:/ I'm sorry you feel that way. I can only speak for myself, but I certainly don't want to bury any security issues, I want to fix them.
> what is properly considered a piece of core functionality for Rails.
Maybe automatically parsing XML parameters shouldn't be?