Age verification vendor Persona left frontend exposed, researchers say
ID: 515ce351-4678-54a2-bce5-b887cbe5152d
STIX ID: report--515ce351-4678-54a2-bce5-b887cbe5152d
Feed Name: Malwarebytes Blog
Researchers found a publicly exposed Persona frontend on a U.S. government–authorized endpoint with 2,456 files that detail Persona’s broad biometric and surveillance stack — including 269 verification checks, facial recognition against watchlists and politically exposed persons, adverse-media screening across 14 categories, and retention of PII (names, government IDs, phone numbers, IPs, device/browser fingerprints, and selfies) for up to three years. The exposure raises significant privacy and trust concerns for platforms reported to use Persona (Discord, OpenAI/ChatGPT, Roblox, Lime); the exposed code was later removed and Discord reportedly ceased using Persona for age verification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
