Clearview AI Source Code Exposed in Major Security Lapse
A misconfigured server exposes the secretive facial recognition startup's source code, apps, and internal credentials to the open internet, raising serious privacy concerns.
A major security lapse exposes the secretive facial recognition startup Clearview AI, allowing anyone on the internet to access its closely guarded source code and internal files. Cybersecurity firm SpiderSilk discovers that a misconfigured setting on a protected repository lets anyone register as a new user and log in to the system. This breach reveals the underlying code needed to compile and run Clearview's controversial surveillance apps from scratch.
The exposed repository contains much more than just source code, as it also grants access to secret keys and credentials for Clearview's cloud storage buckets. Inside these buckets, the company stores finished apps for Windows, Mac, Android, and iOS, alongside early testing versions of the software. Furthermore, the leak includes Clearview's Slack tokens, which potentially give hackers password-less access to the company's private messages and internal communications.
This discovery brings intense new scrutiny to a company that already faces massive backlash over its privacy practices and massive database of scraped social media images. Clearview founder Hoan Ton-That responds by claiming the company faces constant cyber intrusion attempts and recently sets up a bug bounty program to improve its security. However, this visible failure to secure its own highly sensitive infrastructure raises serious doubts about the startup's ability to protect the vast amounts of personal data it collects.