4 ms·
This is a good example why you need regular pentests in big companies. Everyone (should) know that using pickle is insecure and everyone (should) know that djan
by Grollicus 8y ago
This is a good example why you need regular pentests in big companies. Everyone (should) know that using pickle is insecure and everyone (should) know that django debug should be False in production. Still, if the numbers get large enough someone will miss something.
- Polycryptus 8y agoThe use of Pickle isn't uncommon for session cookies in Python apps, from what I've seen. Pickle isn't really a problem unless you end up unserializing untrusted data... which a sign+encrypt scheme is supposed to ensure doesn't happen. You just can't leak the secret key or you're in trouble. Though, there's no excuse for leaving Django debug on in production.
- smsm42 8y agoI'd say it's a bad idea anyway - why you need to trust the user with anything that needs pickle (as opposed to much more primitive format) to unserialize? If you ever have a reason for non-opaque-id cookies at all, it should be very simple. If you stuff very complex objects that require native serialization into user-side storage, it's probably bad idea regardless of security implications.
- arachnids 8y agoFacebook does pentests all the time, but they don't find everything. This is why you should also run a bug bounty program.