AUTO-UPDATED

ClarityCheck people-finder left millions of face photos exposed, likely without their knowledge

The facial-identification service ClarityCheck exposed over nine million user-uploaded photos on an unsecured cloud server, potentially compromising the privacy of adults, teenagers, and children worldwide.

Key Points

  • Security researcher Jeremiah Fowler discovered a database containing 9,042,977 image files totaling 450.2GB of data.
  • The exposed files were neither password-protected nor encrypted, allowing public access to facial images for several months.
  • ClarityCheck facilitates reverse image searches to identify individuals from social media profiles and dating apps without their consent.
  • The company acknowledged ownership of the database and confirmed that the server has since been secured.
  • Exposed data included images of minors, raising significant concerns regarding privacy and potential misuse by malicious actors.

Why it Matters

This breach highlights the severe security risks associated with facial-recognition platforms that aggregate personal data without explicit user authorization. The exposure of these images provides scammers with high-quality assets to facilitate identity theft and sophisticated social engineering fraud.
9to5Mac Published by Ben Lovejoy
Read original