this post was submitted on 25 Jul 2026
455 points (98.9% liked)

Technology

87180 readers
3476 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] thatradomguy@lemmy.world 116 points 3 weeks ago

"We are gathered here today because your thoughts and prayers did not secure our app"

[–] luthis@lemmy.nz 96 points 3 weeks ago (6 children)

Why does it need any personal details at all??

[–] Valmond@lemmy.dbzer0.com 36 points 2 weeks ago

So that jesus can torture the bad persons.

[–] real_squids@sopuli.xyz 16 points 3 weeks ago (1 children)

For sharing between users, as I understand it.

[–] luthis@lemmy.nz 15 points 3 weeks ago (1 children)

Username, password is all they need for that. Idiots.

[–] Appoxo@lemmy.dbzer0.com 3 points 2 weeks ago (1 children)
load more comments (1 replies)
[–] jollyrogue@lemmy.ml 10 points 2 weeks ago

So they know what sins I’ve committed.

They don’t follow my mastodon feed. It’s much easier that way.

[–] tacosanonymous@mander.xyz 6 points 2 weeks ago

Historically? Abuse.

I’m sure they say it’s for security : blocking bots, etc and getting their newsletter or some shit.

[–] Blackmist@feddit.uk 4 points 2 weeks ago

They need the list of who's been naughty and who's been nice.

Or is that the other fella?

load more comments (1 replies)
[–] Gork@sopuli.xyz 48 points 3 weeks ago (2 children)

The Catholic Church is known for a lot of things. Keeping up with the times (or cyber security) isn't one of them.

[–] jollyrogue@lemmy.ml 9 points 2 weeks ago

Cyber security isn’t in the bible. Time for an update.

Cyprus 1:1

…. Copy pasta of NIST security standards circa May 2026 …

Nothing could go wrong with this.

load more comments (1 replies)
[–] Zarobi@aussie.zone 45 points 2 weeks ago* (last edited 2 weeks ago) (4 children)

the API endpoint GET [redacted] will return user data for any account - not just your own account - so long as you supply a valid, five-digit user ID. It doesn’t perform any authorization check or ownership validation. “Just increment the number and get someone else's data,” she wrote.

This data includes users’ email addresses, first and last names, country, dates of birth, and whether the account has been deleted, and the API exposes all 719,517 accounts on the prayer site. “With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform,” the hacker explained. “One GET request per user. for i in range(1, 719518): scrape(). That's it. That's the exploit.”

My God, that's horrific. Plus it doesn't even delete your data if you delete your account, it's still vulnerable.

[–] Appoxo@lemmy.dbzer0.com 13 points 2 weeks ago* (last edited 2 weeks ago) (4 children)

I wonder of the vatican is part of the gdpr...
Would be funny to read about the church getting sued for that.

load more comments (4 replies)
[–] Zeoic@lemmy.world 6 points 2 weeks ago (6 children)

5 digit user ids, yet over 700k users? Im sure they must have gone up to 6 digits

[–] ViatorOmnium@piefed.social 6 points 2 weeks ago

I tried the endpoint. 5 digits always gives you a valid user, 6 stops working after some point.

[–] Zarobi@aussie.zone 4 points 2 weeks ago* (last edited 2 weeks ago)

They probably meant 6 digit and it was a typo. The rest of the article references 6 digits. If it's just an integer (highly likely) it would go up to 10 digits or roughly 2 billion max users. My old coworkers and I used to joke that hitting INTEGER.MAX_VALUE for your customer ID is a good problem to have

load more comments (4 replies)
[–] themachinestops@lemmy.dbzer0.com 5 points 2 weeks ago (3 children)

It sill works, you get first name and last name.

load more comments (3 replies)
load more comments (1 replies)
[–] username_1@discuss.tchncs.de 45 points 3 weeks ago (3 children)

Vatican Programmer: Oh, mighty Lord, sitting in the Sky, show me the way to this bug I seek and eliminate ineffectiveness. Amen.

[–] bitjunkie@lemmy.world 33 points 3 weeks ago (2 children)

Still better than vibe coding

[–] real_squids@sopuli.xyz 14 points 3 weeks ago

The OG vibecoders

[–] Appoxo@lemmy.dbzer0.com 3 points 2 weeks ago (1 children)

How so? They are praying for it to work

[–] Axolotl_cpp@feddit.it 4 points 2 weeks ago

Well, i pray to not have any runtime bug too

[–] ripcord@lemmy.world 11 points 2 weeks ago

Vatican Programmer: Contractor in India

load more comments (1 replies)
[–] FartMaster69@lemmy.dbzer0.com 28 points 3 weeks ago (4 children)

So uh.. what does a prayer app even do?

[–] real_squids@sopuli.xyz 19 points 3 weeks ago (1 children)

It connects users across the globe to pray for the Holy Father’s intentions, and as of July 2026, it has 719,517 registered accounts

The only two screenshots they have on GPlay feature prayer scheduling and sharing your prayer.

[–] Kissaki@feddit.org 14 points 2 weeks ago (1 children)

Damn, with that many people praying these prayers are about to get real effective. I'm surprised we haven't heard of their effects and effectiveness yet.

[–] caurvo@aussie.zone 3 points 2 weeks ago

I'd like to see the media mix modeling data to really assess the ROP of these prayers. Cross check that against miracle count and we'll really be cooking.

[–] jollyrogue@lemmy.ml 12 points 2 weeks ago

It leaks personal data.

[–] a1studmuffin@aussie.zone 12 points 2 weeks ago* (last edited 2 weeks ago)

Press F to pray respects

[–] it_depends_man@lemmy.world 6 points 2 weeks ago* (last edited 2 weeks ago)

See, humans are smart. Praying and blessing things yourself? By hand, so to speak? Boooo! Pedestrian! Ain't nobody got time fo dat!

https://en.wikipedia.org/wiki/Prayer_flag

the Tibetans believe the prayers and mantras will be blown by the wind to spread the good will and compassion into all pervading space. Therefore, prayer flags are thought to bring benefit to all.

By hanging flags in high places the Lung ta will carry the blessings depicted on the flags to all beings. As wind passes over the surface of the flags, which are sensitive to the slightest movement of the wind, the air is purified and sanctified by the mantras.

I choose to believe that the prayer app is just a hip, new and with it innovation in prayer spreading.

[–] Kissaki@feddit.org 21 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

As it often is, the source has more information, and significantly so. I also find it much easier and more informative to read. Simple direct speech, headlines, more concrete on what is exposed, more technical details, etc.

They didn't just send one email to report the vulnerability.

and on January 3rd I emailed nine people: the general info address, six individual staff members at clicktopray.org, and two contacts at popesprayer.va (the Pope's Worldwide Prayer Network). No response. From any of them.

For July they have three entries of 'reported to Journalist' ("Dark Reading"), journalist contacted the Pope's Worldwide Prayer Network, and 'still no response'.

They also posted an update about it being fixed on 2026-07-24 that it has been fixed.

The authorization check is there now: request your own user ID and you still get your email back, request someone else's and you get a public profile. Names are supposed to be public on a platform where you pray alongside other people, so what's left is what was always meant to be visible.

I also never got an email. Not an acknowledgment, not a thank you, not a "we've addressed this."

Given that The Register posted this article on 2026-07-24 22 UTC it must have been very unfortunate timing. Presumably they didn't check the source again before pressing publish? And also haven't noticed or bothered to include an information update.

[–] Soup@lemmy.world 11 points 2 weeks ago (1 children)

“Pope sprayer .va” is how I’m choosing to read that.

[–] lena@gregtech.eu 20 points 3 weeks ago (2 children)

It still works lmao

No email and some other stuff though.... maybe they just removed that from the endpoint?

[–] hexagonwin@lemmy.today 7 points 2 weeks ago (1 children)

lmao did they vibe patch it or smth

load more comments (1 replies)
load more comments (1 replies)
[–] CyberChicken@whatcom.social 19 points 3 weeks ago (1 children)

Misread it as

Pope's official prayer app, "Cardinal Sin"...

[–] jollyrogue@lemmy.ml 5 points 2 weeks ago (1 children)

That’s the official Catholic hook up app. It’s different.

Actually….

load more comments (1 replies)
[–] spacehulk@lemmy.zip 13 points 2 weeks ago

Why not just give the app away and let people access the content without having them sign up? Oh right.... The people are the product.

[–] expatriado@lemmy.world 11 points 3 weeks ago (1 children)

a pope app? perfect for indulgence micro transactions

load more comments (1 replies)
[–] Martineski@lemmy.dbzer0.com 10 points 2 weeks ago

There's a fucking official app for prayers?!

[–] jollyrogue@lemmy.ml 8 points 2 weeks ago

Was this vibe coded?

That would be rather ironic.

[–] CubitOom@infosec.pub 6 points 2 weeks ago (1 children)

Is JD Vance in here? He's supposed to be Catholic right?

[–] AllNewTypeFace@leminal.space 5 points 3 weeks ago

To borrow a tenet from another abrahamic religion, trust in God, but tie up your camel.

[–] CriticalMiss@lemmy.world 3 points 2 weeks ago

Why should they care about security user data? We’re all equal before God.

[–] magnetosphere@fedia.io 3 points 2 weeks ago

I’ve seen so many stories about leaks that I skip most of them. I’m glad I didn’t skip this one.

load more comments
view more: next ›