Yoti's age verification service shares facial photographs and device fingerprints with third-party companies, raising privacy concerns for users seeking age-gated content access.
The age verification platform transmits biometric data beyond its direct operations, according to findings shared on tech forums. Users undergoing Yoti's age checks unknowingly have their facial images and device identifiers distributed to external parties.
The practice affects anyone using Yoti for age verification across websites and services. Device fingerprints—unique identifiers tied to hardware and software configurations—are collected alongside facial data.
Yoti's data-sharing practices lack prominent disclosure at the point of verification. Users attempting to access age-restricted content face the choice of submitting biometric data with limited transparency about downstream recipients.
The revelation prompted 112 points of discussion on Hacker News, with 24 comments addressing privacy implications. Questions emerged regarding consent mechanisms and regulatory compliance under GDPR and similar frameworks.
No statement from Yoti was immediately available regarding the scope or purpose of third-party data sharing.
Security research firms METR and Redwood have published a detailed postmortem examining the HuggingFace security incident. The analysis provides technical insights into how the breach occurred and what systems were compromised.
More than a decade of Steam files, including beta builds and finished games from Valve and third-party developers, have been exposed in a major data leak totaling over 12 terabytes.
A new vulnerability called Omarchy allows any user-level process to gain root privileges through privilege escalation. The flaw has sparked significant discussion in security circles.
Hacking group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group. Security researchers confirmed the breach included detailed customer, booking, and travel records.