• spacehulk@lemmy.zip
    link
    fedilink
    English
    arrow-up
    15
    ·
    20 hours ago

    Why not just give the app away and let people access the content without having them sign up? Oh right… The people are the product.

  • Kissaki@feddit.org
    link
    fedilink
    English
    arrow-up
    21
    ·
    edit-2
    1 day ago

    As it often is, the source has more information, and significantly so. I also find it much easier and more informative to read. Simple direct speech, headlines, more concrete on what is exposed, more technical details, etc.

    They didn’t just send one email to report the vulnerability.

    and on January 3rd I emailed nine people: the general info address, six individual staff members at clicktopray.org, and two contacts at popesprayer.va (the Pope’s Worldwide Prayer Network). No response. From any of them.

    For July they have three entries of ‘reported to Journalist’ (“Dark Reading”), journalist contacted the Pope’s Worldwide Prayer Network, and ‘still no response’.

    They also posted an update about it being fixed on 2026-07-24 that it has been fixed.

    The authorization check is there now: request your own user ID and you still get your email back, request someone else’s and you get a public profile. Names are supposed to be public on a platform where you pray alongside other people, so what’s left is what was always meant to be visible.

    I also never got an email. Not an acknowledgment, not a thank you, not a “we’ve addressed this.”

    Given that The Register posted this article on 2026-07-24 22 UTC it must have been very unfortunate timing. Presumably they didn’t check the source again before pressing publish? And also haven’t noticed or bothered to include an information update.

    • Tetragrade@leminal.space
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      18 hours ago

      I expect they’re using some kind of authentication framework that supports full names in its User entity, and just went with that without considering whether it’s sensible.

      Looks like you can leave comments on prayers? Could also be that they want a particular aesthetic where everyone has their innate “Christian Name”, instead of a username, which is assocated with left wing ideas like digital utopianism. Because…

      Real names also enforce a complex of related authoritarian information structures i.e. they provide information about a person’s culture, race, gender, which you can use to assign them a place within your religion’s moral hierarchy.

    • jollyrogue@lemmy.ml
      link
      fedilink
      English
      arrow-up
      12
      ·
      1 day ago

      So they know what sins I’ve committed.

      They don’t follow my mastodon feed. It’s much easier that way.

    • Blackmist@feddit.uk
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 day ago

      They need the list of who’s been naughty and who’s been nice.

      Or is that the other fella?

    • tacosanonymous@mander.xyz
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      1
      ·
      1 day ago

      Historically? Abuse.

      I’m sure they say it’s for security : blocking bots, etc and getting their newsletter or some shit.

  • Gork@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    53
    ·
    2 days ago

    The Catholic Church is known for a lot of things. Keeping up with the times (or cyber security) isn’t one of them.

    • jollyrogue@lemmy.ml
      link
      fedilink
      English
      arrow-up
      8
      ·
      1 day ago

      Cyber security isn’t in the bible. Time for an update.

      Cyprus 1:1

      …. Copy pasta of NIST security standards circa May 2026 …

      Nothing could go wrong with this.

    • Kissaki@feddit.org
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      I thought they were known for keeping things under the rug/hidden. Only priest’s not follower’s personal data I guess.

  • username_1@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    47
    ·
    2 days ago

    Vatican Programmer: Oh, mighty Lord, sitting in the Sky, show me the way to this bug I seek and eliminate ineffectiveness. Amen.

    • real_squids@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      18
      ·
      2 days ago

      It connects users across the globe to pray for the Holy Father’s intentions, and as of July 2026, it has 719,517 registered accounts

      The only two screenshots they have on GPlay feature prayer scheduling and sharing your prayer.

      • Kissaki@feddit.org
        link
        fedilink
        English
        arrow-up
        16
        ·
        2 days ago

        Damn, with that many people praying these prayers are about to get real effective. I’m surprised we haven’t heard of their effects and effectiveness yet.

    • it_depends_man@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      edit-2
      2 days ago

      See, humans are smart. Praying and blessing things yourself? By hand, so to speak? Boooo! Pedestrian! Ain’t nobody got time fo dat!

      https://en.wikipedia.org/wiki/Prayer_flag

      the Tibetans believe the prayers and mantras will be blown by the wind to spread the good will and compassion into all pervading space. Therefore, prayer flags are thought to bring benefit to all.

      By hanging flags in high places the Lung ta will carry the blessings depicted on the flags to all beings. As wind passes over the surface of the flags, which are sensitive to the slightest movement of the wind, the air is purified and sanctified by the mantras.

      I choose to believe that the prayer app is just a hip, new and with it innovation in prayer spreading.

  • Lena@gregtech.eu
    link
    fedilink
    English
    arrow-up
    23
    ·
    2 days ago

    It still works lmao

    No email and some other stuff though… maybe they just removed that from the endpoint?

    • Kissaki@feddit.org
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      From the source blog post, which has the update

      The authorization check is there now: request your own user ID and you still get your email back, request someone else’s and you get a public profile. Names are supposed to be public on a platform where you pray alongside other people, so what’s left is what was always meant to be visible.

      • Kissaki@feddit.org
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 days ago

        If sinners go to hell, do you even have to do due diligence? Let us pray for the vulnerability to disappear.