A reverse image search and people-finder service that promises users that their reverse image search is "private and secure" has been found to have left over 9 million image files exposed online, including photographs of people's faces.
The images were found by independent security researcher Jeremiah Fowler in an unsecured Amazon S3 bucket, which is a type of cloud storage. The photos were of adults, teenagers, and children, and included profile pictures, screenshots, and other photos. The images were organized in folders labeled "faces" and "profiles."
Fowler said the database, which was about 450 GB in size, was likely exposed for months, and that he had tried to inform the company, ClarityCheck, about it earlier, but received no response. The URL of the S3 bucket was discoverable through the website's publicly available code, meaning that anyone could have accessed it online.
Fowler told WIRED that the fact that the images were exposed in this way is particularly concerning because faces can be used to identify people, and unlike other sensitive personal information, a face cannot be changed. "An AI bot could crawl it, extract faces, and use them for training. And there are lots of pictures of kids in there," he said.
The purpose of ClarityCheck – to identify people – also means that those whose photos are in the database are unlikely to have given their consent for it to be there.
But the promise of privacy and security made by ClarityCheck – whose business model is to collect and then sell access to sensitive data – is not only ironic but also apparently false. Fowler's discovery was not the only security flaw found in the service.
After he contacted WIRED, the publication was able to find another one – by manipulating the website's URLs, email addresses, home addresses, and phone numbers of people could be revealed simply by typing their name in a browser. This did not require any special tools, just an ordinary browser, and anyone could have done it.
ClarityCheck reacted by securing both the S3 bucket and fixing the URL vulnerability. But the company disputes that the images were exposed "publicly," because, according to a spokesperson, "an ordinary member of the public" would not have been able to find the URL. They also said there was "no suggestion of malicious access."
However, Malwarebytes' Mark Beare said that data is exposed when it is "left accessible, discoverable, or otherwise put at risk of unauthorized access, whether or not anyone has yet taken or misused it."
ClarityCheck also said the number of unique images was much lower than 9 million, as the total number included duplicates, as well as copies of images that were cropped or resized, and non-image data. The company also said that the addresses and phone numbers were "sourced from publicly available information and licensed third-party data providers."
Leaks like this are increasingly common and will be more of a problem in the future as data brokers continue to collect personal information on people and digital ID laws are encouraging ID uploads.

