[In]secure deserialization, and how [not] to do it