Accueil / Apps & Logiciels / ClarityCheck people-finder left millions of face photos exposed, likely without their knowledge

ClarityCheck people-finder left millions of face photos exposed, likely without their knowledge

ClarityCheck, a facial-identification tool for which it’s hard to think of many legitimate uses, reportedly left millions of face photos publicly exposed on the internet in a major privacy breach.

It’s likely that the vast majority of victims had no idea their photos had been uploaded to the site, and had never granted consent …

The service allows anyone to upload a photo of someone in order to carry out a reverse search of things like social media sites in order to identify them. ClarityCheck requires people to agree they have permission to upload the photo, but security researcher Jeremiah Fowler told Wired he was extremely skeptical about this.

He notes the service is explicitly designed for identification, and people don’t typically seek to identify themselves or people they [already] know.

The website has blog posts including Find Someone on Dating Sites by Email and How to Find Someone on Hinge (Even Without Matching).

Farrell told ExpressVPN that more than nine million image files uploaded to ClarityCheck were left publicly accessible on a cloud server for several months, noting that these were primarily facial images, though this included some duplication in the form of cropped and resized images.

I recently discovered a publicly exposed database that was neither password-protected nor encrypted. The database contained approximately 9,042,977 image files totaling 450.2GB of data. The exposed records consisted primarily of facial images stored in folders labeled “faces” and “profiles.” In a limited sample of the exposed images I reviewed as part of the investigation, I observed facial images of adults, teens, and children […]

Many of the uploaded images I saw may have originated from third-party sources such as private profiles, social media accounts, dating app accounts, screenshots, or physical photographs uploaded by third-party users.

He tracked the database to ClarityCheck, and the company acknowledged ownership and said it has now secured the data.

One of the risks identified by Fowler is that the photos and their associated identities could be used by scammers to create fake social media posts intended to fool family and friends. A very common scam is to impersonate a family member in an emergency situation requiring immediate funds to be sent. Having access to face photos could certainly help facilitate this type of fraud.

We’ve previously outlined nine steps you can take to protect yourself against hackers and scammers.

FTC: We use income earning auto affiliate links. More.

Check out 9to5Mac on YouTube for more Apple news:

Privacy is a growing concern in today's world. F…

Ben Lovejoy is a British technology writer and EU Editor for 9to5Mac. He’s known for his op-eds and diary pieces, exploring his experience of Apple products over time, for a more rounded review. He also writes fiction, with two technothriller novels, a couple of SF shorts and a rom-com!

Origine de l’article : lire l’article original
Traduction