]>

Statements dreamed up by the utterly deranged.

This is what happens when you let a bunch of academics and nerds run the W3C. The W3C needs to be fired for this.

Reply to this note

Please Login to reply.

Discussion

yeah seriously, I was looking at this like "I remember patching and documenting XXE bugs in FreeBSD packages like 10 years ago, how it this still a thing? Shouldn't everything be hardened against this by default because of all the SOAP exploits everyone was screaming about around 2010?"

This design by committee shit is inexcusable.

Also, personally, I think it's inexcusable to leave libraries vulnerable by default because of being afraid of breaking backwards compatibility which I assume is the reasoning here.