That is the sanitization happening for security purpose.
Anyway, those entities would appear as normal '&' and '"' on the frontend (which is where the content is supposed to display). So, shouldn't be any problem except looking a bit weird on the admin-side (the client, I'm sure, can be made to understand what is happening). What do you say?