But Microsoft isn't saying we shouldn't have fonts, video codecs, and whatnot. They're saying this thing isn't worth the security price we will inevitably pay for it. And: fine, if you want to disagree with that. Maybe I disagree too. But fonts and image libraries are facts that seem to me to support Microsoft's point.
Microsoft isn't saying that. They completely avoided talking about the trade offs i.e. they didn't even try to weight the benefits of having WebGL vs. the security risks.
The point is that they took a hard line: this technology has potential problems therefore we're not going to implement it.
The point is that they never took this hard line wrt. any other technology implemented in the browser, either standard or of their own making (like ActiveX, BHOs, Silverlight). In fact, as far as I know, they never even publicly mentioned the fact that essentially every new feature you add to a browser comes with a risk of new bugs just by virtue of them being implemented in C.
The point is that they singled out WebGL and made a big, public stink about it when they have never made even a small stink about any other browser technology with similar issues.
The point is that they didn't bother to even hint that they have a proposal for standard web technology that fills the same role as WebGL which strongly suggest that they just want to kill it. After all, who needs it when we have Silverlight 5.
MSRC didn't say it's not worth it. They said it couldn't survive the SDL process or be securable, which is the standard for technologies they deploy. Given that they deploy those pre-existing technologies and added more in IE9 (WOFF, accelerated H.264, accelerated canvas), and given that they have to pass SDL review, I think they are being unhelpfully inconsistent.
(Does MSRC ever make the worth it/not worth it call? I thought they just analyzed the security side, and didn't make the product decisions.)