The facial-identification service ClarityCheck exposed over nine million user-uploaded photos on an unsecured cloud server, potentially compromising the privacy of adults, teenagers, and children worldwide.
Key Points
- Security researcher Jeremiah Fowler discovered a database containing 9,042,977 image files totaling 450.2GB of data.
- The exposed files were neither password-protected nor encrypted, allowing public access to facial images for several months.
- ClarityCheck facilitates reverse image searches to identify individuals from social media profiles and dating apps without their consent.
- The company acknowledged ownership of the database and confirmed that the server has since been secured.
- Exposed data included images of minors, raising significant concerns regarding privacy and potential misuse by malicious actors.