but they are especially dangerous when it comes to biometric data like facial images, which cannot be changed or reissued like a password.
ClarityCheck’s terms require users to confirm they have permission to upload photos. But Fowler stresses that many people whose faces ended up in the database probably had no clue their image was stored there. The service is built for identifying strangers, he notes, not for people to look up themselves or their own acquaintances.
“If you’re trying to find out who a person is, you might not have authorization or permission, so people might not know that their image had been dumped into this database that was public,” Fowler told WIRED. “An AI bot could crawl it, extract faces, and use them for training. And there are lots of pictures of kids in there.”
In a statement to WIRED, a ClarityCheck spokesperson thanked Fowler for flagging the issues and said the company acted quickly once the problem was brought to the relevant teams. “Once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access,” the spokesperson said.
However, the company pushed back on the characterization that the data was “exposed,” arguing that an average internet user would not have stumbled upon it. “We do not accept that data in the temporary storage location was ‘publicly exposed,’ which implies large-scale public access,” the spokesperson said. “Access required knowledge of a specific, unindexed URL that was not discoverable through ordinary use of the ClarityCheck service or a general web search.”
Security experts and the US federal government take a different view. Data is considered exposed if it can be reached by anyone who is not supposed to see it, especially when it sits on the open internet without any login requirement. “Exposure is the state in which personal or sensitive data has been left accessible, discoverable, or otherwise put at risk of unauthorized access, whether or not anyone has yet taken or misused it,” said Mark Beare, head of consumer products at Malwarebytes. “A publicly reachable database backup, a misconfigured storage bucket, or credentials sitting in a system that a researcher can reach are all exposures.”
(Source: Wired)




