Security lapse exposed Clearview AI source code
techcrunch.com
techcrunch.com
Ton-That explained that, “as part of prototyping a security camera product we collected some raw video strictly for debugging purposes, with the permission of the building management.”"
It makes me angry that's all the permission they think they need - and even more so that it's all they are probably legally required to need.
Hey building manager! Wanna make some money with no additional work? We will collect anonymized data from your cameras, but that's it!
https://www.huffpost.com/entry/clearview-ai-facial-recogniti...
Does anyone know the security researcher to ask them to run this? git log --format='%aN' | sort | uniq -c | sort -rn
They contacted Clearview and made sure that the issue was fixed before sharing the information they found with the press. What problem do you see with this? The researchers have no responsibility to keep Cleaeview's failures secret.
No problem with disclosing the vulnerability, but it's definitely problematic making the video footage publicly available—sure, anonymised, but we know how reliable that is, even if done with the best of intentions. At least, that's how I read your parent:
> But it's disquieting that this story appears to include sensitive private information obtained through security research and released directly to a media outlet, including camera footage apparently taken from a compromised cloud storage bucket. That's not how security research works.
Which is why they informed the press that Clearview kept that footage and made it publicly available.
I understand the point you're trying to make, but a small amount of proof is necessary to verify such claims. A few seconds showing that some people were at an apartment building is unlikely to be sensitive, and it's entirely possible they contacted the people before publishing.
I wasn't trying to make the point, only to emphasise my grandparent's point.
But, for what it's worth, I agree with that point: the journalists probably needed to see the video footage as proof, but there was no need for the journalists to publish the video footage. If I don't trust reporters when they tell me that they've seen the footage themselves, then why would I trust them when they show me footage that could have come from anywhere but that they say came from a data leak?
The residents may have signed away their rights to surveillance footage being shared with 3rd party "partners" like in many privacy agreements in U.S. If that's the case, it probably wasn't clear to them what they were signing, and how the footage would be used.
Now that this has come to light, I wonder if the next chapter involves some legal action from these residents? Would they have a case?
NYC has really progressively renters rights and many public advocacy groups who may want to study the rental agreements that make this stuff possible.
AFAIK under GDPR it would be imposssible to share those data without explicit, free, informed consent of all affected persons [1]. Even if shared, you have a right to information with whom the data was shared (and for which purpose) and a right for demanding erasure.
[1] https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
seems grey to me
I believe ptacek was complaining about unilateral disclosure. I'm arguing that the researcher was pushed into it. However, it's still grey: just because you are presented with an option you simply don't like, doesn't mean you leak actual data. You can still disclose the breach without exposing the data. It's very grey.
Most people who self-host Gitlab doesn't realize that between the default self-registration and "Explore" button at the bottom, possible for entirely random individuals to gain enormous access.
I have written the Naval Postgraduate School several times since December about their open Gitlab server (maybe it is supposed to be open though) which seems exposed via the "Explore" tab at the bottom: https://204.102.228.54/users/sign_in
Smartphone apps for interfacing with a SaaS are now "Clearview AI source code"?
Directly before what you quote:
> The repository contained Clearview’s source code, which could be used to compile and run the apps from scratch. The repository also stored some of the company’s secret keys and credentials, which granted access to Clearview’s cloud storage buckets. Inside those buckets, ...