A cybersecurity researcher has uncovered a 450 GB database left unprotected by ClarityCheck, a search engine that can identify people online from a photograph.
Because of an error by ClarityCheck, a reverse-search website, a 450.2 GB folder had been left openly accessible on the web. The concern is that the file may have contained photographs of individuals. ClarityCheck’s services can identify someone using a telephone number, email address and other information. It also offers photo-based searches, which can help users locate a person’s profile on social media or dating websites.
ClarityCheck’s exposed 450.2 GB database
The issue was found by cybersecurity researcher Jeremiah Fowler, whose investigation was published by the ExpressVPN blog. According to Fowler, the folder could be accessed online without password protection or encryption. At the time of writing, ClarityCheck had already resolved the problem. “As soon as this was brought to the attention of the relevant teams, we immediately took steps to restrict access,” the website confirmed.
No malicious access detected
The positive news is that ClarityCheck says there is no evidence of malicious access to the folder. “It was necessary to know the specific, unlisted URL of a page that was not accessible through normal use of the ClarityCheck service or through a general Internet search,” the website also explained.
ClarityCheck disputes the image count
ClarityCheck has also challenged part of Jeremiah Fowler’s investigation. In his report, the researcher referred to more than 9 million image files stored in the folder of more than 400 GB. “In a limited sample of the exposed images I examined as part of the investigation, I observed images of the faces of adults, teenagers and children,” Jeremiah Fowler also wrote.
However, ClarityCheck stated that “the data concerned includes duplicate, cropped and resized copies of the same files, as well as data unrelated to images; therefore, these are not 9 million unique images.”
Comments
No comments yet. Be the first to comment!
Leave a Comment