RE: Is MathML really Dangerous?
Paul Topping <[email protected]> Fri, 4 Dec 2015 22:01:21 +0000
| Newsgroups | gmane.comp.web.mathematics |
|---|---|
| Message-ID | <[email protected]> |
This reminds me that the Chrome team ripped out the MathML support code fro= m their Blink engine when it was forked from WebKit over two years ago. If = I recall correctly, they said it was for "security reasons" and that they d= idn't have resources that could ensure that the code didn't have security v= ulnerabilities. Paul > -----Original Message----- > From: Deyan Ginev [mailto:[email protected]] > Sent: Friday, December 04, 2015 1:49 PM > To: Schubotz, Moritz <[email protected]>; [email protected] > Subject: Re: Is MathML really Dangerous? >=20 > Dear all, >=20 > It's great to hear that there is interest in security for MathML. I > would also be curious to hear if a "security audit" of any form has been > performed on the spec, maybe as part of the integration work with the > HTML5 working group. >=20 > Security audits are an inevitability when production-ready technologies > start being used in enterprise settings, and given the scale and > importance of the MediaWiki installations out there, it's reasonable > that they would at least ask the question. In this scope, this is a > question also suitable for the HTML5 community, and I see MathML is > already featured on html5sec: >=20 > https://html5sec.org/?mathml >=20 > Does the Math WG know of prior interest in this subject? >=20 > Greetings, > Deyan >=20 >=20 > On 12/04/2015 03:26 PM, Schubotz, Moritz wrote: > > Hi Bruce, > > > > I have the feeling to give a reasonable answer to the question "is ASCI= I > > dangerous": > > https://xkcd.com/327 > > At least in the context of SQL injections it has been well studied. > > If you expose MathML to browsers that might not even know what > MathML is, > > they might freak out. > > > > Moritz > > >=20