if the default behaviour is to pretend to be IE and open up vulnerabilities That's slightly misleading. The pretend-to-be is user-adjustable but it's mainly useragent stuff and possibly some box-model interpretation. From what I understand, the vulnerabilities from XML rendering are not due to "default behaviour" in the same sense; I doubt there is another XML rendering option. (I may be wrong, I don't touch desktop Opera).
no subject
That's slightly misleading. The pretend-to-be is user-adjustable but it's mainly useragent stuff and possibly some box-model interpretation. From what I understand, the vulnerabilities from XML rendering are not due to "default behaviour" in the same sense; I doubt there is another XML rendering option. (I may be wrong, I don't touch desktop Opera).