[issue9276] pickle should support methods

Jean-Paul Calderone report at bugs.python.org
Mon Aug 2 14:01:38 CEST 2010


Jean-Paul Calderone <exarkun at twistedmatrix.com> added the comment:

> This is a security feature and should not be broken !

Can you explain this?

I don't think I agree, since an attacker can always serialize whatever they feel like.  It's the person doing the deserialization that has to be careful.

----------

_______________________________________
Python tracker <report at bugs.python.org>
<http://bugs.python.org/issue9276>
_______________________________________


More information about the Python-bugs-list mailing list