Actually there are many more reasons than fears about "code injection" to disable it. That was only one valid reason of many. HTML should never have been allowed to be posted in comments in the first place. We believe that was a mistake by one engineer that has now been undone.
We prevented using HTML or BBCode in the game for several reasons:
- Protecting our users identities from tracking by marketing spam / companies (even images can be used for this purpose)
- Improved security and faster loading times
- Reduced bandwidth usage on mobile phones running on 3G/4G networks, where it's possible to embed images several megabytes in size
- Performance - in-game is not designed for an unlimited amount of multimedia assets to be introduced into the rendering of the content. It could significantly slow down the apps in particular, were a user to embed several high-resolution images or other multimedia content.