Always implement readObject() to prevent untrusted deserialization when loading from ObjectInputStream | CAST Appmarq