>So since you don't run XFER, and none of your friends run XFER, it's a good
>idea to leave open a possible security hole in the relationship between WWW
>and XFER?

Not at all, because XFER isnt wide spread, the chances of someone writing a
specific attack for XFER is close to zero.


