RE: [xml-dev] The <any/> element: bane of security or savior of versioning?

From
Michael Kay <>
To
"'Costello, Roger L.'" <>,
Date
2007-10-19T12:17:54Z
ID
<00da01c8124a$13d1de20$6501a8c0@turtle>
Thread
RE: [xml-dev] The <any/> element: bane of security or savior of versioning?
> From a security perspective the <any/> element represents a 
> high risk and should be avoided if possible. 

Why? This sounds as crazy as banning .xml attachments (or .zip attachments)
as a security risk. 

If you want to stop people communicating, then regulating the markup that's
used isn't going to achieve the aim.

If you want to stop recipients of information doing bad things, then control
the recipients.

Michael Kay
http://www.saxonica.com/