WEBVTT 1 00:00:02.220 --> 00:00:06.260 So lets continue on about our discussions of binary files in Python. 2 00:00:06.260 --> 00:00:09.760 And what we're going to do is talk about something called pickle. 3 00:00:09.760 --> 00:00:12.490 Now if you've used Java in the past you might be familiar with 4 00:00:12.490 --> 00:00:14.330 the concept of serialization. 5 00:00:14.330 --> 00:00:17.680 That's a process that allows objects to be saved to a file. 6 00:00:17.680 --> 00:00:21.330 So that they can be stored or restored I should say from the file later. 7 00:00:21.330 --> 00:00:25.430 Now python provides a mechanism for serializing objects called pickling. 8 00:00:25.430 --> 00:00:26.510 Hence the word pickle. 9 00:00:26.510 --> 00:00:29.930 So when and object is pickled and it's written to a file and 10 00:00:29.930 --> 00:00:34.440 format that contains the objects data together with sufficient information to 11 00:00:34.440 --> 00:00:37.840 allow that object to be recreated when it's loaded back in. 12 00:00:37.840 --> 00:00:40.990 Now as we've seen, converting an object to a byte array. 13 00:00:40.990 --> 00:00:44.960 in order to save it into a binary file isn't particularly easy, and 14 00:00:44.960 --> 00:00:47.020 we saw that in the previous video. 15 00:00:47.020 --> 00:00:50.250 And no information about the object itself is stored, 16 00:00:50.250 --> 00:00:52.480 unless we write code to somehow do that. 17 00:00:52.480 --> 00:00:55.730 And if you thought just writing a simple number was complicated, 18 00:00:55.730 --> 00:00:59.500 imagine how tricky it would be to store something like our locations dictionary 19 00:00:59.500 --> 00:01:02.030 From the adventure game challenge that we've done previously. 20 00:01:02.030 --> 00:01:04.190 Clearly there needs to be a better way of doing it. 21 00:01:04.190 --> 00:01:07.700 Now using pickle, saving objects is very easy and 22 00:01:07.700 --> 00:01:09.110 I'm gonna show you that in an example. 23 00:01:09.110 --> 00:01:09.690 Now once again, 24 00:01:09.690 --> 00:01:13.560 what we're gonna do is we're going to use the details, detail as I should say. 25 00:01:13.560 --> 00:01:16.280 If you remember the that we saw in an earlier video. 26 00:01:16.280 --> 00:01:19.390 So let's make a start, first we're gonna type import pickle, 27 00:01:19.390 --> 00:01:24.680 which is a library that we're going to be using for this, 28 00:01:24.680 --> 00:01:30.642 we're gonna type imelda = ( 29 00:01:30.642 --> 00:01:37.923 'More Mayhem', Imelda May. 30 00:01:41.942 --> 00:01:43.948 2011. 31 00:01:47.967 --> 00:01:53.129 And it's gonna be 1, the actual song's 32 00:01:53.129 --> 00:01:59.808 Pulling the Rug [SOUND] Two psycho. 33 00:02:03.848 --> 00:02:08.382 Three, let's put a bracket there. 34 00:02:08.382 --> 00:02:09.936 Three. 35 00:02:09.936 --> 00:02:15.843 Mayhem and lastly four 36 00:02:15.843 --> 00:02:20.507 Kentish Town Wall. 37 00:02:20.507 --> 00:02:23.400 And three brackets. 38 00:02:23.400 --> 00:02:25.250 So that's that line. 39 00:02:25.250 --> 00:02:28.210 Now the code To pick all these saved objects. 40 00:02:28.210 --> 00:02:32.890 So what we're trying to do is pickle, or save this imelda object, effectively. 41 00:02:32.890 --> 00:02:41.887 So we're going to type with open("imelda.pickle", 42 00:02:41.887 --> 00:02:43.730 "Wb"). 43 00:02:43.730 --> 00:02:48.880 Or you can also do double quote set, Wb. 44 00:02:48.880 --> 00:02:50.944 s pickle_file. 45 00:02:52.920 --> 00:02:57.273 And we'll talk pickle.dump 46 00:02:57.273 --> 00:03:01.880 imelda pickle file. 47 00:03:01.880 --> 00:03:02.900 So looking at the code, 48 00:03:02.900 --> 00:03:06.310 we first have to import the pickle module to be able to use it. 49 00:03:06.310 --> 00:03:09.210 And that's the line one that does that. 50 00:03:09.210 --> 00:03:12.000 So it can be saved with a single call as you saw 51 00:03:12.000 --> 00:03:14.778 on line 12 using the pickle.dump method. 52 00:03:15.800 --> 00:03:20.000 Is quite complex cuz it's obviously got a tuple containing another tuple, 53 00:03:20.000 --> 00:03:22.030 of tuples for the track listings. 54 00:03:22.030 --> 00:03:25.060 Even so, it can be stored with a single dump call, which is pretty cool. 55 00:03:25.060 --> 00:03:27.900 So, now, the format of the data is specific to Python. 56 00:03:27.900 --> 00:03:28.950 That's important. 57 00:03:28.950 --> 00:03:32.920 And if we open the [INAUDIBLE] file in Editor, for example, IntelliJ. 58 00:03:32.920 --> 00:03:36.300 So, if we come back here or need to run it first so it gets created, 59 00:03:36.300 --> 00:03:39.510 then we should find the [INAUDIBLE] in our project then we'll try and open it. 60 00:03:39.510 --> 00:03:41.260 You saw it appear over there other side. 61 00:03:41.260 --> 00:03:43.830 So if you try to open it, 62 00:03:43.830 --> 00:03:48.180 it wants you to associate a file type we'll click on text to see what happens. 63 00:03:48.180 --> 00:03:52.500 You can see the format that is on screen now for this object. 64 00:03:52.500 --> 00:03:55.380 You could also open this in if you prefer to do that as well. 65 00:03:55.380 --> 00:03:57.930 So you can see the data is clearly present there you can see bits and 66 00:03:57.930 --> 00:03:59.150 pieces of the data. 67 00:03:59.150 --> 00:04:03.410 But there's a load of binary data sort of in and around it, and you can see those 68 00:04:03.410 --> 00:04:06.200 sort of strange characters that we talked about in the previous video. 69 00:04:06.200 --> 00:04:08.060 The good thing about this though, is that fortunately, 70 00:04:08.060 --> 00:04:12.120 the pickle module itself takes care of all the structural detail for us. 71 00:04:12.120 --> 00:04:14.590 So in other words, we can just load our object back 72 00:04:14.590 --> 00:04:18.148 easily by using the pickle.load method. 73 00:04:18.148 --> 00:04:19.560 So close that down. 74 00:04:19.560 --> 00:04:23.910 So obviously pickle.dump, and to retrieve it We do pickle.load. 75 00:04:23.910 --> 00:04:28.200 So what I'm going to do is I'm just going to that code. 76 00:04:28.200 --> 00:04:29.080 So we still got there. 77 00:04:29.080 --> 00:04:31.290 And I'll just grab this bit of code. 78 00:04:31.290 --> 00:04:32.632 We'll just make a change to it. 79 00:04:32.632 --> 00:04:35.610 So comment that again and 80 00:04:36.620 --> 00:04:39.740 this time instead of writing we are going to read from it again. 81 00:04:39.740 --> 00:04:42.270 So we are going to read. 82 00:04:42.270 --> 00:04:43.390 So with open. 83 00:04:43.390 --> 00:04:47.740 And the name of the file that we use to save it we're gonna set that to read. 84 00:04:47.740 --> 00:04:52.190 Let's just call that [INAUDIBLE] _pickled. 85 00:04:52.190 --> 00:04:56.970 And we need to change this format. 86 00:04:56.970 --> 00:05:00.980 It's not a dump anymore, so it's going to be [INAUDIBLE] 87 00:05:00.980 --> 00:05:06.020 the variable that we want to be used is gonna contain the data. 88 00:05:06.020 --> 00:05:13.876 Equals then we type pickle.load and it's only at this point now imelda_pickled. 89 00:05:13.876 --> 00:05:17.111 So imelda_pickled, 90 00:05:17.111 --> 00:05:23.010 like so.So that's now reading the data out of the imelda.pickle file. 91 00:05:23.010 --> 00:05:24.820 And out in order two object. 92 00:05:24.820 --> 00:05:29.582 Now just to confirm that we can go print 93 00:05:32.974 --> 00:05:38.184 two and of course we go album, artist, 94 00:05:38.184 --> 00:05:44.350 year, track, list equals m l two. 95 00:05:46.100 --> 00:05:51.147 Make it print album, print artist, 96 00:05:51.147 --> 00:05:59.090 print year, and then we can even go for track in track and let's call list. 97 00:05:59.090 --> 00:06:01.190 Okay, and let's extract the data from the top one now. 98 00:06:01.190 --> 00:06:07.903 So, its track track_number, track_title = track. 99 00:06:07.903 --> 00:06:14.880 And of course at that point, we can then print(track_number, 100 00:06:14.880 --> 00:06:18.020 track_title) like so. 101 00:06:18.020 --> 00:06:26.710 If we run that, You can see we've got all that data, loaded from that binary file. 102 00:06:26.710 --> 00:06:30.340 Pulled back into Python and then stored in the Imelda 2 variable, and we're able to 103 00:06:30.340 --> 00:06:33.800 go right through it all, through the topless role grabbing the necessary data. 104 00:06:33.800 --> 00:06:38.235 So it's all been stored and nicely retrieved, by that simple command, 105 00:06:38.235 --> 00:06:42.600 pickle.load Now the good thing is, once you open the file for 106 00:06:42.600 --> 00:06:47.370 writing, we can literally pick as many objects as we want to in that one file. 107 00:06:47.370 --> 00:06:52.220 So to show that, I'm just gonna uncomment some of this card. 108 00:06:52.220 --> 00:06:54.850 And this card again, cause we wanna write that again to this file. 109 00:06:58.340 --> 00:06:59.620 Now I'll comment this bit here. 110 00:07:01.190 --> 00:07:04.630 So I'm going to start off with our melded data again, 111 00:07:04.630 --> 00:07:09.560 and then up here, we're going to create a few extra, two extra lists. 112 00:07:09.560 --> 00:07:14.878 So even equals list list range, 0, 10, 113 00:07:14.878 --> 00:07:19.830 2 And odd equals list(range(1,10, 20). 114 00:07:19.830 --> 00:07:26.440 So we can do with open imelda.pickle and we can dump the imelda 115 00:07:26.440 --> 00:07:30.800 list first, which we're doing online 41 but then we can also add to that. 116 00:07:30.800 --> 00:07:36.540 So we can put pickle.dump[even], 117 00:07:36.540 --> 00:07:44.763 pickle_file, pickle.dump[odd], 118 00:07:44.763 --> 00:07:47.941 pickle_file. 119 00:07:49.250 --> 00:07:50.380 We can even do pickle. 120 00:07:53.720 --> 00:07:59.510 Type in a number like 299302, pickle underscore file as well. 121 00:07:59.510 --> 00:08:03.750 That stored all four, 122 00:08:03.750 --> 00:08:07.920 all three variables, in fact this other number bar that we typed in. 123 00:08:07.920 --> 00:08:11.650 And we can grab this code back We can grab all this code there that we used to 124 00:08:11.650 --> 00:08:16.120 read it back it object first brough that back in and 125 00:08:16.120 --> 00:08:21.370 we'll uncomment that so that we'll be able to see our data again. 126 00:08:21.370 --> 00:08:23.730 Print that all out including the tuples. 127 00:08:23.730 --> 00:08:25.450 Then we'll make a gap there so it will print. 128 00:08:31.490 --> 00:08:34.720 I'm gonna put for i in even_list, so 129 00:08:34.720 --> 00:08:38.455 we're gonna extract all the items out of the list, the even list. 130 00:08:38.455 --> 00:08:41.460 Print[i]. And what we need to do here, is before 131 00:08:41.460 --> 00:08:45.880 that'll work, we need to change this so we also grab the other data out as well. 132 00:08:45.880 --> 00:08:51.973 So we're going to put even_list = pickle.load. 133 00:08:51.973 --> 00:08:57.897 And that's going to be _pickled. 134 00:08:57.897 --> 00:09:04.560 Then I'll put odd_list = pickle.load( _pickled). 135 00:09:04.560 --> 00:09:11.740 And let's just say x = pickle.load( .pickled). 136 00:09:11.740 --> 00:09:16.060 So we've now grabbed the full data Items relating to the items that we saved in 137 00:09:16.060 --> 00:09:20.900 lines 41 to 44 and we into these variables in lines 47 through 50. 138 00:09:20.900 --> 00:09:25.720 So now we can print them out so we are printing out obviously. 139 00:09:25.720 --> 00:09:28.810 But also we've now gone through the even list. 140 00:09:28.810 --> 00:09:30.410 And we can do the same for the odd list as well. 141 00:09:30.410 --> 00:09:35.350 Let's just put another space in there and copy all that and 142 00:09:35.350 --> 00:09:38.216 we'll make that odd list. 143 00:09:38.216 --> 00:09:39.908 Of this. 144 00:09:39.908 --> 00:09:44.400 >> [NOISE] >> And then we'll put another one there. 145 00:09:44.400 --> 00:09:46.520 Another long spacing effectively. 146 00:09:46.520 --> 00:09:47.230 And predicts. 147 00:09:48.350 --> 00:09:52.070 So what should have happened now is we should be saving the four variables you 148 00:09:52.070 --> 00:09:55.500 can see there we're now retrieving them back then I'm just going through them, 149 00:09:55.500 --> 00:09:57.360 printing out the values of the various ones and 150 00:09:57.360 --> 00:10:00.350 they should equate to the values that we used when we saved. 151 00:10:01.980 --> 00:10:04.760 And then you can see that all the items in there including x, which of 152 00:10:04.760 --> 00:10:09.090 course which was the number from line 44 that we typed in without a variable name. 153 00:10:09.090 --> 00:10:12.170 So the only real thing to remember here when we're doing this is that the objects 154 00:10:12.170 --> 00:10:15.990 themselves must be read back in the same order that they're written. 155 00:10:15.990 --> 00:10:20.169 So we pick followed by two lists and an integer So we have to read back a. 156 00:10:20.169 --> 00:10:22.250 Very important to do it in the same order. 157 00:10:22.250 --> 00:10:27.080 Much of the code in this example is concerned with initializing the variables 158 00:10:27.080 --> 00:10:28.200 and printing them out. 159 00:10:28.200 --> 00:10:31.940 The actually reading and writing is really only four lines. 160 00:10:31.940 --> 00:10:37.560 It's lines 41 to 44 to write, and 47 to 50 to load them back in. 161 00:10:37.560 --> 00:10:40.230 And I think you'll agree it's a lot easier 162 00:10:40.230 --> 00:10:43.160 Than the earlier approach of converting everything to binaries. 163 00:10:43.160 --> 00:10:44.600 And the good thing also is, 164 00:10:44.600 --> 00:10:48.960 there's very few objects in Python that can not be saved by pickling them. 165 00:10:48.960 --> 00:10:52.300 Now when you're pickling objects to save to a file, 166 00:10:52.300 --> 00:10:57.115 you can choose from one From one which at the time of the recording the video five 167 00:10:57.115 --> 00:11:01.185 different protocols that python is going to use when serialising the data. 168 00:11:01.185 --> 00:11:07.190 Now the latest version is version four and that was introduced with python 3.4. 169 00:11:07.190 --> 00:11:09.830 That was an improvement on the earlier protocols. 170 00:11:09.830 --> 00:11:12.450 In other words, it was better support for very large objects and 171 00:11:12.450 --> 00:11:15.120 also the ability to pickle more kinds of objects. 172 00:11:15.120 --> 00:11:18.610 The protocols, this is the disadvantages, aren't backwards compatible. 173 00:11:18.610 --> 00:11:22.690 Sometimes if you use a version 4 protocol from earlier Python versions And 174 00:11:22.690 --> 00:11:26.770 you won't be able to un tuple your data so just to confirm the protocols 175 00:11:26.770 --> 00:11:30.330 aren't backwards compatible so if you used the version four protocol from 176 00:11:30.330 --> 00:11:33.925 earlier python versions you won't be able to add data. 177 00:11:33.925 --> 00:11:37.012 So let's go through and look at some of the different types. 178 00:11:37.012 --> 00:11:40.110 So the original protocol was and 179 00:11:40.110 --> 00:11:44.930 what we can do is we can change the way we the data by the protocol And 180 00:11:44.930 --> 00:11:47.650 then go back and actually have a look at the file itself that is produced. 181 00:11:47.650 --> 00:11:52.050 So I'm going to change these lines to do with writing the file lines 41 though 44, 182 00:11:52.050 --> 00:11:55.970 and what we want to do is put the third parameter there. 183 00:11:55.970 --> 00:12:01.670 We're going to put call comma protocol equals zero. 184 00:12:01.670 --> 00:12:04.080 I'm going to do that for all three. 185 00:12:07.740 --> 00:12:11.180 Like so, and now if we run that and 186 00:12:11.180 --> 00:12:14.040 then close this window off, and if we have a look at that file, 187 00:12:15.120 --> 00:12:18.450 you can see there that we've got something down Now that's much easier to read. 188 00:12:18.450 --> 00:12:20.850 Now it still doesn't make perfect sense. 189 00:12:20.850 --> 00:12:23.290 You can see there's a bracket there in t7 and tp8. 190 00:12:23.290 --> 00:12:27.060 And so it still doesn't make complete sense but 191 00:12:27.060 --> 00:12:30.250 we can set the numbers in our data are delivered with a capital L. 192 00:12:30.250 --> 00:12:34.370 That's really the point we wanna make there, that the limiter is an there. 193 00:12:34.370 --> 00:12:38.510 And you can see the 2998302 there with an L on either side of it as well. 194 00:12:38.510 --> 00:12:41.790 So you can at least make out that the numerical values are And 195 00:12:41.790 --> 00:12:45.700 you can see most of the other data, so that's protocol zero, but there's always 196 00:12:45.700 --> 00:12:50.000 the protocol version one, and that's the first primary protocol in old versions of 197 00:12:50.000 --> 00:12:54.740 python should be able to unpick the data created with that protocol. 198 00:12:54.740 --> 00:12:57.740 Now python 2.3 introduced The protocol version two, 199 00:12:57.740 --> 00:13:00.980 which could pick up classes or efficiently. 200 00:13:00.980 --> 00:13:05.850 Now, this version, protocol version two, also has a never security checks removed. 201 00:13:05.850 --> 00:13:10.410 It was declared insecure, and for that reason, really I don't suggest you use it. 202 00:13:10.410 --> 00:13:14.470 And, we'll discuss more about that security implication shortly. 203 00:13:14.470 --> 00:13:18.320 Now the first Python 3 protocol was Version 3, unsurprisingly. 204 00:13:18.320 --> 00:13:21.060 And this is also the default protocol, 205 00:13:21.060 --> 00:13:24.210 which is used if you don't specify one obviously early on. 206 00:13:24.210 --> 00:13:28.580 In our code, before we added the protocol equal, we didn't specify one, 207 00:13:28.580 --> 00:13:32.610 so we were using protocol version three by default. 208 00:13:32.610 --> 00:13:36.290 Now all versions of Python 3 can understand that protocol that's version 3, 209 00:13:36.290 --> 00:13:38.770 but data created, this is important, 210 00:13:38.770 --> 00:13:43.610 won't be readable using Python 2.x any version of version 2 of Python. 211 00:13:43.610 --> 00:13:47.990 It's very important if you are sort of creating code that's gonna be using Python 212 00:13:47.990 --> 00:13:48.650 2 and Python 3. 213 00:13:48.650 --> 00:13:54.390 The protocol used to pickle objects can be determined by Python automatically. 214 00:13:54.390 --> 00:13:58.530 So it's not necessary in other words to specify a protocol when using the method. 215 00:13:58.530 --> 00:14:02.440 In fact you could use different protocols in the same file, even. 216 00:14:02.440 --> 00:14:03.910 So you could do something like this. 217 00:14:03.910 --> 00:14:05.740 Instead of putting a number there, so let's go back and 218 00:14:05.740 --> 00:14:11.225 we could put Protocol equals pickle.HIGHEST_PROTOCOL. 219 00:14:11.225 --> 00:14:12.830 You can leave the second one at zero, 220 00:14:12.830 --> 00:14:18.690 the third one is we could say something at pickle.DEFAULT_PROTCOL and 221 00:14:18.690 --> 00:14:24.040 we can even do the same for that one as well so pickle.DEFAULT_PROTOCOL. 222 00:14:24.040 --> 00:14:26.240 That's still going to work if you run this. 223 00:14:27.410 --> 00:14:30.000 You see we've still got our data back and everything is working fine. 224 00:14:30.000 --> 00:14:34.390 Because Python's got those checks in built to know which protocol is being used for 225 00:14:34.390 --> 00:14:36.750 a particular dump, which is pretty neat. 226 00:14:36.750 --> 00:14:38.960 And we're gonna even open the file up again and have a look at it. 227 00:14:40.180 --> 00:14:42.620 We notice that we've got a couple of different formats in there. 228 00:14:42.620 --> 00:14:46.130 You can see the even numbers there, two, four, six, eight, delimited by Ls. 229 00:14:46.130 --> 00:14:47.600 But the other ones don't really make a lot of sense, 230 00:14:47.600 --> 00:14:50.000 because they're much more binary than the other version. 231 00:14:50.000 --> 00:14:54.850 Of course why the even numbers are working is that we are used protocol 0 for 232 00:14:54.850 --> 00:14:56.100 that line for the even numbers. 233 00:14:56.100 --> 00:14:58.950 Which was, of course, the most human readable of all the protocols. 234 00:14:58.950 --> 00:15:01.770 There's probably no good reason why you would ever want to do it that way. 235 00:15:01.770 --> 00:15:05.050 Except maybe to demonstrate that the method can't automatically detect 236 00:15:05.050 --> 00:15:07.130 the correct protocol version to use. 237 00:15:07.130 --> 00:15:11.380 Now to talk about security protocol versions before version two performed 238 00:15:11.380 --> 00:15:15.123 a safety check when but the problem was the program 239 00:15:15.123 --> 00:15:20.130 would refuse to call functions or class instructors that weren't marked. 240 00:15:20.130 --> 00:15:22.770 Now these checks were removed in version 2 on 241 00:15:22.770 --> 00:15:26.230 the basis that the security checks hadn't been extensively audited. 242 00:15:26.230 --> 00:15:27.330 And as it turns out, 243 00:15:27.330 --> 00:15:31.610 a number of bugs made them easy to circumvent in most Python versions. 244 00:15:31.610 --> 00:15:32.120 As a result, 245 00:15:32.120 --> 00:15:38.490 it was safe If we publicizing the fact that pickling uses an insecure protocol, 246 00:15:38.490 --> 00:15:42.580 rather than people trusting a protocol that haven't been thoroughly checked. 247 00:15:42.580 --> 00:15:45.745 And even protocols that have been checked such as SSH For 248 00:15:45.745 --> 00:15:48.125 arguments sake, have security flaws, but 249 00:15:48.125 --> 00:15:51.935 the flaws are far more dangerous if the protocol is trusted, so we think 250 00:15:51.935 --> 00:15:56.435 prior from the python team made the right decision by publicizing that fact. 251 00:15:56.435 --> 00:16:00.080 So what the message here is that You should really only unpickling 252 00:16:00.080 --> 00:16:02.130 data that you can trust. 253 00:16:02.130 --> 00:16:05.610 Pickling is fun for storing your program's data but shouldn't be used when dealing 254 00:16:05.610 --> 00:16:09.430 with data of untrusted sources such as over the internet for argument's sake. 255 00:16:09.430 --> 00:16:11.720 So rather than repeated several times and hope that one or 256 00:16:11.720 --> 00:16:15.240 two people actually take the notice what we'll do is we'll demonstrate 257 00:16:15.240 --> 00:16:18.280 how easy it is to wreak havoc by unpickling data. 258 00:16:18.280 --> 00:16:21.090 They can't be trusted and interesting enough this [INAUDIBLE] 259 00:16:21.090 --> 00:16:23.140 will give us a chance to look at another way to pickle and 260 00:16:23.140 --> 00:16:25.760 un pickle using the dumps and loads method. 261 00:16:25.760 --> 00:16:27.810 These are very similar to dump and load, but 262 00:16:27.810 --> 00:16:30.640 instead of writing to we're reading from a file. 263 00:16:30.640 --> 00:16:35.050 What they do is send data to or get data from a bytes object, in other words 264 00:16:35.050 --> 00:16:39.715 a sequence of bytes So we're gonna create a row byte sequence that uses 265 00:16:39.715 --> 00:16:44.400 pickle.load to create an object that it represents, but exactly the same effect 266 00:16:44.400 --> 00:16:48.200 could be reduced by saving the bytes in a file and calling the pickle.load method. 267 00:16:48.200 --> 00:16:49.580 So the short program's gonna be here, and 268 00:16:49.580 --> 00:16:53.830 what I'm gonna do is I'm gonna paste it on screen just to show you. 269 00:16:53.830 --> 00:16:56.550 You wanna use the right one for your operating system. 270 00:16:56.550 --> 00:16:59.440 And what we're going to do, is just after everything else there, 271 00:16:59.440 --> 00:17:01.130 we're going to paste that code in there, 272 00:17:01.130 --> 00:17:04.150 leave the pickle out, import cause that's already at the top of the line. 273 00:17:04.150 --> 00:17:07.880 But we're going to put another one in here, to separate, separator there. 274 00:17:07.880 --> 00:17:11.270 Now you're going to want to use one of these lines of code. 275 00:17:11.270 --> 00:17:14.400 and I'm obviously going to use the top one because I'm running on a Mac, but 276 00:17:14.400 --> 00:17:16.620 if you're a Linux user you'd also use that, but 277 00:17:16.620 --> 00:17:20.040 if you're a Window's user you're going to want to use the one on the next line. 278 00:17:20.040 --> 00:17:23.330 If your looking at that carefully you're probably going to get an idea what's going 279 00:17:23.330 --> 00:17:27.610 to happen here, but I'll leave you in suspense and not tell you until it's done. 280 00:17:27.610 --> 00:17:30.330 So I'm going to delete that because we don't want to run a Windows command 281 00:17:30.330 --> 00:17:33.040 on a Mac, but you'd leave that in if you were on a Windows machine. 282 00:17:33.040 --> 00:17:36.630 So we're going to delete that now And what we'll do is we'll comment out all this 283 00:17:36.630 --> 00:17:40.320 other code now because we've already got our file. 284 00:17:41.560 --> 00:17:42.990 We've already got imelda.pickle. 285 00:17:42.990 --> 00:17:46.640 And just pay attention to imelda.pickle over here. 286 00:17:46.640 --> 00:17:48.480 And I'm gonna run it and watch what happens. 287 00:17:49.970 --> 00:17:50.770 Did you see what happened? 288 00:17:50.770 --> 00:17:52.200 It actually disappeared. 289 00:17:52.200 --> 00:17:55.530 So obviously, very, very simple example of what the code 290 00:17:55.530 --> 00:18:00.570 Was the code to remove a file, RM is remove file in a Linux or Mac machine. 291 00:18:00.570 --> 00:18:06.410 And of course, if you use a Windows machine, del is the command to delete. 292 00:18:06.410 --> 00:18:10.510 Bottom line is just by executing that command pickle.load S, 293 00:18:10.510 --> 00:18:11.930 it actually deleted that file. 294 00:18:11.930 --> 00:18:16.160 So this is obviously a very simple example, and it only deleted a single file 295 00:18:16.160 --> 00:18:19.180 And no real damage was done but it doesn't take much effort to imagine 296 00:18:19.180 --> 00:18:24.000 far worse results that could result from using a from a untrusted source. 297 00:18:24.000 --> 00:18:28.530 Now our data was a representation of an os dot system object 298 00:18:28.530 --> 00:18:31.460 that's used to execute operating system commands. 299 00:18:31.460 --> 00:18:35.940 And because our stream included the command to delete the file 300 00:18:35.940 --> 00:18:39.410 The simple act of loading a data file resulted in another file being deleted. 301 00:18:39.410 --> 00:18:40.890 That's the point I wanna make here. 302 00:18:40.890 --> 00:18:41.990 We're loading a file, and 303 00:18:41.990 --> 00:18:44.170 just loading that file caused something else to be deleted. 304 00:18:44.170 --> 00:18:47.550 And again, a very simple example but you can imagine some 305 00:18:47.550 --> 00:18:52.940 spywares could be created or could be caused by easy untrusted sources here. 306 00:18:52.940 --> 00:18:54.840 So the pickle module itself's very useful. 307 00:18:54.840 --> 00:18:56.930 And it's great for storing and retrieving your own data. 308 00:18:56.930 --> 00:19:01.050 And there's also ways to prevent the security problems we've just seen. 309 00:19:01.050 --> 00:19:03.200 So it is possible to use pickle in production code, 310 00:19:03.200 --> 00:19:05.146 but these methods are quite advanced. 311 00:19:05.146 --> 00:19:07.770 I mean We won't be until much later in the course. 312 00:19:07.770 --> 00:19:10.550 What you really need to do is heed the warning at the web server I'm about to 313 00:19:10.550 --> 00:19:11.180 put on the screen. 314 00:19:11.180 --> 00:19:14.650 If you do that you'll have no trouble using the pickle module to desist your 315 00:19:14.650 --> 00:19:15.370 programs data. 316 00:19:15.370 --> 00:19:18.420 So let's just open that up briefly before we end the lecture. 317 00:19:19.650 --> 00:19:23.380 Here's the link and link will be in the resources section and 318 00:19:23.380 --> 00:19:28.300 just have a look at that and it talks more and more detail about Serialization and 319 00:19:28.300 --> 00:19:32.010 again if you just heed the warnings on that page you'll be good to go. 320 00:19:32.010 --> 00:19:33.580 Alright, so we'll see you in the next video.