top 50 comments

sorted by: hot top controversial new old
[–] 144 points 1 month ago

"We are gathered here today because your thoughts and prayers did not secure our app"

  • source
  • [–] 116 points 1 month ago (9 children)

    Why does it need any personal details at all??

  • source
  • hideshow 9 child comments
  • [–] 20 points 1 month ago (3 children)

    For sharing between users, as I understand it.

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (1 reply)
    [–] 63 points 1 month ago* (last edited 1 month ago) (17 children)

    the API endpoint GET [redacted] will return user data for any account - not just your own account - so long as you supply a valid, five-digit user ID. It doesn’t perform any authorization check or ownership validation. “Just increment the number and get someone else's data,” she wrote.

    This data includes users’ email addresses, first and last names, country, dates of birth, and whether the account has been deleted, and the API exposes all 719,517 accounts on the prayer site. “With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform,” the hacker explained. “One GET request per user. for i in range(1, 719518): scrape(). That's it. That's the exploit.”

    My God, that's horrific. Plus it doesn't even delete your data if you delete your account, it's still vulnerable.

  • source
  • hideshow 17 child comments
  • load more comments (1 reply)
    [–] 56 points 1 month ago (2 children)

    The Catholic Church is known for a lot of things. Keeping up with the times (or cyber security) isn't one of them.

  • source
  • hideshow 2 child comments
  • load more comments (1 reply)
    [–] 50 points 1 month ago (6 children)

    Vatican Programmer: Oh, mighty Lord, sitting in the Sky, show me the way to this bug I seek and eliminate ineffectiveness. Amen.

  • source
  • hideshow 6 child comments
  • load more comments (1 reply)
    [–] 30 points 1 month ago (6 children)

    So uh.. what does a prayer app even do?

  • source
  • hideshow 6 child comments
  • [–] 21 points 1 month ago (2 children)

    It connects users across the globe to pray for the Holy Father’s intentions, and as of July 2026, it has 719,517 registered accounts

    The only two screenshots they have on GPlay feature prayer scheduling and sharing your prayer.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 18 points 1 month ago (1 child)

    Damn, with that many people praying these prayers are about to get real effective. I'm surprised we haven't heard of their effects and effectiveness yet.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 6 points 1 month ago*

    See, humans are smart. Praying and blessing things yourself? By hand, so to speak? Boooo! Pedestrian! Ain't nobody got time fo dat!

    https://en.wikipedia.org/wiki/Prayer_flag

    the Tibetans believe the prayers and mantras will be blown by the wind to spread the good will and compassion into all pervading space. Therefore, prayer flags are thought to bring benefit to all.

    By hanging flags in high places the Lung ta will carry the blessings depicted on the flags to all beings. As wind passes over the surface of the flags, which are sensitive to the slightest movement of the wind, the air is purified and sanctified by the mantras.

    I choose to believe that the prayer app is just a hip, new and with it innovation in prayer spreading.

  • source
  • parent
  • [–] 24 points 1 month ago (3 children)

    It still works lmao

    No email and some other stuff though.... maybe they just removed that from the endpoint?

  • source
  • hideshow 3 child comments
  • load more comments (1 reply)
    [–] 23 points 1 month ago* (2 children)

    As it often is, the source has more information, and significantly so. I also find it much easier and more informative to read. Simple direct speech, headlines, more concrete on what is exposed, more technical details, etc.

    They didn't just send one email to report the vulnerability.

    and on January 3rd I emailed nine people: the general info address, six individual staff members at clicktopray.org, and two contacts at popesprayer.va (the Pope's Worldwide Prayer Network). No response. From any of them.

    For July they have three entries of 'reported to Journalist' ("Dark Reading"), journalist contacted the Pope's Worldwide Prayer Network, and 'still no response'.

    They also posted an update about it being fixed on 2026-07-24 that it has been fixed.

    The authorization check is there now: request your own user ID and you still get your email back, request someone else's and you get a public profile. Names are supposed to be public on a platform where you pray alongside other people, so what's left is what was always meant to be visible.

    I also never got an email. Not an acknowledgment, not a thank you, not a "we've addressed this."

    Given that The Register posted this article on 2026-07-24 22 UTC it must have been very unfortunate timing. Presumably they didn't check the source again before pressing publish? And also haven't noticed or bothered to include an information update.

  • source
  • hideshow 2 child comments
  • [–] 20 points 1 month ago (2 children)

    Misread it as

    Pope's official prayer app, "Cardinal Sin"...

  • source
  • hideshow 2 child comments
  • [–] 18 points 1 month ago

    Why not just give the app away and let people access the content without having them sign up? Oh right.... The people are the product.

  • source
  • [–] 13 points 1 month ago (1 child)

    a pope app? perfect for indulgence micro transactions

  • source
  • hideshow 1 child comment
  • [–] 12 points 1 month ago

    There's a fucking official app for prayers?!

  • source
  • [–] 8 points 1 month ago

    Was this vibe coded?

    That would be rather ironic.

  • source
  • [–] 6 points 1 month ago

    To borrow a tenet from another abrahamic religion, trust in God, but tie up your camel.

  • source
  • [–] 6 points 1 month ago (3 children)

    Is JD Vance in here? He's supposed to be Catholic right?

  • source
  • hideshow 3 child comments
  • [–] 5 points 1 month ago

    Why should they care about security user data? We’re all equal before God.

  • source
  • load more comments
    view more: next ›