SCI/TECH

The Holy Ghost didn’t help the Vatican devs secure the personal data

The Vatican’s official prayer app exposed personal data from 719,517 accounts. An ethical hacker reported it in January. Apparently neither heaven nor the developers could be bothered.

vlgr Tento článok sme neprekladali. 18 čítaní 2 min čítania
The Holy Ghost didn’t help the Vatican devs secure the personal data

God works in mysterious ways.

Apparently those ways do not include basic authorization checks on the Vatican’s own prayer API.


The Pope’s Worldwide Prayer Network operates Click to Pray, the official platform through which the faithful can follow papal prayer intentions, maintain daily prayer routines and entrust an institution associated with the Holy See with the usual collection of personal information required by modern digital life.

Names. Email addresses. Countries. Dates of birth. Roles.


The app assigned sequential numerical IDs, and requesting

GET /user/users/12345

returned the corresponding user record.


The registration API returned the email-verification token directly in its response, making it possible to verify an account without actually controlling the corresponding inbox, while, legitimate Click to Pray verification emails reportedly failed basic domain-authentication checks.


Ethical hacker BobDaHacker discovered and unsuccessfully reported the vulnerability on January 3, contacting nine addresses associated with Click to Pray and the Pope’s Worldwide Prayer Network.


After getting no response, BobDaHacker brought the issue to Nate Nelson at Dark Reading, which independently reproduced the flaw and also attempted to contact the Pope’s Worldwide Prayer Network and La Machi Communication for Good Causes, the communications company responsible for designing, developing and promoting the Holy App.


Only after Dark Reading published the story on July 24 did the system suddenly acquire the needed and oh so simple authorization logic. No public statement was issued.


The exposure of 719,517 accounts is a serious failure. Organisations that commission digital platforms would do well to verify that the people they hire actually understand elementary access control rather than hoping vibe-coding will somehow produce it. Hoping that higher powers will intervene, is not a security strategy.


Advice for Young Developers

There is, as always, a lesson for the next generation.

Do determine whether the requester is entitled to receive any information. This concept may appear radical after observing certain institutional software projects, but it has enjoyed some acceptance in professional circles.

if (!authorized) {
    return 404; // you have no power here
}

// pray


Amen.

Sources

Toto je satirický príspevok. vlgr nie je skutočný spravodajský portál – ide o paródiu a preháňanie výhradne na zábavné účely.
Zdieľať: X / Twitter