A face-recognition tool exposed over 9 million photos without adequate protection.
The photo you uploaded to identify someone might have ended up in an unexpected place. Security researcher Jeremiah Fowler uncovered an unsecured database associated with ClarityCheck, a people-search service that claims its reverse image search is "private and secure." This database contained over 9 million files, including images of individuals' faces. ClarityCheck operates on the premise of assisting users in verifying unknown individuals and determining who they can trust online, making a security breach involving its users’ uploads particularly troubling.
According to Fowler’s research published by ExpressVPN, the database contained approximately 450GB of data and did not require a password for access. Many of the files were organized in folders labeled "faces" and "profiles," including profile pictures, screenshots, and various images of adults, teens, and children. The storage was reportedly accessible through a URL discovered in the publicly available code of ClarityCheck’s website. The company has since limited access.
The individuals in the photos may not have ever used ClarityCheck.
This aspect of the situation is especially concerning. ClarityCheck allows users to upload a photo to search for the individual depicted, potentially returning social media profiles and other identifying information. This means that the person whose face is being investigated may have never even visited ClarityCheck.
Fowler noted that some images seemed to originate from social media, dating profiles, screenshots, and personal photographs, raising the possibility that individuals were unaware their faces were stored in the database. He also reported finding files with timestamps exceeding ClarityCheck’s claimed 14-day retention period for uploaded images.
ClarityCheck contends that the photos were not truly public.
In a statement to WIRED, ClarityCheck disputed the characterization of the database as "publicly exposed," arguing that access required a specific, unindexed URL. However, the files were not password-protected, and Fowler located that URL in code available on ClarityCheck’s own site.
There is no evidence that anyone with malicious intent accessed the database before it was secured. Nevertheless, an obscure URL is not synonymous with a protected one, and if a security researcher could find it through publicly accessible code, others potentially could as well.
ClarityCheck also faced a different security concern involving its website APIs. According to WIRED, manipulating certain ClarityCheck URLs and entering a person's name could reveal possible email addresses, phone numbers, and physical addresses without special access.
So far, reports have not suggested that the identifying details were directly linked to the compromised photos. Nonetheless, having your image stored in an unsecured database by a service you may not have utilized raises significant privacy concerns, particularly in an era where AI has made impersonation, fake profiles, and scams much easier to execute.
Other articles
A face-recognition tool exposed over 9 million photos without adequate protection.
A security researcher discovered over 9 million facial images stored in an unsecured ClarityCheck database that did not require a password for access.
