SkillByAIOpen interactive version →

Lesson 17 / 25

Software and Data Integrity Failures

Unsigned code and unsafe deserialisation.

Verify before you trust

Integrity failures happen when code or data is trusted without verification: auto-updates without signature checks, plugins loaded from untrusted sources, CI/CD pipelines that anyone can modify, CDN scripts without integrity checks, and insecure deserialisation, where native object formats (Python pickle, Java serialisation) from untrusted input can execute code. Verify signatures and checksums, use Subresource Integrity (SRI) for third-party scripts, protect pipelines with reviews and least privilege, and use safe data formats such as JSON with schema validation.

Unsafe and safe deserialisation, plus SRI

Python and HTML.

import json, pickle

# VULNERABLE: unpickling attacker data can run arbitrary code
obj = pickle.loads(request.data)

# SAFE: parse a data-only format and validate its structure
payload = json.loads(request.data)
validate(payload, ORDER_SCHEMA)      # e.g. jsonschema or pydantic

# HTML: the browser refuses the script if its hash does not match
# <script src="https://cdn.example.com/lib.min.js"
#         integrity="sha384-<base64 hash>" crossorigin="anonymous"></script>

Treat CI/CD as production

Pipelines hold deployment credentials; protect branches, require reviews and restrict who can change workflows.

Quick check: Why is pickle.loads on untrusted data dangerous?

  • It only supports strings
  • It is slow
  • Deserialising pickle data can execute arbitrary code
  • It deletes the input
Answer

Deserialising pickle data can execute arbitrary code — Use data-only formats for untrusted input.