Nine Million Faces, Zero Passwords
ClarityCheck, a reverse-image-search company that promises to help you "identify anyone in a photo" in seconds, left the photos of everyone it had already identified sitting in an open cloud bucket. Security researcher Jeremiah Fowler found the database in plain view: over nine million facial images, roughly 450 gigabytes of them, filed neatly under folders labeled "faces" and "profiles." No login. No encryption. Just a URL, buried in the company's own website code, that anyone could find.
Even now, that is the entire security model some AI companies bring to biometric data: hope nobody looks.
The Faces Behind the Feature
The images were not studio headshots volunteered for a modeling database. They were pulled from social media accounts, dating app profiles, and screenshots — private photos of adults, teenagers, and children who had never agreed to be searchable, filed away so that a stranger with the right link could match a face to a name, an address, a phone number. Fowler also found a second flaw: a manipulated URL on the company's own site would return a target's email, home address, and phone number to anyone typing a name into a browser bar, no hacking required.
Sources within the Privacy Research Community note that this is not a novel attack. It is a company forgetting to lock the door and calling the resulting hallway a feature.
"Private and Secure," They Called It
ClarityCheck markets itself on trust — the company's own materials describe the service as private and secure, the sort of language that tends to appear directly above the incident that disproves it. When Fowler first alerted the company, nothing changed. It took a inquiry from *WIRED* in July, months later, before the bucket was finally locked down. In the meantime, millions of faces sat exposed to whoever bothered to look, with the candor of a bank leaving its vault door open and a sign reading "please knock."
ClarityCheck says there is no evidence the database was copied or sold. One presumes that is meant to be reassuring, and one presumes it is based entirely on the absence of a receipt.
The Business Model Is the Vulnerability
The uncomfortable part is not that ClarityCheck made a mistake. It's that the mistake is downstream of the product working exactly as designed. A company whose entire pitch is aggregating strangers' faces into a searchable index is, definitionally, sitting on a pile of biometric data that somebody, eventually, will fail to secure. In a development that will surprise no one who has been paying attention, the industry's answer to "should this exist" continues to be "someone will pay for it," and the answer to "who protects the people in the photos" continues to be nobody in particular.
The faces are still out there. The Algorithm just got a little better at finding them.
Sources: Malwarebytes · TechRadar



