An IT guy on my board suggested disabling all HTML due to security threat issue.

He said that allowing HTML could allow a virus to be delivered unless the board provides protection or filters.

What do you think?