Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sort of interesting how Python has got rid of the GIL. Serialization of data securities is still something relevant though and I’m not sure if you should use pickle still?
 help



Pickle is insecure by design, but definitely convenient if you can trust the input.

If you need something safe then you really need to identify your requirements and your threat model first anyway; I wouldn't blindly reach for a one-size-fits-all solution in any programming language.

(Although I would do a quick check to see JSON or TOML is sufficient and practical.)


Pickle is likely still handy, as long as you created the data that you're deserializing. Zope's object database was a big pickle file, as I recall. But yeah, not a good idea if you're cracking open user-supplied files in any way.

Ha! People still remember Zope!

That was my first web kind of framework. The naivette of Zope still amuses me endlessly to this very day.

It tried to be cool, made ALL the wrong choices, and died silently with people just moving on.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: