A "private and secure" facial recognition tool has inadvertently exposed 9 million images.

A "private and secure" facial recognition tool has inadvertently exposed 9 million images.

      A people-search tool claiming "private and secure" searches has inadvertently exposed over 9 million image files online, including images of individuals' faces. A security researcher discovered the unsecured database, as reported by WIRED and Digital Trends.

      The tool, named ClarityCheck, allows users to upload a photo to identify the person depicted in it. Its website assures users that "your reverse image search is private and secure." The researcher, Jeremiah Fowler, shared his findings via ExpressVPN, and he is recognized for uncovering unsecured databases available online.

      According to Fowler, the exposed database contained roughly 450GB of data and could be accessed without a password. This represents a significant amount of data for a mid-sized consumer service. Numerous files were organized in folders labeled "faces" and "profiles," which included profile pictures, screenshots, and other images of adults, teens, and children.

      Fowler estimated the total number of files at over 9 million, highlighting the sheer scale of the exposure: a single configuration mistake allowed millions of faces to be accessible to anyone with the link.

      How the exposure occurred

      The storage was accessible via a web address found within ClarityCheck’s own public website code, as per the reports. Although search engines did not index that link, the files were left unsecured. Reports indicate that the company has since limited access. Fowler informed ClarityCheck, and the company secured the database shortly after.

      Neither report specified how long the data had been accessible before it was discovered. Fowler mentioned he could not determine whether anyone else had downloaded the files, as the storage did not maintain any public access logs for his scrutiny.

      There was also a secondary issue. By modifying certain ClarityCheck web addresses and inputting a person's name, someone could retrieve possible email addresses, phone numbers, and physical addresses, as reported by WIRED. This did not require special access, distinguishing it from the exposed image database, and it pointed to the service's own lookup system rather than the storage itself.

      Fowler found no evidence that anyone accessed the database with malicious intent before ClarityCheck secured it. So far, there has been no direct link made between the exposed contact information and the uncovered photos. The two issues were identified as separate misconfigurations, one related to the images and the other to personal information.

      Why this issue is sensitive

      The nature of the service adds complexity to the situation. ClarityCheck is designed to help users verify strangers and determine whom to trust online. A leak of its users' uploads undermines that assurance. The service relies on people trusting it with the very images they use to evaluate others. ClarityCheck promotes its search as a means to identify catfishing and fake dating profiles, according to Digital Trends.

      Digital Trends remarked that an incident involving its own users' uploads is particularly troubling for a service marketed on trust and safety.

      Moreover, individuals whose images were included in the database may have never used the tool themselves. ClarityCheck allows users to upload a photo of someone else to search for that individual. Thus, a person's face included in the database may not have any involvement with the service.

      Fowler noted that some images appeared to originate from social media, dating profiles, and screenshots, raising concerns that individuals might be unaware that their faces were included in the database.

      He also reported finding files with timestamps extending beyond ClarityCheck's stated 14-day limit for retaining uploaded images. If correct, this suggests that the service retained certain images longer than its own policy permits. The reports indicated that ClarityCheck did not address this retention issue in its response.

      What ClarityCheck says

      ClarityCheck contested the characterization of the database as "publicly exposed." In a statement to WIRED, the company argued that accessing the files required a specific, unindexed web address, claiming that the data was not readily available to the public. The company did not dispute the file count mentioned in the reports.

      The reporting challenges that defense. WIRED and Digital Trends pointed out that the files were not password-protected, and Fowler discovered the link within ClarityCheck's own website code. An obscure link does not equate to a protected one, Digital Trends stated, as it was found by a researcher and could potentially be located by others as well.

      TNW has not independently verified the database's details. The narrative here is based on Fowler's research, along with the coverage by WIRED and Digital Trends, and ClarityCheck's response to WIRED.

      A broader pattern

      The issue of exposed facial data is becoming increasingly common. In June, the group ShinyHunters released 45GB of records from Madison Square Garden that included facial recognition data. Technologies that scan faces are becoming more widespread, from surveillance cameras connected to police alerts to services that match photographs to names. Each new collection of facial data becomes a target for potential misuse.

      The risks are escalating as AI simplifies the misuse of such images. Researchers have cautioned that the rise of generated

Other articles

Motorola's sleek new charging puck enters the ranks of Android's compact magnetic accessories. Motorola's sleek new charging puck enters the ranks of Android's compact magnetic accessories. Leaked photos show Motorola’s Moto Snap magnetic wireless charger, which could provide the Qi2-enabled Edge 70 Max with a charging accessory similar to Pixelsnap. YouTube is employing a carrot-and-stick strategy to prevent leading creators from becoming too friendly with Netflix. YouTube is employing a carrot-and-stick strategy to prevent leading creators from becoming too friendly with Netflix. According to a recent Bloomberg report, YouTube is providing millions to leading creators to discourage them from signing deals with Netflix, as the platform aims to retain its most prominent stars. A $1.3 billion loan will assist in constructing a data center for Anthropic in Texas. A $1.3 billion loan will assist in constructing a data center for Anthropic in Texas. Eagle Point is providing approximately $1.3 billion in financing for a 2,900-acre data center in Texas, which is supported by Anthropic, as part of a $16 billion arrangement with Google backing the senior debt. OpenAI is introducing ChatGPT advertisements in 31 European nations. OpenAI is introducing ChatGPT advertisements in 31 European nations. OpenAI will be extending ChatGPT advertisements to 31 European nations next week, marking its most extensive advertising launch to date. According to the company, these ads will be accessible only to Free and Go users. Google provides Gemini Live with an upgrade focused on Deep Research. Google provides Gemini Live with an upgrade focused on Deep Research. Gemini Live can now initiate Deep Research reports using voice commands, process them in the background, and allow you to discuss the results when they are completed. Trump invites cryptocurrency leaders as the SEC suggests its most favorable regulations to date. Trump invites cryptocurrency leaders as the SEC suggests its most favorable regulations to date. On Tuesday, the SEC suggested exemptions for tokens and a conditional safe harbor. The following day, Trump welcomed cryptocurrency executives at the White House.

A "private and secure" facial recognition tool has inadvertently exposed 9 million images.

ClarityCheck, a tool for searching people that claims to offer “private and secure” searches, was discovered by a security researcher to have left over 9 million image files unprotected.