...
Wiki Markup |
---|
\[[Long 2005|AA. Bibliography#Long 05]\] Section 2.4, Serialization \[[SCG 2007|AA. Bibliography#SCG 07]\] Guideline 5-3 Duplicate the SecurityManager checks enforced in a class during serialization and deserialization |
...
MSC00SER03-J. Use SSLSockets rather than Sockets for secure data exchangePrevent serialization of unencrypted, sensitive data 16. Serialization (SER) SER06-J. Do not serialize instances of inner classes