RE: Is MathML really Dangerous?

Paul Topping <[email protected]> Fri, 4 Dec 2015 22:01:21 +0000
Newsgroups gmane.comp.web.mathematics
Message-ID <[email protected]>
This reminds me that the Chrome team ripped out the MathML support code fro=
m their Blink engine when it was forked from WebKit over two years ago. If =
I recall correctly, they said it was for "security reasons" and that they d=
idn't have resources that could ensure that the code didn't have security v=
ulnerabilities.

Paul

> -----Original Message-----
> From: Deyan Ginev [mailto:[email protected]]
> Sent: Friday, December 04, 2015 1:49 PM
> To: Schubotz, Moritz <[email protected]>; [email protected]
> Subject: Re: Is MathML really Dangerous?
>=20
> Dear all,
>=20
> It's great to hear that there is interest in security for MathML. I
> would also be curious to hear if a "security audit" of any form has been
> performed on the spec, maybe as part of the integration work with the
> HTML5 working group.
>=20
> Security audits are an inevitability when production-ready technologies
> start being used in enterprise settings, and given the scale and
> importance of the MediaWiki installations out there, it's reasonable
> that they would at least ask the question. In this scope, this is a
> question also suitable for the HTML5 community, and I see MathML is
> already featured on html5sec:
>=20
> https://html5sec.org/?mathml
>=20
> Does the Math WG know of prior interest in this subject?
>=20
> Greetings,
> Deyan
>=20
>=20
> On 12/04/2015 03:26 PM, Schubotz, Moritz wrote:
> > Hi Bruce,
> >
> > I have the feeling to give a reasonable answer to the question "is ASCI=
I
> > dangerous":
> > https://xkcd.com/327
> > At least in the context of SQL injections it has been well studied.
> > If you expose MathML to browsers that might not even know what
> MathML is,
> > they might freak out.
> >
> > Moritz
> >
>=20