3 ms·
Pickle Serialization in Data Science
- hdd2k 5y agoBlog post on the dangers of pickle files in data science!
- compressedgas 5y agoOddly fixing the security problem of pickle is actually easy and not mentioned in the article: limit what callables that are allowed to be called during unpickling. The pickle module doesn't directly supports doing this as one has to implement a Unpickler subclass to override find_class to permit only the callables from modules that are acceptable to be called.