Reverse-Lookup Service Exposed Millions of Photos of People’s Faces

← Back to the feed

Reverse-Lookup Service Exposed Millions of Photos of People’s Faces

Wired · 2 hours ago

Security researcher Jeremiah Fowler discovered that ClarityCheck, a reverse-image people-search service, left more than 9 million image files — including facial photographs of adults, teenagers and children — publicly accessible online, despite the site's promise that searches are "private and secure." A separate misconfiguration also exposed users' email addresses and phone numbers. The exposure is particularly concerning because it involved biometric data, which cannot be changed once compromised, and because many people whose faces appeared in the database likely never knew they had been uploaded, given the service's purpose is to identify people without their involvement.

The roughly 450GB of images were stored in an unsecured Amazon S3 bucket, in folders labelled "faces" and "profiles", accessible via a URL embedded in the company's public website code. Fowler said the database appeared to have been exposed for months and that his initial attempts to alert ClarityCheck went unanswered; the company secured it only after WIRED made contact in July. ClarityCheck disputed that the data was genuinely "exposed", arguing the URL was not publicly discoverable, though security experts and the US government generally classify unauthenticated, internet-reachable data as exposed regardless of whether it was indexed or accessed.

  • ClarityCheck left 9 million+ face photos publicly exposed online
  • Unsecured S3 bucket also leaked emails and phone numbers
  • Company disputes "exposed" label; secured data after WIRED enquiry

Software

Read the full article at the source →