Uploading a photo to the people-search tool ClarityCheck comes with a reassuring promise: “Your reverse image search is private and secure.” The reality, according to independent security researcher Jeremiah Fowler, was rather less comforting. The service left more than 9 million image files publicly accessible — and a separate misconfiguration exposed people’s email addresses and phone numbers on top of that.
The numbers are stark. Fowler found roughly 450 GB of images sitting in an unsecured Amazon S3 bucket, sorted into folders bluntly labeled “faces” and “profiles”. Inside were profile pictures, screenshots and photographs of adults, teenagers and children. Anyone could reach the files through a URL that was baked into the company’s own publicly available website code.
ClarityCheck belongs to a growing crop of people-finder services that claim to identify individuals by trawling the web, public records and third-party databases. Its search box accepts phone numbers, email addresses, vehicle identification numbers and names. The photo-search page pitches an even bolder trick: it says it can “identify anyone in a photo” and surface their social media profiles “in seconds.”
A WIRED reporter who tested the tool with their own face watched the site announce that it was “scanning facial landmarks” and “mapping unique face geometry” before spitting out a report. For a fee, that report could include a full name, addresses, location history, public appearances, photos, videos, social media profiles and even “hidden dating profiles.” In the reporter’s case, it correctly named them and linked to multiple photos online.
The privacy problem cuts deeper than a typical leak. Face images are biometric data — you cannot reset your face the way you would reset a password. And because the whole point of ClarityCheck is to identify strangers, the people in that bucket almost certainly never knew their images were there.
“If you’re trying to find out who a person is, you might not have authorization or permission, so people might not know that their image had been dumped into this database that was public,” Fowler told WIRED. “An AI bot could crawl it, extract faces, and use them for training. And there are lots of pictures of kids in there.”
ClarityCheck secured the database after WIRED made contact in July, and later locked down the manipulable API URLs that had been leaking names, addresses and phone numbers. But Fowler says the data appeared to have been exposed for months, and his early warnings went unanswered.
The company pushed back on the word “exposed,” arguing that reaching the data required knowledge of a specific, unindexed URL and that the trove included duplicate, cropped and resized copies rather than 9 million unique images. Security professionals see it differently. “A publicly reachable database backup, a misconfigured storage bucket, or credentials sitting in a system that a researcher can reach are all exposures,” said Malwarebytes’ Mark Beare.
ClarityCheck says it has since improved its security-reporting procedures. The subscription, for the record, runs $29.99 a month.