555
you are viewing a single comment's thread
view the rest of the comments
[-] Zarobi@aussie.zone 63 points 2 months ago* (last edited 2 months ago)

the API endpoint GET [redacted] will return user data for any account - not just your own account - so long as you supply a valid, five-digit user ID. It doesn’t perform any authorization check or ownership validation. “Just increment the number and get someone else's data,” she wrote.

This data includes users’ email addresses, first and last names, country, dates of birth, and whether the account has been deleted, and the API exposes all 719,517 accounts on the prayer site. “With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform,” the hacker explained. “One GET request per user. for i in range(1, 719518): scrape(). That's it. That's the exploit.”

My God, that's horrific. Plus it doesn't even delete your data if you delete your account, it's still vulnerable.

[-] Appoxo@lemmy.dbzer0.com 16 points 2 months ago* (last edited 2 months ago)

I wonder of the vatican is part of the gdpr...
Would be funny to read about the church getting sued for that.

[-] Zarobi@aussie.zone 2 points 2 months ago

I don't know much about GDPR… is it illegal to have badly written software like this? Technically the user is bypassing normal usage and "hacking" the API

[-] Appoxo@lemmy.dbzer0.com 13 points 2 months ago

Negligence to delete the account data after termination is a reason to be fined.
They don't need to keep that data.
Afaik the only reason would be if MTX were offered (for book-keeping reasons)

[-] xiii@lemmy.world 7 points 2 months ago

It is illegal to keep deleted profiles

[-] needanke@feddit.org 4 points 2 months ago

Yes, especially once you have been informed about it

[-] Zeoic@lemmy.world 6 points 2 months ago

5 digit user ids, yet over 700k users? Im sure they must have gone up to 6 digits

[-] ViatorOmnium@piefed.social 7 points 2 months ago

I tried the endpoint. 5 digits always gives you a valid user, 6 stops working after some point.

[-] Zarobi@aussie.zone 4 points 2 months ago* (last edited 2 months ago)

They probably meant 6 digit and it was a typo. The rest of the article references 6 digits. If it's just an integer (highly likely) it would go up to 10 digits or roughly 2 billion max users. My old coworkers and I used to joke that hitting INTEGER.MAX_VALUE for your customer ID is a good problem to have

[-] Earthwormjim91@lemmy.world 2 points 2 months ago

Unless by “digit” they mean any alphanumeric.

You’ve got a lot of options if you go to a 5 characters with letters.

Which they’d kind of have to with 700k users if it’s 5 characters.

If it’s case insensitive, you’ve got 60,000,000+ combinations, and if case sensitive then 916,000,000+ combinations.

[-] ViatorOmnium@piefed.social 5 points 2 months ago

It's numerical only, but the number doesn't need leading 0s so anything from 1 to 6 digits might be a valid user ID.

[-] Earthwormjim91@lemmy.world 2 points 2 months ago

That would be an absolute nightmare to administer lol. Though I guess that tracks.

1, 01, 001, 0001, and 00001 would all be different users

[-] Zeoic@lemmy.world 1 points 2 months ago

Good point, could easily be hex or some higher base

[-] themachinestops@lemmy.dbzer0.com 5 points 2 months ago

It sill works, you get first name and last name.

[-] Zarobi@aussie.zone 2 points 2 months ago

Maybe I should remove that from my comment lol, I feel like I'm contributing to a data breach or something

[-] themachinestops@lemmy.dbzer0.com 4 points 2 months ago

It is in the article doesn't matter if you remove it. The moment the article became public it is already too late.

[-] Zarobi@aussie.zone 1 points 2 months ago

I know, but a lot of people don't click the article, they just look at headline + comments, so it's still a reduction of visibility or an extra step. My comment is like exposing the endpoint right there front and centre. Plus, I don't like being personally responsible for any data breach. Maybe it's just a tiny thing but it felt like the right thing to do

[-] nymnympseudonym@piefed.social 1 points 2 months ago

What's more, scammers now have a list of 750k people known for their gullibility

this post was submitted on 25 Jul 2026
555 points (98.8% liked)

Technology

88491 readers
3458 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS