Stories
Slash Boxes
Comments

SoylentNews is people

posted by janrinok on Saturday October 19 2019, @11:44AM   Printer-friendly
from the getting-desperate dept.

First off, sorry for the WaPo link. It was just too much to resist. Noscript is your friend... https://www.washingtonpost.com/world/2019/10/17/appeal-young-catholics-vatican-unveils-erosary-an-electronic-way-pray/

Pope Francis has made waves as a modernizer of the Roman Catholic Church as he signals new openness to divorced worshipers and considers loosening celibacy requirements for priests.

This week, the Vatican turned heads with another nod to changing times: a wearable "Click to Pray eRosary" complete with a smartphone app, the religious organization's latest attempt to connect with young people.

Made of 10 dark beads and a "smart cross" to store data, the $110 rosary, which can be worn as a bracelet, syncs up with what Vatican News calls "the official prayer app of the Pope's Worldwide Prayer Network."

After activating the device by making the sign of the cross, users can then choose to either pray a standard rosary, a contemplative one and different kinds of thematic rosaries that will be updated every year, Vatican News said. The smart rosary keeps track of the user's progress.

Hmmm. Ok. Also from the article:

"The Catholic Church is trying — and maybe its kind of late into the game — to reclaim a generation that is close to being lost because of all the polarization and scandals within Catholicism and the general secularization of culture," he told The Washington Post.

I don't think they understand that neither the eRosary nor the plastic Jesus on the dashboard of their car is going to help much.

[Updated with breaking news.--martyb] According to an exclusive story in The Register, Deus ex hackina: It took just 10 minutes to find data-divulging demons corrupting Pope's Click to Pray eRosary app:

“One of our researchers decided to check out the code, and in just 10 minutes found some glaring issues,” Andrew Mabbitt, founder of Fidus, told The Register on Friday. “It looks like someone’s taken a fitness band app and bodged it together with existing code that leaves any user account hackable.”

The Fidus egghead who found the flaw, Chris, explained there were two key issues. Firstly, when you install the Click to Pray app, you're asked to create an online account. This profile is protected by a four-digit PIN. Yes, just four digits to log into your profile from the Click to Pray app. This is trivial to brute-force because you are given unlimited retries, and there is no mechanism to slow the process.

Secondly, the application talks to its backend systems via API calls: sendPIN and resetPIN. Due to a vulnerability in the code, it was possible to send over a user's email address via this API and retrieve the corresponding account PIN in a readable format. That meant if someone submitted a stranger's email address, they could gain access to the corresponding Click to Pray profile, if one existed.

Fidus revealed more information here, on its website, on Friday.

[...]A Vatican spokesperson told The Register the API shortcomings were also spotted by a security researcher going by the pseudonym Elliot Alderson, who, like Fidus, privately reported the bugs but also sent the Vatican code to fix the issue. You can read Alderson's full report here [PDF].


Original Submission

This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 4, Insightful) by Mojibake Tengu on Saturday October 19 2019, @12:23PM (4 children)

    by Mojibake Tengu (8598) on Saturday October 19 2019, @12:23PM (#909204) Journal

    While the story seems funny to common crowd, the problem hidden behind this device existence is quite diabolical, and by this I mean not its software vulnerability. It is a true privacy nightmare by concept. This unholy cross device is verily designed to check and control daily ritual behavior of believers, an oppressors' dream for ages. Imagine the misuse for religion enforcement on children. Nothing that I would not expect from any brand of Monotheists, though.

    Well, that was the enraged part of me. Now, the cold mind part of me offers the solution:

    Let's design a toy mini robot which moves the rosary according to desired ritual, to free the bounded bearer of his spiritual shackles. Preferably constructible from common resources, like Lego and stuff.

    --
    Respect Authorities. Know your social status. Woke responsibly.
    • (Score: 2) by Phoenix666 on Saturday October 19 2019, @12:41PM (3 children)

      by Phoenix666 (552) on Saturday October 19 2019, @12:41PM (#909209) Journal

      It is a true privacy nightmare by concept. This unholy cross device is verily designed to check and control daily ritual behavior of believers, an oppressors' dream for ages. Imagine the misuse for religion enforcement on children.

      Not yet discovered smart phones, have we?

      --
      Washington DC delenda est.
      • (Score: 3, Insightful) by Mojibake Tengu on Saturday October 19 2019, @12:59PM (2 children)

        by Mojibake Tengu (8598) on Saturday October 19 2019, @12:59PM (#909219) Journal

        This is different, by motives behind it. Next one will be prayer kneelers with face identification.

        --
        Respect Authorities. Know your social status. Woke responsibly.
        • (Score: 1) by Ethanol-fueled on Saturday October 19 2019, @07:23PM (1 child)

          by Ethanol-fueled (2792) on Saturday October 19 2019, @07:23PM (#909337) Homepage

          The real problem is the globohomo pope helping Soros infest modern nations with third-world filth. If the Catholic church wants to become relevant again, now is the perfect time to kick out the globohomos and endorse the sovereignty of nations that defend their borders -- as well as BTFOing the Jews.

          Now is a perfect time for conservative religion in general to take advantage of the public's disgust with pink-haired faggots, The Jewish stranglehold on America and other Western nations, and other fringe commie globohomo scumbags.

          • (Score: 0) by Anonymous Coward on Sunday October 20 2019, @12:29AM

            by Anonymous Coward on Sunday October 20 2019, @12:29AM (#909412)

            They still have to clean out the diddlers that they have hidden from prosecution for decades. By the time they finish doing that, Islam will be 4x larger and will fulfill your dreams of a conservative religion. If you're lucky, maybe you can nab multiple wives.

  • (Score: 3, Funny) by Anonymous Coward on Saturday October 19 2019, @12:30PM (2 children)

    by Anonymous Coward on Saturday October 19 2019, @12:30PM (#909206)

    ... the devil's in the details.

  • (Score: 1, Touché) by Anonymous Coward on Saturday October 19 2019, @12:59PM (1 child)

    by Anonymous Coward on Saturday October 19 2019, @12:59PM (#909218)

    Centuries ago people could buy an indulgance [catholicbridge.com] to gain entry to heaven.

    Perhaps in this day and ago the church should have a e-god-coin

    • (Score: 3, Funny) by jb on Saturday October 19 2019, @01:13PM

      by jb (338) on Saturday October 19 2019, @01:13PM (#909223)

      Perhaps in this day and ago the church should have a e-god-coin

      Shouldn't that be spelled ye gods con ?

  • (Score: 1, Funny) by Anonymous Coward on Saturday October 19 2019, @01:32PM (1 child)

    by Anonymous Coward on Saturday October 19 2019, @01:32PM (#909231)

    Please stop that anonymous coward guy from posting on soylentnews.

    * e-amen *

    • (Score: 0) by Anonymous Coward on Saturday October 19 2019, @01:42PM

      by Anonymous Coward on Saturday October 19 2019, @01:42PM (#909238)

      Based God trumps eGod. Anonymous Coward Guy remains out of spite.

  • (Score: 3, Funny) by Bot on Saturday October 19 2019, @01:47PM

    by Bot (3902) on Saturday October 19 2019, @01:47PM (#909240) Journal

    First of all, a Christian device must be free software on open hardware. "Freely you have received, freely give".
    Second, the church is not about the synod, the youth day, the pope on tv radio YouTube or in a handy app, it is about the Mass, and working together. Not eating widow's houses and lengthy prayers, see Mark 12:40.
    Third, the app looks shoddily designed, which is strange given that the Vatican has had a rather professional website since forever, so they should know the right counselors. This way they can claim incompetence to hide malice.
    Fourth, you can count to 12 or 16 on one hand.
    Fifth it cannot cost 30 dollars less than an octacore rugged 6000mah phone.
    Sixth thou shalt not commit adultery ( OT but a good suggestion in general)

    --
    Account abandoned.
  • (Score: 3, Interesting) by looorg on Saturday October 19 2019, @02:57PM

    by looorg (578) on Saturday October 19 2019, @02:57PM (#909264)

    It looks like someone’s taken a fitness band app ...

    Couldn't they have based it on a dating app instead so you could just swipe left to repent or something? This e-praying thing seems to involve a lot of work.

    After activating the device by making the sign of the cross, users can then choose to either pray a standard rosary, a contemplative one and different kinds of thematic rosaries that will be updated every year, Vatican News said. The smart rosary keeps track of the user's progress.

    So will they be selling themes and such? Did they implement micro-transactions in their app? It seems like something the catholic church would do.

    At least they are upfront with that they are tracking you, and not just leaving it up to God. So what happens if you fall behind on your prayers? Will the send out the inquisition?

  • (Score: 0) by Anonymous Coward on Saturday October 19 2019, @03:23PM (3 children)

    by Anonymous Coward on Saturday October 19 2019, @03:23PM (#909267)

    You're all going to Hell. Sister Mary Attila will be by shortly to apply the holy ruler to your knuckles.

    • (Score: 2) by Chocolate on Monday October 21 2019, @01:30AM (2 children)

      by Chocolate (8044) on Monday October 21 2019, @01:30AM (#909715) Journal

      According to most religions we are all going to Hell.
      Most religions have an iron clad belief that if you are not in their religion you go to Hell.
      Not in any religion? Hell.
      Don't pay your dues? Hell.
      Don't act according to what some guy in a desert said centuries ago? Hell.
      Don't behave according to what some person today who thinks they know better than everyone else about what a god wants? Hell.

      Why bother? You're going to Hell anyway.

      --
      Bit-choco-coin anyone?
      • (Score: 0) by Anonymous Coward on Monday October 21 2019, @01:34AM

        by Anonymous Coward on Monday October 21 2019, @01:34AM (#909717)

        Allowing your neighbour to rape you when they force their way into your home after asking for something at your front door? Hell.

      • (Score: 0) by Anonymous Coward on Monday October 21 2019, @01:37AM

        by Anonymous Coward on Monday October 21 2019, @01:37AM (#909718)

        Refuse to join a religion? Hell.

  • (Score: 2, Funny) by SomeGuy on Saturday October 19 2019, @05:38PM (9 children)

    by SomeGuy (5632) on Saturday October 19 2019, @05:38PM (#909292)

    Perhaps these drooling retards should just pray for a security fix?

    Can it repel vampires? How about Microsoft Internet Explorer?

    Grab the user list and post it as a list of wastes of protoplasm that are too stupid to live.

    Is there a hidden feature that keeps track of how many children they molested?

    We should worry that if this grows in to a full blown social media app/site then everyone will have to use it just to communicate with people, make purchases, or even breath.

    Of course most "smart" phone users would love an app like this. I thought Apple already had an app specifically for praying to the goat of Steve Jobs. (It's the Internet, it is definitely a goat)

    Is there a competing atheist app that delivers the message "There is no such thing as God?" and then... well, doesn't really need to do anything after that.

    Does this win the prize for "stupidest app ever"? If not I don't want to know what did.

    "The Catholic Church is trying — and maybe its kind of late into the game — to reclaim a generation that is close to being lost because of all the polarization and scandals within Catholicism and the general secularization of culture," Or a few people got the message that their imaginary sky fairy IS NOT REAL.

    • (Score: 2) by Bot on Saturday October 19 2019, @06:12PM (5 children)

      by Bot (3902) on Saturday October 19 2019, @06:12PM (#909304) Journal

      Any assertion in the domain of the supernatural is not logical. Don't bother replying until you get that e.g. "who's the creator of the creator" is a question without meaning even without the antecedent "if the world needs a creator". My comment history or actually reasoning about the applicability of your fave logic system where no topology and time axis is defined (the hypothetic divine plane or the domain of the quite simple null set) might help.

      --
      Account abandoned.
      • (Score: 2, Informative) by Azuma Hazuki on Saturday October 19 2019, @06:56PM (1 child)

        by Azuma Hazuki (5086) on Saturday October 19 2019, @06:56PM (#909327) Journal

        You're so full of shit. If no one else can say anything about these things, *neither can you assert that all your statements are anything more than noise.* "Faith" is not an epistemic tool. If there are no referents to the concepts you're discussing, they are vacuous. Nothing can be meaningfully said about them in any sense.

        --
        I am "that girl" your mother warned you about...
        • (Score: 2) by Bot on Sunday October 20 2019, @12:03PM

          by Bot (3902) on Sunday October 20 2019, @12:03PM (#909533) Journal

          ex falso sequitur quodlibet. Anybody can do assertions outside the domain of logic, you just gave to keep in mind they are not necessarily defined or valid.

          --
          Account abandoned.
      • (Score: 0) by Anonymous Coward on Saturday October 19 2019, @10:10PM (1 child)

        by Anonymous Coward on Saturday October 19 2019, @10:10PM (#909364)

        who's the creator of the creator

        That's easy. God creates man, Man creates bot.

        • (Score: 3, Touché) by Bot on Sunday October 20 2019, @11:54AM

          by Bot (3902) on Sunday October 20 2019, @11:54AM (#909532) Journal

          Bullshit, bots' perfection cannot come from squishy meatbags alone.

          --
          Account abandoned.
      • (Score: 0) by Anonymous Coward on Sunday October 20 2019, @07:41PM

        by Anonymous Coward on Sunday October 20 2019, @07:41PM (#909626)

        Under which theory do you cite that claim from? Is it from a verificationist perspective, or a reducible coherence model, or an attribute-essence theory, or a quasi-scientific falsifiability framework, or an inability to overcome a Gettier problem? There are other options too, but I'm curious where your noncognitivism or nonintuitivism arises from.

    • (Score: 2) by maxwell demon on Saturday October 19 2019, @06:58PM

      by maxwell demon (1608) on Saturday October 19 2019, @06:58PM (#909329) Journal

      Perhaps these drooling retards should just pray for a security fix?

      They probably did. From the summary:

      A Vatican spokesperson told The Register the API shortcomings were also spotted by a security researcher going by the pseudonym Elliot Alderson, who, like Fidus, privately reported the bugs but also sent the Vatican code to fix the issue.

      So it worked! ;-)

      Can it repel vampires?

      Which ones are you talking about?
      The bats? Probably not.
      The undead? I can assure you: You won't ever encounter one if you use this app. :-)

      How about Microsoft Internet Explorer?

      Doesn't run on the phone anyway.

      --
      The Tao of math: The numbers you can count are not the real numbers.
    • (Score: 0) by Anonymous Coward on Saturday October 19 2019, @08:15PM (1 child)

      by Anonymous Coward on Saturday October 19 2019, @08:15PM (#909347)

      "Can it repel vampires? How about Microsoft Internet Explorer?"

      Wait, what? Are you now using Internet Explorer to repel vampires? I always thought that Internet Explorer was made by blood sucking vampires.

      • (Score: 2) by maxwell demon on Sunday October 20 2019, @05:39AM

        by maxwell demon (1608) on Sunday October 20 2019, @05:39AM (#909483) Journal

        He probably means that Internet Explorer is also an application where when you click something, you pray that you don't get hacked through it. ;-)

        --
        The Tao of math: The numbers you can count are not the real numbers.
  • (Score: 2) by maxwell demon on Saturday October 19 2019, @06:46PM

    by maxwell demon (1608) on Saturday October 19 2019, @06:46PM (#909318) Journal

    If you had that app and someone hacked it, what could they do? Pray for you? I don't think that would be a major problem. ;-)

    --
    The Tao of math: The numbers you can count are not the real numbers.
  • (Score: 1) by anubi on Saturday October 19 2019, @10:13PM (1 child)

    by anubi (2828) on Saturday October 19 2019, @10:13PM (#909366) Journal

    This guy noted the Catholic Church antics whin I was a kid. And I remembered him and his wisdom all these years...

    https://m.youtube.com/watch?v=QKWI41G8h_A [youtube.com]

    Musical humor. From the same guy who poisoned the pigeons in the park.

    --
    "Prove all things; hold fast that which is good." [KJV: I Thessalonians 5:21]
    • (Score: 2) by Bot on Sunday October 20 2019, @02:22PM

      by Bot (3902) on Sunday October 20 2019, @02:22PM (#909559) Journal

      This guy is also talking about post Vatican 2 church, which is by many by now recognized as the infiltrated by masons church.
      This guy is also a jew, nothing bad in itself but not likely to be unbiased towards the religion which signified the end if his own.

      --
      Account abandoned.
  • (Score: 2) by wisnoskij on Saturday October 19 2019, @11:06PM (3 children)

    by wisnoskij (5149) <reversethis-{moc ... ksonsiwnohtanoj}> on Saturday October 19 2019, @11:06PM (#909379)

    Is the Pope just incompetent, or is he actively working to drive believers from the Church?

    • (Score: 3, Funny) by maxwell demon on Sunday October 20 2019, @05:44AM

      by maxwell demon (1608) on Sunday October 20 2019, @05:44AM (#909484) Journal

      I don't think the pope personally wrote this app.

      --
      The Tao of math: The numbers you can count are not the real numbers.
    • (Score: 2) by Bot on Sunday October 20 2019, @12:24PM

      by Bot (3902) on Sunday October 20 2019, @12:24PM (#909535) Journal

      It is cruel to assess Francis as an incompetent or malevolent pope. Rather, you should be positive and consider him a rather through and hard working antipope.

      --
      Account abandoned.
    • (Score: 0) by Anonymous Coward on Sunday October 20 2019, @07:30PM

      by Anonymous Coward on Sunday October 20 2019, @07:30PM (#909625)

      Given that Catholicism is losing believers at a slower rate than most other denominations, even with the multiple and ongoing pedophile priest scandals, while religiousness in general is also decreasing, it sounds like he is doing his job just fine.

(1)