• Zarobi@aussie.zone
    link
    fedilink
    English
    arrow-up
    43
    ·
    edit-2
    9 days ago

    the API endpoint GET [redacted] will return user data for any account - not just your own account - so long as you supply a valid, five-digit user ID. It doesn’t perform any authorization check or ownership validation. “Just increment the number and get someone else’s data,” she wrote.

    This data includes users’ email addresses, first and last names, country, dates of birth, and whether the account has been deleted, and the API exposes all 719,517 accounts on the prayer site. “With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform,” the hacker explained. “One GET request per user. for i in range(1, 719518): scrape(). That’s it. That’s the exploit.”

    My God, that’s horrific. Plus it doesn’t even delete your data if you delete your account, it’s still vulnerable.

    • Appoxo@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      13
      ·
      edit-2
      9 days ago

      I wonder of the vatican is part of the gdpr…
      Would be funny to read about the church getting sued for that.

      • Zarobi@aussie.zone
        link
        fedilink
        English
        arrow-up
        2
        ·
        9 days ago

        I don’t know much about GDPR… is it illegal to have badly written software like this? Technically the user is bypassing normal usage and “hacking” the API

        • Appoxo@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          11
          ·
          9 days ago

          Negligence to delete the account data after termination is a reason to be fined.
          They don’t need to keep that data.
          Afaik the only reason would be if MTX were offered (for book-keeping reasons)

    • Zeoic@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      9 days ago

      5 digit user ids, yet over 700k users? Im sure they must have gone up to 6 digits

      • Zarobi@aussie.zone
        link
        fedilink
        English
        arrow-up
        2
        ·
        9 days ago

        They probably meant 6 digit and it was a typo. The rest of the article references 6 digits. If it’s just an integer (highly likely) it would go up to 10 digits or roughly 2 billion max users. My old coworkers and I used to joke that hitting INTEGER.MAX_VALUE for your customer ID is a good problem to have

      • Earthwormjim91@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        9 days ago

        Unless by “digit” they mean any alphanumeric.

        You’ve got a lot of options if you go to a 5 characters with letters.

        Which they’d kind of have to with 700k users if it’s 5 characters.

        If it’s case insensitive, you’ve got 60,000,000+ combinations, and if case sensitive then 916,000,000+ combinations.

      • Zarobi@aussie.zone
        link
        fedilink
        English
        arrow-up
        0
        ·
        9 days ago

        Maybe I should remove that from my comment lol, I feel like I’m contributing to a data breach or something

          • Zarobi@aussie.zone
            link
            fedilink
            English
            arrow-up
            1
            ·
            9 days ago

            I know, but a lot of people don’t click the article, they just look at headline + comments, so it’s still a reduction of visibility or an extra step. My comment is like exposing the endpoint right there front and centre. Plus, I don’t like being personally responsible for any data breach. Maybe it’s just a tiny thing but it felt like the right thing to do

  • Gork@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    40
    ·
    9 days ago

    The Catholic Church is known for a lot of things. Keeping up with the times (or cyber security) isn’t one of them.

    • jollyrogue@lemmy.ml
      link
      fedilink
      English
      arrow-up
      7
      ·
      9 days ago

      Cyber security isn’t in the bible. Time for an update.

      Cyprus 1:1

      …. Copy pasta of NIST security standards circa May 2026 …

      Nothing could go wrong with this.

  • username_1@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    34
    ·
    9 days ago

    Vatican Programmer: Oh, mighty Lord, sitting in the Sky, show me the way to this bug I seek and eliminate ineffectiveness. Amen.

    • real_squids@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      14
      ·
      9 days ago

      It connects users across the globe to pray for the Holy Father’s intentions, and as of July 2026, it has 719,517 registered accounts

      The only two screenshots they have on GPlay feature prayer scheduling and sharing your prayer.

    • it_depends_man@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      9 days ago

      See, humans are smart. Praying and blessing things yourself? By hand, so to speak? Boooo! Pedestrian! Ain’t nobody got time fo dat!

      https://en.wikipedia.org/wiki/Prayer_flag

      the Tibetans believe the prayers and mantras will be blown by the wind to spread the good will and compassion into all pervading space. Therefore, prayer flags are thought to bring benefit to all.

      By hanging flags in high places the Lung ta will carry the blessings depicted on the flags to all beings. As wind passes over the surface of the flags, which are sensitive to the slightest movement of the wind, the air is purified and sanctified by the mantras.

      I choose to believe that the prayer app is just a hip, new and with it innovation in prayer spreading.

  • eicker@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    9 days ago

    Turns out the biggest miracle wasn’t multiplying loaves, it was making authentication disappear. An IDOR this basic on an app handling personal data is embarrassing. 🙈