One open link in the source code of the ClarityCheck page revealed a photo of 9 million people

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
398
Reaction score
645
Deposit
0$
The service of searching people ClarityCheck promised to users private and safe checking of photos, but more than 9 million files with adults and children were available on the Internet without a password.

The problem was discovered by the security specialist Jeremaya Fowler. According to him, the open storage contained 9 042 977 images with a total volume of about 450.2 GB. Among the files were profile photos, screenshots and regular photos of adults, teenagers and children.

The files were stored in Amazon S3 cloud storage in directories with the names "faces" and "profiles." The database was not protected by password or encryption, and the storage address was found directly in the source code of the public page ClarityCheck. Amazon recommends shutting down public access to S3 if open storage is not required for the service to operate.

ClarityCheck allows you to search for information about a person by name, phone number, email and photos. When uploading the image, the user must confirm that he has the right to transmit the image. The current policy of the service also states that only photos that the user is entitled to dispose of can be downloaded.


Fowler believes the people depicted in the pictures might not have known at all that their photos had been uploaded. The service is designed to establish the identity of a stranger, so the permission of the person himself could be absent. Photographs of persons are particularly dangerous, since such a biometric feature cannot be replaced as a password or bank card number.

The specialist also noticed files that were stored longer than the declared period. According to the terms of ClarityCheck, the images uploaded for reverse search must be temporarily stored for 14 days, after which the service promises to remove them automatically.

After the notification, the company restricted access to the storage. ClarityCheck did not agree with the wording about the public leak, as in order to get the files, it was necessary to know a special non-indexable address. The U.S. Cybersecurity and Infrastructure Agency attributes Internet-acceptable misconfigured resources to the external risk surface and advises to close access to all systems that do not need it.

Fowler found no signs that outsiders were downloading the base. It is possible to check whether third parties have access to it only on the internal journals of ClarityCheck. The company also said it had improved the reception of vulnerability messages.

A separate error affected the ClarityCheck software interface. Changing the request address in a regular browser, you could get email addresses, phones and physical addresses associated with the specified name. After the notification, ClarityCheck closed this method of access and stated that the information came from open sources and from licensed data providers.
 
Top Bottom