2026年8月21日 · 星期五
● 每日更新·改变自己
Eurekar·TOP
捕捉真实世界的英语信号
25信息来源
12,659精选文章
168单词卡片
18照片图片
全部8,201口语2,071外贸4免费1,065帖子4,167新闻1,602hackernews1,187techmeme748tmz640slashdot527techcrunch497arstechnica431随笔330外刊291Cards168simonwillison100sethgodin60图片18information3
← 返回

反向查找服务暴露了数百万张人脸照片

2026-08-21 slashdot

← 上一篇返回列表下一篇 →

# Reverse-Lookup Service Exposed Millions of Photos of People's Faces

# 反向查找服务暴露了数百万张人脸照片

来源: wired.com | 主题: Privacy | 评论: 17

时间: on Thursday August 20, 2026 @01:05PM


Security researcher Jeremiah Fowler found that people-search service ClarityCheck left more than 9 million image files accessible in an unsecured Amazon S3 bucket , despite advertising its reverse-image search as "private and secure." A separate misconfiguration also exposed email addresses, phone numbers, and other personal information. Wired reports: Overall, according to findings from independent security researcher Jeremiah Fowler, the exposed ClarityCheck database contained roughly 450 GB of images, including what appeared to be profile images, screenshots, and other photographs of adults, teenagers, and children. All of the images were stored in an unsecured Amazon S3 bucket, with files in folders named "faces" and "profiles," which could be accessed by anyone online through a URL included in the company's publicly available website code. ClarityCheck is one of a number of so-called people-finder tools that have appeared online in recent years. These websites broadly claim to be able to search the web, public records, and other databases to identify individuals. ClarityCheck's website says it can run searches on phone numbers, email addresses, vehicle identification numbers, and names. Its photo-search page says it can help "identify anyone in a photo" and find social media profiles "in seconds." While ClarityCheck secured the giant image database after WIRED contacted the company in July, Fowler warns that it was seemingly exposed for months, and his initial efforts to flag the problem to the company were unsuccessful. Accidental data exposures create risk for any personal information, but particularly for sensitive and unchangeable biometric data like face images. [...] In addition to the face data, ClarityCheck had also misconfigured its APIs such that its website URLs could be manipulated to reveal data about people simply by entering names; anyone using any consumer browser could have done this. Entering a name into one of the URLs would return multiple potential email addresses, physical addresses, and phone numbers for people with that name. After WIRED contacted the company, the URLs were secured. The ClarityCheck spokesperson said in the statement that the details displayed were "sourced from publicly available information and licensed third-party data providers." A spokesperson for ClarityCheck said in a statement: "Once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access." The company disputed any characterization that the data was "exposed," saying that an "ordinary member of the public" would not have come across it. "We do not accept that data in the temporary storage location was 'publicly exposed,' which implies large-scale public access," the spokesperson says. "Access required knowledge of a specific, unindexed URL that was not discoverable through ordinary use of the ClarityCheck service or a general web search."

⋯ 继续阅读请开通会员 ⋯

🔒

MEMBERS ONLY

这篇是会员专享内容,你看到的是预览段。

会员每天解锁 6000+ 篇真实英语素材——双语科技、口语、外刊、单卡,不设上限。

年会员 ¥365 —— 一天一块钱,续费一直能用。

了解会员 →

已是会员?点此登录解锁全文。

← 上一篇返回列表下一篇 →