Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Bit of a weird comment from Chrome. 'XML' doesn't generate 'security bugs'

It seems you failed to either read or understand the comment, and meanwhile were also too eager to post snarky comments.

If you pay attention to the argument that was actually made, the commenter mentioned specifically "everything implemented using libxml and libxslt".

Meanwhile, here's a list of libxml security issues:

* https://www.cvedetails.com/vulnerability-list/vendor_id-1962...

Here's a list of security issues affecting libxslt:

* https://www.cvedetails.com/vulnerability-list/vendor_id-1962...

OP's point is very clear: if they could remove support for this feature, any of this vulnerabilities, past, present and future, would vanish.



Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: