Replying to @⁨stermy4u@lemmy.world⁩

As it often is, the source has more information, and significantly so. I also find it much easier and more informative to read. Simple direct speech, headlines, more concrete on what is exposed, more technical details, etc.

They didn’t just send one email to report the vulnerability.

and on January 3rd I emailed nine people: the general info address, six individual staff members at clicktopray.org, and two contacts at popesprayer.va (the Pope’s Worldwide Prayer Network). No response. From any of them.

For July they have three entries of ‘reported to Journalist’ (“Dark Reading”), journalist contacted the Pope’s Worldwide Prayer Network, and ‘still no response’.

They also posted an update about it being fixed on 2026-07-24 that it has been fixed.

The authorization check is there now: request your own user ID and you still get your email back, request someone else’s and you get a public profile. Names are supposed to be public on a platform where you pray alongside other people, so what’s left is what was always meant to be visible.

I also never got an email. Not an acknowledgment, not a thank you, not a “we’ve addressed this.”

Given that The Register posted this article on 2026-07-24 22 UTC it must have been very unfortunate timing. Presumably they didn’t check the source again before pressing publish? And also haven’t noticed or bothered to include an information update.

bobdahacker.comClick to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User EmailsHow I found that anyone can pull the email address, name, country, and date of birth of any of the 719,517 users on Click To Pray, the Pope's official prayer app, with a single GET request. Reported January 3rd. Still live six months later. Nobody has ever responded.
Edited ⁨⁨Jul⁩ ⁨26⁩, ⁨2026⁩, ⁨05:39⁩⁩en