Insecurity and Python pickles
Insecurity and Python pickles
Posted Mar 14, 2024 19:01 UTC (Thu) by adobriyan (subscriber, #30858)In reply to: Insecurity and Python pickles by pizza
Parent article: Insecurity and Python pickles
> Except that criminal laws are not retroactive.
I'm not proposing new law. I believe all the laws are in place already, it is just that governments chose to not exercise them.
I remember Nimda pandemic while at the university. Us, Linux users were laughing at Windows suckers.
But our machine was dual booting so we were laughing at ourselves too.
It is unthinkable how Microsoft was not crucified for those stunts. It was so easy politically.
> > Whoever enables eval() equivalent by default goes to prison.
> Ok, so users have to change the default setting to achieve common legitimate use cases.
Yes, and then it is not on the manufacturer.
> Or they're prompted "do <potentially dangerous thing> Y/N?" so often that they automatically say "Yes" without thinking about it any more.
Police officers don't even get prompted by their gun's safety lock, they just disable it and shoot the criminal if necessary.
Somehow, the society lives with it and this situation is considered OK by general public, gun manufacturers, police and soldiers.
Nobody is saying "hey, police officer would have override safety lock so many times in his career that they would do it without thinking".
Maybe it is time to stop saying that when talking about software.