Facial Recognition Startup ClarityCheck Left 9 Million Face Photos on an Unsecured Server A people-search tool that promises to identify anyone from a single photograph left more than 9 million image files, including close-ups of adults, teenagers, and children, sitting on an unsecured cloud server for months, according to research published this week. The database, traced to the facial-recognition service ClarityCheck, contained roughly 450 GB of images stored in an Amazon S3 bucket without password protection or encryption. Anyone with the right URL could have browsed folders labeled "faces" and "profiles," downloading what appeared to be profile pictures, screenshots, and other photographs. A second misconfiguration also exposed email addresses and phone numbers through the company's website. The findings come from Jeremiah Fowler, an independent security researcher who has documented a long string of exposed databases in recent years. Fowler told WIRED that he discovered the open bucket while investigating ClarityCheck and that his initial attempts to notify the company went unanswered. The database was only secured after WIRED contacted ClarityCheck in July. ClarityCheck is among the growing number of so-called people-finder tools that have proliferated online. The company's website advertises searches by phone number, email address, vehicle identification number, and name. Its photo-search page claims it can "identify anyone in a photo" and locate social media profiles "in seconds." A WIRED reporter who tested the service with their own face watched as the site said it was "scanning facial landmarks" and "mapping unique face geometry" before returning a report that included the reporter's full name, biography, and links to multiple online photos. The company offers deeper reports, including "hidden dating profiles," for a fee. The site requires users to attest that they have permission to upload any photo they submit. But Fowler argues that this safeguard is essentially meaningless for