Is implementing `serializable` even desirable in a modern Java application?

No modern serialisation frameworks seem to require it; plus, Java's inbuilt serialization mostly seems to give security people cold sweats.