Published · 4d agoProduct3 min read
A "private and secure" face search left 9 million images in an open bucket
ClarityCheck exposed 450GB of photos plus a second leak of emails and phone numbers, according to researcher Jeremiah Fowler. The company disputes the word "exposed."
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- ClarityCheck's website tells users uploading a photo: "Your reverse image search is private and secure."
- New research shows ClarityCheck left more than 9 million image files, including photographs of people's faces, publicly exposed.
- According to findings from independent security researcher Jeremiah Fowler, the exposed ClarityCheck database contained roughly 450 GB of images, including what appeared to be profile images, screenshots and other photographs of adults, teenagers and children, all stored in an unsecured Amazon S3 bucket with files in folders named "faces" and "profiles".
- The unsecured S3 bucket could be accessed by anyone online through a URL included in the company's publicly available website code.
- A second misconfiguration publicly exposed people's email addresses and phone numbers.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
A people-search site whose upload page promises "Your reverse image search is private and secure" left more than 9 million image files, including photographs of people's faces, reachable on the open internet [1][2]. The tools that employees use to check who they are dealing with are themselves unassessed vendors holding third-party biometric-adjacent data, and this one had no lock on the door. According to research by independent security researcher Jeremiah Fowler, the exposed ClarityCheck store held roughly 450GB of images, including what appeared to be profile pictures, screenshots and other photographs of adults, teenagers and children, all sitting in an unsecured Amazon S3 bucket with folders named "faces" and "profiles" [3]. The access path is the part worth dwelling on: the bucket was reachable by anyone online through a URL included in the company's own publicly available website code [4]. A second misconfiguration exposed email addresses and phone numbers [5], and Fowler found the site's APIs were misconfigured such that its URLs could be manipulated to reveal data about people simply by entering names [6]. ClarityCheck secured the image database after WIRED contacted it in July, but Fowler says it appeared to have been exposed for months and that his initial attempts to flag the problem to the company were unsuccessful [7]. A company spokesperson told WIRED that "once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access" [8]. The company disputes the characterisation that the data was exposed, saying an "ordinary member of the public" would not have come across it and that access "required knowledge of a specific, unindexed URL that was not discoverable through ordinary use of the ClarityCheck service or a general web search" [9]. It also said there is no suggestion of malicious access and that the files include duplicate, cropped and resized copies of the same images along with non-image data, not 9 million unique images [10]. It says it has improved its security reporting procedures [11]. On duplicates, the arithmetic is at least consistent with the company's account: 450GB spread across 9 million files averages about 51KB each, which is thumbnail and crop territory rather than originals [12]. On the unindexed URL, the definition is not the vendor's to set. The security industry and the US federal government treat data as exposed if it could be accessed by people not intended to have access, particularly if it is reachable on the open internet without an authentication requirement [13]. Mark Beare, head of consumer products at Malwarebytes, puts it as "the state in which personal or sensitive data has been left accessible, discoverable, or otherwise put at risk of unauthorized access, whether or not anyone has yet taken or misused it" [14]. A path published in your own front-end code is not obscurity. The operator problem sits in what the product is for. ClarityCheck says it can run searches on phone numbers, email addresses, vehicle identification numbers and names, and its photo-search page says it can help "identify anyone in a photo" and find social media profiles "in seconds" [15]. That is a description of work already being done inside recruiting, fraud, trust and safety and sales teams, and nothing about pasting a photo into a website touches procurement. The site asks uploaders to attest that they have permission to upload the photo [16]. Fowler's point is that the attestation is structurally hollow: the service exists to identify people, and people do not usually set out to identify themselves or people they already know, so those whose faces were in the bucket may have had no idea it held their image [17]. If someone in your organisation ran a candidate's or a counterparty's photo through it, your organisation moved a third party's face into a vendor it never reviewed, and it has no record that it happened.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
ClarityCheck's website tells users uploading a photo: "Your reverse image search is private and secure."
ReportedView cited source - [2]
New research shows ClarityCheck left more than 9 million image files, including photographs of people's faces, publicly exposed.
ReportedView cited source - [3]
According to findings from independent security researcher Jeremiah Fowler, the exposed ClarityCheck database contained roughly 450 GB of images, including what appeared to be profile images, screenshots and other photographs of adults, teenagers and children, all stored in an unsecured Amazon S3 bucket with files in folders named "faces" and "profiles".
ReportedView cited source - [4]
The unsecured S3 bucket could be accessed by anyone online through a URL included in the company's publicly available website code.
ReportedView cited source - [5]
A second misconfiguration publicly exposed people's email addresses and phone numbers.
ReportedView cited source - [6]
In addition to the face data, ClarityCheck had misconfigured its APIs such that its website URLs could be manipulated to reveal data about people simply by entering names.
ReportedView cited source
Sources & coverage · 4 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- wired.comLily Hay Newman, Matt Burgess4d agoReverse-Lookup Service Exposed Millions of Photos of People’s Faces
- 9to5mac.comBen Lovejoy4d agoClarityCheck people-finder left millions of face photos exposed, likely without their knowledge
- thenextweb.comAlina Maria Stan



