www.biometricupdate.com
ClarityCheck Exposes Millions of Facial Biometrics in Unsecured Database
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
Cybersecurity researcher Jeremiah Fowler discovered that ClarityCheck, a reverse-image lookup service, left over 9 million facial images accessible in an unsecured Amazon S3 bucket. The database, containing approximately 450.2 GB of data, included profile images and photographs of adults, teens, and children. Despite ClarityCheck's claims of privacy and security, the exposed data was accessible via URLs found in the company's website code. Additionally, misconfigured APIs exposed personal information such as email addresses and phone numbers. After being notified, ClarityCheck secured the database, but the exposure had been ongoing for months. Fowler emphasized the need for companies to treat biometric data as sensitive information. The incident highlights significant vulnerabilities in data handling practices within tech companies.
Key Points: • Over 9 million facial images were exposed in an unsecured Amazon S3 bucket. • ClarityCheck's misconfiguration also leaked personal information like email addresses and phone numbers. • The database was accessible for months before being secured after being reported.