4 ms·
> does not make any reference to costs or benefits to other users of the web platform > arguments for are being presented publicly in that thread while those a
by halflings 6y ago
> does not make any reference to costs or benefits to other users of the web platform
> arguments for are being presented publicly in that thread while those against are being discussed elsewhere (perhaps at Google?)
It's right there at the end of the highlighted comment:
"we would love to [...] replace them with something that generates less security bugs. Increasing the capabilities of XML in the browser runs counter to that goal."
So security bugs in XML seems to be the main issue?
- richx 6y agoI’m wondering which security risks they mean. I don’t see any security risk in XML itself, maybe it’s related to some XPath or XQuery functions?
- barefootliam 6y agoI think more about the fact libxml and libxslt are large pieces of code and have had CVEs raised against them (and fixed) in the past. They are still actively maintained.
- foota 6y agoI think the idea is the increased security risk of potentially poorly maintained large body of code with a wide surface area.