Reverse-Lookup Service Exposed Millions of Photos of People’s Faces

A security researcher discovered that a 'people-finder' service called ClarityCheck left millions of sensitive images, including faces and profiles, exposed in an unsecured database. The incident highlights the risks associated with data-scraping services that collect biometric information without user consent.
Why it matters
It raises significant privacy and security concerns regarding the unregulated collection and storage of biometric data by third-party search services.
Overall, according to findings from independent security researcher Jeremiah Fowler, the exposed ClarityCheck database contained roughly 450 GB of images, including what appeared to be profile images, screenshots, and other photographs of adults, teenagers, and children. All of the images were stored in an unsecured Amazon S3 bucket, with files in folders named “faces” and “profiles,” which could be accessed by anyone online through a URL included in the company’s publicly available website code.
ClarityCheck is one of a number of so-called people-finder tools that have appeared online in recent years. These websites broadly claim to be able to search the web, public records, and other databases to identify individuals. ClarityCheck’s website says it can run searches on phone numbers, email addresses, vehicle identification numbers, and names. Its photo-search page says it can help “identify anyone in a photo” and find social media profiles “in seconds.”
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in