ClarityCheck Exposes 9 Million Images on Unsecured Database

People-search platform ClarityCheck left over 9 million image files, including biometric data, exposed on an unsecure AWS database for months.

Jason Kwon ·

ClarityCheck Exposes 9 Million Images on Unsecured Database

ClarityCheck, a platform specializing in people searches, inadvertently exposed more than 9 million image files on an unsecured Amazon Web Services (AWS) database. This oversight left sensitive biometric data accessible without requiring password protection. The exposed data cache comprised approximately 450 gigabytes, organized into folders designated for faces and user profiles.

The security vulnerability persisted for several months. The company only secured the system in July, after independent security researcher Jeremiah Fowler reported the exposure. This incident highlights ongoing challenges in data security within platforms that handle extensive personal information.

Infrastructure Vulnerabilities Identified

ClarityCheck's service is designed to identify individuals rapidly by querying public records and other databases. Its capabilities extend beyond reverse image searches to include queries based on phone numbers, email addresses, vehicle identification numbers, and names.

Fowler discovered the open Amazon S3 bucket through unindexed URLs embedded within the company's public website code. Further exacerbating the issue, a distinct infrastructure flaw in the platform's application programming interface (API) also exposed private email addresses and phone numbers. This API vulnerability permitted manipulation of URLs, allowing data about individuals to be revealed simply by entering names into a standard web browser.

Corporate Response and Data Risks

A spokesperson for ClarityCheck confirmed that the company immediately restricted access upon receiving the notification. The representative clarified that the exposed cache contained duplicate, cropped, and resized copies, rather than 9 million unique images. The company disputed the characterization of the event as a public exposure, contending that access necessitated knowledge of specific URLs not discoverable through typical use or general web searches.

However, cybersecurity protocols generally define data as exposed if it resides on the open internet without authentication requirements, irrespective of search engine indexing. The exposure of facial images presents significant privacy risks, primarily because biometric data, once compromised, cannot be altered. Fowler noted a critical concern that automated systems could crawl the cache to extract faces for training artificial intelligence models, potentially escalating risks for minors whose images were part of the database.

Future Security Measures

Following the data exposure incident, ClarityCheck announced new measures to bolster its security practices. The company has implemented upgraded security reporting procedures. These new protocols aim to more effectively manage future disclosures of vulnerabilities, indicating a commitment to preventing similar incidents.

The incident serves as a reminder of the complex security challenges faced by companies that aggregate and store large volumes of personal and biometric data. Ensuring robust authentication and access controls remains paramount in safeguarding user privacy and maintaining public trust in digital platforms.

More stories