Skip to main content
  1. Home
  2. Social Media
  3. News

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

A face-search tool left more than 9 million photos sitting unprotected

Researchers found face photos in ClarityCheck’s database that appeared older than its stated 14-day deletion period

Add as a preferred source on Google
Fake alerts on iPhone
NordVPN

That photo you uploaded to identify someone may have ended up somewhere you never expected. Security researcher Jeremiah Fowler discovered an unsecured database linked to ClarityCheck, a people-search service that says its reverse image search is “private and secure,” containing more than 9 million files, including photos of people’s faces. ClarityCheck has built its service around helping people verify strangers and decide who they can trust online, which makes a security lapse involving its own users’ uploads particularly uncomfortable.

According to Fowler’s research published by ExpressVPN, the database held roughly 450GB of data and did not require a password to access. Many of the files were stored inside folders labelled “faces” and “profiles,” and included profile photos, screenshots, and other images of adults, teenagers, and children. The storage location was reportedly accessible through a URL found in ClarityCheck’s publicly available website code. The company has since restricted access.

The people in the photos may never have used ClarityCheck

This is where the situation gets particularly uncomfortable. ClarityCheck lets someone upload a photo to search for the person shown in it, potentially returning social media profiles and other identifying information. That means the person whose face is being searched may have never visited ClarityCheck themselves.

Fowler says some of the images appeared to come from social media, dating profiles, screenshots, and photographs, raising the possibility that people had no idea their faces were sitting inside the database. He also reported finding files carrying timestamps beyond ClarityCheck’s stated 14-day retention period for uploaded images.

ClarityCheck says the photos weren’t really public

In a statement to WIRED, ClarityCheck pushed back on the description that the database was “publicly exposed,” arguing that access required a specific, unindexed URL. However, the files themselves were not password-protected, and Fowler found that URL in code available on ClarityCheck’s own website.

Recommended Videos

There is no evidence that anyone maliciously accessed the database before it was secured. Still, an obscure URL is not the same as a protected one, and if a security researcher could find it through publicly available code, someone else potentially could too.

ClarityCheck also had a separate security issue involving its website APIs. According to WIRED, manipulating certain ClarityCheck URLs and entering a person’s name could reveal possible email addresses, phone numbers, and physical addresses without requiring any special access.

For now, reports have not indicated that the identifying details were directly linked to the exposed photos. Even so, having your image stored in an unsecured database by a service you may never have used is a serious privacy problem, especially when AI has made impersonation, fake profiles, and scams much easier to pull off.

Sudhanshu Kumar Mangalam
I’ve got about 4 years of experience, mostly covering gaming, PC hardware, and smartphones. In my free time, I like…
Child abuse material continues to surface on X despite Elon Musk’s promises
New investigation claims several previously flagged child abuse images were found on X.
X-logo

Elon Musk once called removing child sexual abuse material from X his top priority. Yet new investigations suggest the platform still struggles to keep known abusive content offline. Reviews by The New York Times and the Canadian Center for Child Protection found previously flagged material on X, while Grok generated sexualized images involving children earlier this year.

Grok generated images involving known abuse victims

Read more
Researchers warn that social media can reveal sensitive details about users
Social media activity can reveal your politics, religion, and shopping habits, researchers warn
Social Media

What you post online is only part of the story. A new review of research into social media privacy warns that platforms and third parties can potentially infer sensitive details about people from seemingly ordinary digital activity, including their political opinions, religious leanings and shopping habits.

The findings, as reported by Techxplore, published in the International Journal of Management Concepts and Philosophy, point to a widening gap between the amount of personal information generated online and the legal and ethical protections designed to safeguard it. The researchers examined privacy breaches, regulatory frameworks, and the responsibilities of both social media companies and their users.

Read more
Instagram scammers are holding creators’ accounts hostage with copyright strikes
Meta’s copyright system is being weaponized against the creators it’s supposed to protect
A person holding a phone with the Instagram app open on it.

Imagine waking up to find your Instagram account suspended because someone claims you stole their content. You might know that the claim is false, but appealing it could take weeks. If you're a content creator, each day offline could cost you money. Meanwhile, the person behind the complaint offers to make the problem disappear for just a few hundred dollars.

According to a new BBC investigation, Instagram creators are being hit with this new online racket. Scammers are filing bogus copyright complaints and demanding payment to withdraw them, exploiting the fact that repeated claims can put an account at risk of suspension. The account owner may still have their password and login credentials, but that does little good when their content or account has been taken offline.

Read more