Reverse-lookup service exposed millions of photos of people’s faces
Summary
A website called ClarityCheck, which helps people find information about others using photos and personal details, accidentally left over 9 million photos and other personal data publicly accessible online. A security researcher found this issue and alerted the company, which then secured the data, but the exposure lasted for months.Key Facts
- ClarityCheck offers a reverse image search to identify people using photos.
- More than 9 million images, including faces of adults and children, were stored in an unsecured online location.
- The exposed data amounted to around 450 gigabytes of files, including profile pictures and screenshots.
- The images were stored in an Amazon S3 bucket with no password protection, accessible via URL.
- A second security problem exposed email addresses and phone numbers.
- Independent researcher Jeremiah Fowler discovered the exposure and tried to warn ClarityCheck before contacting WIRED.
- ClarityCheck secured the data after learning about the issue but disagreed that the data was truly "exposed" to the public.
- Experts say that any data accessible without login credentials is considered exposed and poses privacy risks.
Read the Full Article
This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.