Date: Thu, 13 Dec 2012 08:19:06 -0800
Subject: Re: Robust XML validation

> Validating against trusted schemas/DTDs would not be sufficient in my
> opinion. For example, such validations are not effective against the
> billion laughs attack (

But... isn't the point that you'd never accept a DTD or schema from an
untrusted source?  That is, never even bother to parse it and
arguably, reject documents from users that contain them.


