Skip to content

Conversation

@mhartmay
Copy link

The parent has other possibilities than doing attacks via malicious messages.
Therefore it's okay to trust the messages from the parent and use unsecure
unpickling methods for those cases.

Note: I'm not very familiar with this codebase, so we should thoroughly review the changes to ensure they don't introduce any security vulnerabilities.

…arent -> child

It's well known that unpickling data received from an untrusted source is not
secure. But since children trust their parents and ancestors, unpickling data
received from a parent or ancestor should be supported. Add a test for this use
case.

Signed-off-by: Marc Hartmayer <[email protected]>
The parent has other possibilities than doing attacks via malicious messages.
Therefore it's okay to trust the messages from the parents and use unsecure
unpickling methods.

Signed-off-by: Marc Hartmayer <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant