ClarityCheck, a people-search tool that markets its services as "private and secure," left a database containing more than 9 million image files publicly exposed. Research by independent security expert Jeremiah Fowler revealed that the exposed data, totaling roughly 450 GB, included profile images and screenshots of adults, teenagers, and children.
A Major Misconfiguration
The images were stored in an unsecured Amazon S3 bucket, with files organized into folders labeled "faces" and "profiles." Anyone online could access these files through a URL embedded within the company’s public website code. A separate misconfiguration involving the site’s APIs also allowed users to manipulate URLs to reveal email addresses and phone numbers simply by entering names into a browser.
The Definition of Exposure
While ClarityCheck secured the database in July after being contacted by WIRED, the company disputed the characterization of the data as "exposed." A spokesperson claimed that an "ordinary member of the public" would not have discovered it, as it required knowledge of a specific, unindexed URL. However, security professionals and the US government maintain that data is exposed if it is reachable on the open internet without authentication, such as a username and password.
- Over 9 million image files were accessible without a password.
- The data included sensitive biometric information like facial landmarks.
- Potential for misuse in AI training or criminal activities like catfishing.
- API flaws exposed contact details including emails and physical addresses.
Security experts warn that the stakes are rising as digital platforms automate the collection of sensitive biometric data. Rebecca Williams, director of strategy at the ACLU, noted that systems built on collecting highly sensitive personal information will inherently carry these risks, regardless of security improvements, because the business model itself depends on the accumulation of such data.