Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.python > #3657

Re: Pickling over a socket

Path csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!aioe.org!news.stack.nl!newsfeed.xs4all.nl!newsfeed5.news.xs4all.nl!xs4all!post.news.xs4all.nl!not-for-mail
Return-Path <balle@chaostal.de>
X-Original-To python-list@python.org
Delivered-To python-list@mail.python.org
X-Spam-Status OK 0.031
X-Spam-Evidence '*H*': 0.94; '*S*': 0.00; 'handled': 0.03; 'socket': 0.05; '-0700': 0.07; 'content-type:multipart/signed': 0.09; 'sockets': 0.09; 'calderone': 0.16; 'content-type:application/pgp- signature': 0.16; 'filename:fname piece:asc': 0.16; 'filename:fname piece:signature': 0.16; 'filename:fname:signature.asc': 0.16; 'symmetric': 0.16; 'tue,': 0.20; 'header:In-Reply-To:1': 0.22; 'load': 0.28; 'server': 0.29; 'jean-paul': 0.31; 'to:addr:python-list': 0.32; 'there': 0.35; 'ssl': 0.35; 'together.': 0.36; 'charset:us-ascii': 0.36; 'data': 0.37; 'it?': 0.37; 'should': 0.37; 'apr': 0.38; 'ways': 0.38; 'but': 0.38; 'completely': 0.38; 'to:addr:python.org': 0.39; 'where': 0.39; 'received:de': 0.39; 'header:Mime-Version:1': 0.39; 'header:Received:5': 0.40; 'received:95': 0.60; '2011': 0.62; 'ever': 0.65; 'encryption': 0.68; 'connection.': 0.77; 'other?': 0.84; 'schrieb': 0.84; 'subject:over': 0.84
Date Wed, 20 Apr 2011 08:44:31 +0200
From Bastian Ballmann <balle@chaostal.de>
To python-list@python.org
Subject Re: Pickling over a socket
In-Reply-To <7a56699d-7387-49a0-8c4f-f794df43df00@22g2000prx.googlegroups.com>
References <61890800-f81a-4a1e-8905-a0237407f016@a21g2000prj.googlegroups.com> <BANLkTi=1d4k6QfscN_F_fPddznfQUuY6wA@mail.gmail.com> <mailman.582.1303241870.9059.python-list@python.org> <7744bf8c-0df6-4dc9-a977-7234d571643f@r4g2000prm.googlegroups.com> <7a56699d-7387-49a0-8c4f-f794df43df00@22g2000prx.googlegroups.com>
X-Mailer Claws Mail 3.7.8 (GTK+ 2.22.1; i686-pc-linux-gnu)
Mime-Version 1.0
Content-Type multipart/signed; micalg=PGP-SHA1; boundary="Sig_/mYR/LI1RxvjN4p4N7TY+PNB"; protocol="application/pgp-signature"
X-Virus-Scanned Debian amavisd-new at lucy.chaostal.de
X-BeenThere python-list@python.org
X-Mailman-Version 2.1.12
Precedence list
List-Id General discussion list for the Python programming language <python-list.python.org>
List-Unsubscribe <http://mail.python.org/mailman/options/python-list>, <mailto:python-list-request@python.org?subject=unsubscribe>
List-Archive <http://mail.python.org/pipermail/python-list>
List-Post <mailto:python-list@python.org>
List-Help <mailto:python-list-request@python.org?subject=help>
List-Subscribe <http://mail.python.org/mailman/listinfo/python-list>, <mailto:python-list-request@python.org?subject=subscribe>
Newsgroups comp.lang.python
Message-ID <mailman.619.1303281905.9059.python-list@python.org> (permalink)
Lines 33
NNTP-Posting-Host 82.94.164.166
X-Trace 1303281905 news.xs4all.nl 41102 [::ffff:82.94.164.166]:38470
X-Complaints-To abuse@xs4all.nl
Xref x330-a1.tempe.blueboxinc.net comp.lang.python:3657

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

Am Tue, 19 Apr 2011 19:28:50 -0700 (PDT)
schrieb Jean-Paul Calderone <calderone.jeanpaul@gmail.com>:

> It is completely insecure.  Do not use pickle and
> sockets together.

Yes pickle is like eval, but that doesnt mean that one should never
ever use it over a socket connection. 
What about ssl sockets where client and server authenticate each other?
Or you encrypt the pickle dump with symmetric encryption and only load
it if you can decrypt it? There are ways to ensure that the data you
get can be handled as trusted.
Greets

Basti

Back to comp.lang.python | Previous | NextPrevious in thread | Next in thread | Find similar


Thread

Pickling over a socket Roger Alexander <rtalexander@mac.com> - 2011-04-19 11:53 -0700
  Re: Pickling over a socket Chris Rebert <clp2@rebertia.com> - 2011-04-19 12:21 -0700
  Re: Pickling over a socket Chris Angelico <rosuav@gmail.com> - 2011-04-20 05:29 +1000
  Re: Pickling over a socket Dan Stromberg <drsalists@gmail.com> - 2011-04-19 12:30 -0700
  Re: Pickling over a socket Chris Angelico <rosuav@gmail.com> - 2011-04-20 05:37 +1000
    Re: Pickling over a socket Roger Alexander <rtalexander@mac.com> - 2011-04-19 15:27 -0700
      Re: Pickling over a socket Jean-Paul Calderone <calderone.jeanpaul@gmail.com> - 2011-04-19 19:28 -0700
        Re: Pickling over a socket Bastian Ballmann <balle@chaostal.de> - 2011-04-20 08:44 +0200
        Re: Pickling over a socket Chris Angelico <rosuav@gmail.com> - 2011-04-20 16:59 +1000
        Re: Pickling over a socket Bastian Ballmann <balle@chaostal.de> - 2011-04-20 09:34 +0200
          Re: Pickling over a socket Thomas Rachel <nutznetz-0c1b6768-bfa9-48d5-a470-7603bd3aa915@spamschutz.glglgl.de> - 2011-04-20 10:25 +0200
            [OT] Re: Pickling over a socket Bastian Ballmann <balle@chaostal.de> - 2011-04-20 10:59 +0200
        Re: Pickling over a socket Chris Angelico <rosuav@gmail.com> - 2011-04-20 19:26 +1000
        Re: Pickling over a socket Bastian Ballmann <balle@chaostal.de> - 2011-04-20 11:41 +0200

csiph-web