Tech

A “private and secure” face-search tool left 9 million photos exposed

Published

on

A people-search tool that promises “private and secure” searches left more than 9 million image files exposed online, including photos of people’s faces. A security researcher found the unprotected database, according to reports by WIRED and Digital Trends.

The tool is ClarityCheck, a service that lets someone upload a photo to identify the person in it. Its website tells users that “your reverse image search is private and secure”. The researcher, Jeremiah Fowler, published his findings through ExpressVPN. Fowler is known for finding unsecured databases left open on the internet.

The exposed store held about 450GB of data and needed no password to open, Fowler reported. That is a large trove for a mid-sized consumer service. Many files sat in folders labelled “faces” and “profiles”. They included profile photos, screenshots and other images of adults, teenagers and children.

Fowler put the total at more than 9 million files. The scale is what stands out: a single misconfiguration left millions of faces reachable to anyone with the link.

Advertisement

How it was exposed

The storage was reachable through a web address found in ClarityCheck’s own public website code, according to the reports. Search engines did not index that link, but the files behind it had no lock. The company has since restricted access, the reports said. Fowler notified ClarityCheck, and the company locked the store down afterwards.

Neither report said how long the data had been open before he found it. Fowler said he could not tell whether anyone else had downloaded the files, since the storage kept no public access logs he could review.

There was a second problem too. By changing certain ClarityCheck web addresses and entering a person’s name, someone could surface possible email addresses, phone numbers and physical addresses, WIRED reported. That required no special access. It is a separate weakness from the exposed image store, and it points at the service’s own lookup system rather than a storage bucket.

Fowler found no sign that anyone reached the database with bad intent before the company secured it, the reports said. So far, they have not connected the exposed contact details directly to the exposed photos. The two problems were separate misconfigurations, the reports said, one for the images and one for the personal details.

Advertisement

Why this is sensitive

The nature of the service makes the lapse awkward. ClarityCheck is built to help people check strangers and decide whom to trust online. A leak of its users’ own uploads cuts against that promise. The service asks people to trust it with the very images they use to vet others. ClarityCheck markets the search as a way to spot catfishing and fake dating profiles, according to Digital Trends.

Digital Trends noted that a lapse involving its own users’ uploads is a particularly uncomfortable one for a service sold on trust and safety.

The people in the photos may never have used the tool. ClarityCheck lets a user upload someone else’s face to search for them. That means a person whose face sits in the database may have had no contact with the service at all.

Some of the images appeared to come from social media, dating profiles and screenshots, Fowler reported. That raises the prospect that people had no idea their faces sat in the store.

Advertisement

He also said he found files with timestamps beyond ClarityCheck’s stated 14-day limit for keeping uploaded images. If accurate, that would suggest the service held some images longer than its own policy allows. ClarityCheck did not address the retention point in its statement, the reports said.

What ClarityCheck says

ClarityCheck disputed the description of the store as “publicly exposed”. In a statement to WIRED, the company argued that reaching the files required a specific, unindexed web address. On that basis, it said, the data was not simply open to the public. The company did not dispute the number of files, according to the reports.

The reporting pushes back on that defence. The files themselves carried no password, WIRED and Digital Trends noted, and Fowler found the address inside code on ClarityCheck’s own website. An obscure link is not the same as a protected one, Digital Trends wrote, since a researcher found it and others might too.

TNW has not independently verified the database. The account here rests on Fowler’s research and the reporting by WIRED and Digital Trends, and on ClarityCheck’s statement to WIRED.

Advertisement

A wider pattern

Exposed face data is a recurring problem. In June, the group ShinyHunters published 45GB of Madison Square Garden records that included facial recognition data. Tools that scan faces are spreading, from shop cameras wired to police alerts to services that match a photo to a name. Each new store of face data becomes another target.

The stakes are rising as AI makes it easier to misuse such images. Researchers have warned that generated media has made impersonation and scams simpler to pull off. Analysts have also cautioned that the next privacy breach may not need to leak data in the classic sense to cause harm. A person can change a leaked password; no one can change their face.

Regulators have started to act on large lapses. South Korea fined the retailer Coupang a record sum this year over a major data breach. For the people whose faces sat in ClarityCheck’s store, the worry is simpler: their image was held by a service many of them had never used, and, for a time, anyone who found the link could see it.

Advertisement

Source link

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version