1. The embed code is sound, it’s just that it basically adds a feature that could potentially be used to inject bad HTML into a blog (as the embed HTML can be fetched off a remote server). Security enforcement techniques will need to be come up with to make it as secure as possible.

    The idea is though that you can post say a YouTube URL on it’s own line and it’ll automatically be replaced with an embed.

