That photo you uploaded to identify someone may have ended up somewhere you never expected. Security researcher Jeremiah Fowler discovered an unsecured database linked to ClarityCheck, a people-search service that says its reverse image search is “private and secure,” containing more than 9 million files, including photos of people’s faces. ClarityCheck has built its service around helping people verify strangers and decide who they can trust online, which makes a security lapse involving its own users’ uploads particularly uncomfortable.

According to Fowler’s research published by ExpressVPN, the database held roughly 450GB of data and did not require a password to access. Many of the files were stored inside folders labelled “faces” and “profiles,” and included profile photos, screenshots, and other images of adults, teenagers, and children. The storage location was reportedly accessible through a URL found in ClarityCheck’s publicly available website code. The company has since restricted access.

The people in the photos may never have used ClarityCheck

This is where the situation gets particularly uncomfortable. ClarityCheck lets someone upload a photo to search for the person shown in it, potentially returning social media profiles and other identifying information. That means the person whose face is being searched may have never visited ClarityCheck themselves.

Fowler says some of the images appeared to come from social media, dating profiles, screenshots, and photographs, raising the possibility that people had no idea their faces were sitting inside the database. He also reported finding files carrying timestamps beyond ClarityCheck’s stated 14-day retention period for uploaded images.

ClarityCheck says the photos weren’t really public

In a statement to WIRED, ClarityCheck pushed back on the description that the database was “publicly exposed,” arguing that access required a specific, unindexed URL. However, the files themselves were not password-protected, and Fowler found that URL in code available on ClarityCheck’s own website.

There is no evidence that anyone maliciously accessed the database before it was secured. Still, an obscure URL is not the same as a protected one, and if a security researcher could find it through publicly available code, someone else potentially could too.

ClarityCheck also had a separate security issue involving its website APIs. According to WIRED, manipulating certain ClarityCheck URLs and entering a person’s name could reveal possible email addresses, phone numbers, and physical addresses without requiring any special access.

For now, reports have not indicated that the identifying details were directly linked to the exposed photos. Even so, having your image stored in an unsecured database by a service you may never have used is a serious privacy problem, especially when AI has made impersonation, fake profiles, and scams much easier to pull off.

Share.
Exit mobile version