“Even God Won’t Help”: Pope Leo’s Prayer App Suffers Devastating Data Breach

Do you use a prayer app? As technology becomes more and more of a part of our daily lives, it’s something that’s only going to surge in popularity.

And it’s catching on in many denominations. Even the Catholic Church wanted to get ahead of the curve, so they made their own Pope-approved app.

In case you’re unaware, Click to Pray is the official app of the Pope’s Worldwide Prayer Network, which is, as the name suggests, chaired by the Pope. It displays Leo’s daily intentions to many hundreds of thousands.

But there’s been a bit of a problem with it in recent days. As reported by Dexerto, Pope Leo’s prayer app has exposed the personal details of over 700,000 devotees.

And the worst part? It all stemmed from a vulnerability that was left for months. A cybersecurity researcher named BobDaHacker found that there was a lapse of security in the app.

It took six months for the security hole to be patched. And yet, no one from the network spoke up about it.

What Was Wrong With the Pope Prayer App?

Well, it’s pretty techy—but let’s break it down. The problem was called an “IDOR”, which stands for an “In-Direct Object Reference”. You know how, when you log in to an account on certain websites, there might be a ticket number or an account number?

Well, as per OWASP, an IDOR vulnerability is where an attacker essentially changes that number. And, in the case of the Pope’s prayer app, there weren’t any checks in place to make sure that person had the credentials.

Think of it like a lock on a door. You know your key fits, right? Well, if someone can guess the shape of your key at random and make it fit into the door, you’re toast. And if there are no security guards (i.e., permission checks from the website), you’ve just been burgled (had your data stolen).

So you’re left with a glaring vulnerability that can leave your personal details stolen. We’re not sure how much data, if any, was stolen, unfortunately.

When these attacks happen because of a security hole, they’re very quiet. People don’t find out until months later… if at all. We hope that no data was taken from Pope Leo’s prayer app.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *