Capture the discovery before contacting the company, hosting provider or anyone else. Save a full-screen screenshot, the exact URL, a UTC timestamp and the search terms that produced the result, while avoiding further access to exposed data.
On January 27, 1986, engineers at Morton Thiokol joined a teleconference with NASA officials about launching the space shuttle Challenger from Kennedy Space Center. The forecast was unusually cold. Engineer Roger Boisjoly and colleagues had already raised concerns about how the solid rocket booster O-rings performed at low temperatures.
Thiokol’s initial recommendation was not to launch below the temperature supported by its existing flight data. After an internal management discussion, the company reversed that recommendation. Challenger launched the following morning and broke apart 73 seconds later, killing all seven crew members.
The warnings did not disappear with the shuttle. Boisjoly had documented the O-ring problem in a 1985 memo, describing the risk in severe terms. The presidential Rogers Commission later examined that memo, engineering charts and the launch-decision process. Its published report preserved the documentary trail well enough to distinguish what engineers knew from what managers decided.
That distinction matters whenever a researcher finds something online that may vanish as soon as its owner learns about it.
Preserve the discovery screen first
A researcher recently found a 450.2GB exposed database attributed to reverse-lookup service ClarityCheck. The database reportedly contained 9,042,977 profile pictures, screenshots and scanned photographs.
The first useful action in a discovery like this is small: stop and capture the screen.
Take a full-screen screenshot that includes the browser chrome, visible URL, result and system clock where practical. A tightly cropped image may look cleaner, but it removes context that an editor, security team or legal reviewer may later need. Keep the original image file. Make a separate copy if you need to blur personal information for publication.
Record the exact URL as text as well. Screenshots can truncate long addresses, hide redirects or make individual characters hard to read. If the discovery came through a search engine, database index or command-line query, preserve the result page or terminal output without probing further.
The objective is to document what was openly visible at the moment of discovery. It is not an invitation to enumerate records, download samples or test how far access extends.
Write down how you reached it
A screenshot shows what appeared. Your notes should explain how it appeared.
Record the date and time in UTC, including the timezone label. Save the precise search terms, filters and operators used. Note whether you were signed in, using a private window or viewing a cached result. If a search result led through one page to another, write down that sequence in plain language.
These details help another person reproduce the path without guessing. They also separate a chance discovery from later investigative steps.
Keep reported facts distinct from analysis. “The page displayed a database listing attributed to ClarityCheck” describes an observation. “ClarityCheck exposed the database” assigns responsibility and requires stronger evidence. Infrastructure may be shared, copied, mislabeled or operated by a contractor. Attribution deserves its own verification.
The same discipline applies to the contents. A visible count and stated database size can be recorded as displayed. Claims about unique individuals, collection methods or affected countries require further reporting.
Do not alter the evidence while checking it
Once you have the basic record, resist the urge to prove the finding by opening more files. Additional access can expose people, change server logs and cross legal or ethical boundaries.
Avoid downloading personal photographs, running bulk queries, testing credentials or attempting to bypass controls. If one visible record already establishes that sensitive material is accessible, collecting fifty more rarely strengthens the public-interest case. It increases the amount of personal data you now have to secure.
Store your notes and screenshots in a restricted location. Preserve originals and edit copies for circulation. A simple evidence log can record the filename, capture time, URL and a short description. If you later revisit the page, treat that as a new observation with a new timestamp rather than silently replacing the first capture.
This separation resembles the broader problem discussed in The 7:12 a.m. Breach Notice That Told a Founder Nothing: an alert without enough context leaves everyone reconstructing events under pressure.
Contact comes after the record
After preservation, decide who needs to know and what can safely be shared. A concise disclosure should identify the visible issue, when it was observed and enough of the location for the recipient to verify it. Do not email exposed personal data as proof. Offer redacted screenshots where they establish the issue without spreading the material.
Give the recipient a reasonable opportunity to investigate before publication, while avoiding promises about timing or outcomes that you cannot control. Record each contact attempt and any material change to the exposed page.
Roger Boisjoly’s documentation could not prevent Challenger once the launch decision was made. It did allow investigators to reconstruct the warnings and decisions without relying only on memories formed after disaster.
Online evidence is more fragile. A search result can change, a bucket can close and a URL can begin returning an error between discovery and the first reply. Capture the screen, URL, UTC timestamp and search terms before sending the first message.
Comments
No comments yet.