Hacker News new | past | comments | ask | show | jobs | submit login

As has been commented several times on other threads here on HN, a new enough Java only protects against one kind of exploit (directly loading arbitrary bytecode) but not others (serialization tricks to execute arbitrary function calls, or data exfiltration).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: